Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
fASbbWNgm1.exe
|
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
|
initial sample
|
||
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\fASbbWNgm1.exe.log
|
CSV text
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\fASbbWNgm1.exe
|
"C:\Users\user\Desktop\fASbbWNgm1.exe"
|
||
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
|
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
reinforcenh.shop
|
|||
stogeneratmns.shop
|
|||
ghostreedmnu.shop
|
|||
https://steamcommunity.com/profiles/76561199724331900q
|
unknown
|
||
https://steamcommunity.com/profiles/76561199724331900
|
104.102.49.254
|
||
https://steamcommunity.com/profiles/76561199724331900/inventory/
|
unknown
|
||
fragnantbui.shop
|
|||
gutterydhowi.shop
|
|||
offensivedzvju.shop
|
|||
drawzhotdog.shop
|
|||
https://sergei-esenin.com/api
|
104.21.53.8
|
||
vozmeatillu.shop
|
|||
https://steamcommunity.com/profiles/76561199724331900/badges
|
unknown
|
||
https://drawzhotdog.shop/api
|
unknown
|
||
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&
|
unknown
|
||
http://ocsp.entrust.net03
|
unknown
|
||
http://ocsp.entrust.net02
|
unknown
|
||
https://sergei-esenin.com/
|
unknown
|
||
http://store.steampowered.com/subscriber_agreement/
|
unknown
|
||
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
|
unknown
|
||
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
|
unknown
|
||
https://community.akamai.steamstu
|
unknown
|
||
https://stogeneratmns.shop:443/api
|
unknown
|
||
https://sergei-esenin.com:443/apip
|
unknown
|
||
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
|
unknown
|
||
https://reinforcenh.shop/api
|
unknown
|
||
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=AeTz
|
unknown
|
||
http://crl.entrust.net/ts1ca.crl0
|
unknown
|
||
https://steamcommunity.com/6
|
unknown
|
||
https://store.steampowered.com/legal/
|
unknown
|
||
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
|
unknown
|
||
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
|
unknown
|
||
http://www.entrust.net/rpa03
|
unknown
|
||
https://ghostreedmnu.shop/apin
|
unknown
|
||
http://store.steampowered.com/privacy_agreement/
|
unknown
|
||
https://steamcommunity.com:443/profiles/76561199724331900
|
unknown
|
||
http://aia.entrust.net/ts1-chain256.cer01
|
unknown
|
||
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
|
unknown
|
||
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
|
unknown
|
||
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
|
unknown
|
||
https://reinforcenh.shop:443/api6
|
unknown
|
||
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
|
unknown
|
||
https://vozmeatillu.shop:443/api
|
unknown
|
||
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
|
unknown
|
||
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
|
unknown
|
||
http://store.steampowered.com/account/cookiepreferences/
|
unknown
|
||
https://steamcommunity.com/
|
unknown
|
||
http://crl.entrust.net/2048ca.crl0
|
unknown
|
||
https://www.entrust.net/rpa0
|
unknown
|
There are 39 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
sergei-esenin.com
|
104.21.53.8
|
||
fragnantbui.shop
|
unknown
|
||
gutterydhowi.shop
|
unknown
|
||
offensivedzvju.shop
|
unknown
|
||
stogeneratmns.shop
|
unknown
|
||
reinforcenh.shop
|
unknown
|
||
drawzhotdog.shop
|
unknown
|
||
ghostreedmnu.shop
|
unknown
|
||
vozmeatillu.shop
|
unknown
|
||
steamcommunity.com
|
104.102.49.254
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
104.21.53.8
|
sergei-esenin.com
|
United States
|
||
104.102.49.254
|
steamcommunity.com
|
United States
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
400000
|
remote allocation
|
page execute and read and write
|
||
B2E000
|
stack
|
page read and write
|
||
D3E000
|
stack
|
page read and write
|
||
2BC1000
|
trusted library allocation
|
page execute and read and write
|
||
D7E000
|
stack
|
page read and write
|
||
D3D000
|
stack
|
page read and write
|
||
F80000
|
trusted library allocation
|
page read and write
|
||
B80000
|
heap
|
page read and write
|
||
95C000
|
stack
|
page read and write
|
||
4D5D000
|
stack
|
page read and write
|
||
F60000
|
trusted library allocation
|
page read and write
|
||
CF8000
|
stack
|
page read and write
|
||
DBB000
|
heap
|
page read and write
|
||
9C0000
|
heap
|
page read and write
|
||
D40000
|
heap
|
page read and write
|
||
990000
|
heap
|
page read and write
|
||
CFD000
|
stack
|
page read and write
|
||
FAB000
|
trusted library allocation
|
page execute and read and write
|
||
C42000
|
heap
|
page read and write
|
||
3BC5000
|
trusted library allocation
|
page read and write
|
||
FB0000
|
heap
|
page read and write
|
||
3BC1000
|
trusted library allocation
|
page read and write
|
||
9C5000
|
heap
|
page read and write
|
||
26EF000
|
stack
|
page read and write
|
||
BFB000
|
heap
|
page read and write
|
||
2BC3000
|
trusted library allocation
|
page read and write
|
||
D9E000
|
heap
|
page read and write
|
||
2A5D000
|
stack
|
page read and write
|
||
840000
|
unkown
|
page readonly
|
||
2BBF000
|
stack
|
page read and write
|
||
25EF000
|
stack
|
page read and write
|
||
DE6000
|
heap
|
page read and write
|
||
FF0000
|
heap
|
page read and write
|
||
11FF000
|
stack
|
page read and write
|
||
B30000
|
heap
|
page read and write
|
||
C56000
|
heap
|
page read and write
|
||
DB6000
|
heap
|
page read and write
|
||
BF8000
|
heap
|
page read and write
|
||
D9A000
|
heap
|
page read and write
|
||
2C6D000
|
stack
|
page read and write
|
||
2DCE000
|
stack
|
page read and write
|
||
2A1E000
|
stack
|
page read and write
|
||
28ED000
|
stack
|
page read and write
|
||
BCF000
|
heap
|
page read and write
|
||
B8A000
|
heap
|
page read and write
|
||
F73000
|
trusted library allocation
|
page execute and read and write
|
||
A15000
|
heap
|
page read and write
|
||
A10000
|
heap
|
page read and write
|
||
2AB0000
|
heap
|
page execute and read and write
|
||
9D0000
|
heap
|
page read and write
|
||
29D0000
|
heap
|
page read and write
|
||
92C000
|
stack
|
page read and write
|
||
85C000
|
stack
|
page read and write
|
||
BA7000
|
heap
|
page read and write
|
||
CBE000
|
stack
|
page read and write
|
||
10FF000
|
stack
|
page read and write
|
||
D90000
|
heap
|
page read and write
|
||
45E000
|
remote allocation
|
page execute and read and write
|
||
9A0000
|
heap
|
page read and write
|
||
DC4000
|
heap
|
page read and write
|
||
BBA000
|
heap
|
page read and write
|
||
2D6D000
|
stack
|
page read and write
|
||
842000
|
unkown
|
page readonly
|
||
27ED000
|
stack
|
page read and write
|
||
9D0000
|
heap
|
page read and write
|
||
2ECF000
|
stack
|
page read and write
|
||
F86000
|
trusted library allocation
|
page read and write
|
||
9C0000
|
heap
|
page read and write
|
||
F74000
|
trusted library allocation
|
page read and write
|
||
29A0000
|
trusted library allocation
|
page read and write
|
||
BD9000
|
heap
|
page read and write
|
||
BF0000
|
heap
|
page read and write
|
||
FE0000
|
trusted library allocation
|
page execute and read and write
|
||
F84000
|
trusted library allocation
|
page read and write
|
||
DD2000
|
heap
|
page read and write
|
There are 65 hidden memdumps, click here to show them.