IOC Report
fASbbWNgm1.exe

loading gif

Files

File Path
Type
Category
Malicious
fASbbWNgm1.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\fASbbWNgm1.exe.log
CSV text
dropped
malicious

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\fASbbWNgm1.exe
"C:\Users\user\Desktop\fASbbWNgm1.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
reinforcenh.shop
malicious
stogeneratmns.shop
malicious
ghostreedmnu.shop
malicious
https://steamcommunity.com/profiles/76561199724331900q
unknown
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
fragnantbui.shop
malicious
gutterydhowi.shop
malicious
offensivedzvju.shop
malicious
drawzhotdog.shop
malicious
https://sergei-esenin.com/api
104.21.53.8
malicious
vozmeatillu.shop
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://drawzhotdog.shop/api
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
http://ocsp.entrust.net03
unknown
http://ocsp.entrust.net02
unknown
https://sergei-esenin.com/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://community.akamai.steamstu
unknown
https://stogeneratmns.shop:443/api
unknown
https://sergei-esenin.com:443/apip
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://reinforcenh.shop/api
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=AeTz
unknown
http://crl.entrust.net/ts1ca.crl0
unknown
https://steamcommunity.com/6
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
http://www.entrust.net/rpa03
unknown
https://ghostreedmnu.shop/apin
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://steamcommunity.com:443/profiles/76561199724331900
unknown
http://aia.entrust.net/ts1-chain256.cer01
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://reinforcenh.shop:443/api6
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://vozmeatillu.shop:443/api
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://steamcommunity.com/
unknown
http://crl.entrust.net/2048ca.crl0
unknown
https://www.entrust.net/rpa0
unknown
There are 39 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
104.21.53.8
malicious
fragnantbui.shop
unknown
malicious
gutterydhowi.shop
unknown
malicious
offensivedzvju.shop
unknown
malicious
stogeneratmns.shop
unknown
malicious
reinforcenh.shop
unknown
malicious
drawzhotdog.shop
unknown
malicious
ghostreedmnu.shop
unknown
malicious
vozmeatillu.shop
unknown
malicious
steamcommunity.com
104.102.49.254

IPs

IP
Domain
Country
Malicious
104.21.53.8
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
400000
remote allocation
page execute and read and write
malicious
B2E000
stack
page read and write
D3E000
stack
page read and write
2BC1000
trusted library allocation
page execute and read and write
D7E000
stack
page read and write
D3D000
stack
page read and write
F80000
trusted library allocation
page read and write
B80000
heap
page read and write
95C000
stack
page read and write
4D5D000
stack
page read and write
F60000
trusted library allocation
page read and write
CF8000
stack
page read and write
DBB000
heap
page read and write
9C0000
heap
page read and write
D40000
heap
page read and write
990000
heap
page read and write
CFD000
stack
page read and write
FAB000
trusted library allocation
page execute and read and write
C42000
heap
page read and write
3BC5000
trusted library allocation
page read and write
FB0000
heap
page read and write
3BC1000
trusted library allocation
page read and write
9C5000
heap
page read and write
26EF000
stack
page read and write
BFB000
heap
page read and write
2BC3000
trusted library allocation
page read and write
D9E000
heap
page read and write
2A5D000
stack
page read and write
840000
unkown
page readonly
2BBF000
stack
page read and write
25EF000
stack
page read and write
DE6000
heap
page read and write
FF0000
heap
page read and write
11FF000
stack
page read and write
B30000
heap
page read and write
C56000
heap
page read and write
DB6000
heap
page read and write
BF8000
heap
page read and write
D9A000
heap
page read and write
2C6D000
stack
page read and write
2DCE000
stack
page read and write
2A1E000
stack
page read and write
28ED000
stack
page read and write
BCF000
heap
page read and write
B8A000
heap
page read and write
F73000
trusted library allocation
page execute and read and write
A15000
heap
page read and write
A10000
heap
page read and write
2AB0000
heap
page execute and read and write
9D0000
heap
page read and write
29D0000
heap
page read and write
92C000
stack
page read and write
85C000
stack
page read and write
BA7000
heap
page read and write
CBE000
stack
page read and write
10FF000
stack
page read and write
D90000
heap
page read and write
45E000
remote allocation
page execute and read and write
9A0000
heap
page read and write
DC4000
heap
page read and write
BBA000
heap
page read and write
2D6D000
stack
page read and write
842000
unkown
page readonly
27ED000
stack
page read and write
9D0000
heap
page read and write
2ECF000
stack
page read and write
F86000
trusted library allocation
page read and write
9C0000
heap
page read and write
F74000
trusted library allocation
page read and write
29A0000
trusted library allocation
page read and write
BD9000
heap
page read and write
BF0000
heap
page read and write
FE0000
trusted library allocation
page execute and read and write
F84000
trusted library allocation
page read and write
DD2000
heap
page read and write
There are 65 hidden memdumps, click here to show them.