Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
A6QFRW2WiY.exe
|
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\A6QFRW2WiY.exe.log
|
CSV text
|
modified
|
||
\Device\ConDrv
|
ASCII text, with CRLF, LF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\A6QFRW2WiY.exe
|
"C:\Users\user\Desktop\A6QFRW2WiY.exe"
|
||
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
|
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
stogeneratmns.shop
|
|||
reinforcenh.shop
|
|||
ghostreedmnu.shop
|
|||
https://steamcommunity.com/profiles/76561199724331900
|
104.102.49.254
|
||
https://steamcommunity.com/profiles/76561199724331900/inventory/
|
unknown
|
||
fragnantbui.shop
|
|||
gutterydhowi.shop
|
|||
offensivedzvju.shop
|
|||
drawzhotdog.shop
|
|||
https://sergei-esenin.com/api
|
172.67.206.204
|
||
vozmeatillu.shop
|
|||
https://steamcommunity.com/profiles/76561199724331900/badges
|
unknown
|
||
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
|
unknown
|
||
http://ocsp.entrust.net03
|
unknown
|
||
http://ocsp.entrust.net02
|
unknown
|
||
https://sergei-esenin.com/
|
unknown
|
||
http://store.steampowered.com/subscriber_agreement/
|
unknown
|
||
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
|
unknown
|
||
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
|
unknown
|
||
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
|
unknown
|
||
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&
|
unknown
|
||
https://drawzhotdog.shop/api-
|
unknown
|
||
https://sergei-esenin.com/apiD
|
unknown
|
||
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
|
unknown
|
||
https://reinforcenh.shop/api
|
unknown
|
||
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
|
unknown
|
||
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
|
unknown
|
||
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=AeTz
|
unknown
|
||
http://crl.entrust.net/ts1ca.crl0
|
unknown
|
||
https://store.steampowered.com/legal/
|
unknown
|
||
https://community.akamai.steamstatic.com/public/shared/javascript
|
unknown
|
||
https://steamcommunity.com/m
|
unknown
|
||
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
|
unknown
|
||
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
|
unknown
|
||
http://www.entrust.net/rpa03
|
unknown
|
||
http://store.steampowered.com/privacy_agreement/
|
unknown
|
||
http://aia.entrust.net/ts1-chain256.cer01
|
unknown
|
||
https://vozmeatillu.shop/api
|
unknown
|
||
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
|
unknown
|
||
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
|
unknown
|
||
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
|
unknown
|
||
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
|
unknown
|
||
https://ghostreedmnu.shop/api
|
unknown
|
||
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
|
unknown
|
||
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
|
unknown
|
||
https://sergei-esenin.com:443/api
|
unknown
|
||
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
|
unknown
|
||
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
|
unknown
|
||
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
|
unknown
|
||
http://store.steampowered.com/account/cookiepreferences/
|
unknown
|
||
https://steamcommunity.com/
|
unknown
|
||
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
|
unknown
|
||
http://crl.entrust.net/2048ca.crl0
|
unknown
|
||
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
|
unknown
|
||
https://www.entrust.net/rpa0
|
unknown
|
There are 45 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
sergei-esenin.com
|
172.67.206.204
|
||
fragnantbui.shop
|
unknown
|
||
gutterydhowi.shop
|
unknown
|
||
offensivedzvju.shop
|
unknown
|
||
stogeneratmns.shop
|
unknown
|
||
reinforcenh.shop
|
unknown
|
||
drawzhotdog.shop
|
unknown
|
||
ghostreedmnu.shop
|
unknown
|
||
vozmeatillu.shop
|
unknown
|
||
steamcommunity.com
|
104.102.49.254
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
172.67.206.204
|
sergei-esenin.com
|
United States
|
||
104.102.49.254
|
steamcommunity.com
|
United States
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
400000
|
remote allocation
|
page execute and read and write
|
||
136E000
|
stack
|
page read and write
|
||
C20000
|
heap
|
page read and write
|
||
FD5000
|
heap
|
page read and write
|
||
1456000
|
heap
|
page read and write
|
||
FF0000
|
heap
|
page read and write
|
||
6ED000
|
heap
|
page read and write
|
||
703000
|
heap
|
page read and write
|
||
13EE000
|
heap
|
page read and write
|
||
904000
|
trusted library allocation
|
page read and write
|
||
6CA000
|
heap
|
page read and write
|
||
34D1000
|
trusted library allocation
|
page read and write
|
||
3B8000
|
stack
|
page read and write
|
||
24D1000
|
trusted library allocation
|
page execute and read and write
|
||
903000
|
trusted library allocation
|
page execute and read and write
|
||
FD0000
|
heap
|
page read and write
|
||
22C000
|
unkown
|
page readonly
|
||
466E000
|
stack
|
page read and write
|
||
2F7D000
|
stack
|
page read and write
|
||
13AA000
|
heap
|
page read and write
|
||
914000
|
trusted library allocation
|
page read and write
|
||
6C0000
|
heap
|
page read and write
|
||
F7C000
|
stack
|
page read and write
|
||
36DE000
|
stack
|
page read and write
|
||
45D000
|
remote allocation
|
page execute and read and write
|
||
8F0000
|
trusted library allocation
|
page read and write
|
||
13CF000
|
heap
|
page read and write
|
||
1463000
|
heap
|
page read and write
|
||
BFE000
|
stack
|
page read and write
|
||
30BE000
|
stack
|
page read and write
|
||
630000
|
heap
|
page read and write
|
||
2BC000
|
stack
|
page read and write
|
||
31FD000
|
stack
|
page read and write
|
||
1760000
|
heap
|
page read and write
|
||
6AE000
|
stack
|
page read and write
|
||
1370000
|
heap
|
page read and write
|
||
49B0000
|
trusted library allocation
|
page read and write
|
||
C00000
|
heap
|
page read and write
|
||
12FC000
|
stack
|
page read and write
|
||
1D0000
|
unkown
|
page readonly
|
||
6CE000
|
heap
|
page read and write
|
||
B47000
|
trusted library allocation
|
page execute and read and write
|
||
13A0000
|
heap
|
page read and write
|
||
37DF000
|
stack
|
page read and write
|
||
1300000
|
heap
|
page read and write
|
||
30FD000
|
stack
|
page read and write
|
||
2FBE000
|
stack
|
page read and write
|
||
13F1000
|
heap
|
page read and write
|
||
34D5000
|
trusted library allocation
|
page read and write
|
||
916000
|
trusted library allocation
|
page read and write
|
||
8D0000
|
heap
|
page read and write
|
||
910000
|
trusted library allocation
|
page read and write
|
||
173D000
|
stack
|
page read and write
|
||
B2E000
|
stack
|
page read and write
|
||
13D8000
|
heap
|
page read and write
|
||
13C6000
|
heap
|
page read and write
|
||
367E000
|
stack
|
page read and write
|
||
357E000
|
stack
|
page read and write
|
||
B4B000
|
trusted library allocation
|
page execute and read and write
|
||
BB0000
|
heap
|
page execute and read and write
|
||
BAE000
|
stack
|
page read and write
|
||
C10000
|
trusted library allocation
|
page execute and read and write
|
||
620000
|
heap
|
page read and write
|
||
24D3000
|
trusted library allocation
|
page read and write
|
||
1D2000
|
unkown
|
page readonly
|
||
660000
|
heap
|
page read and write
|
||
1407000
|
heap
|
page read and write
|
||
A2F000
|
stack
|
page read and write
|
||
144E000
|
heap
|
page read and write
|
||
920000
|
heap
|
page read and write
|
||
8CE000
|
stack
|
page read and write
|
||
665000
|
heap
|
page read and write
|
||
6F5000
|
heap
|
page read and write
|
||
24CE000
|
stack
|
page read and write
|
||
B3A000
|
trusted library allocation
|
page execute and read and write
|
||
2E7F000
|
stack
|
page read and write
|
There are 66 hidden memdumps, click here to show them.