IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.stor
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
bathdoomgaz.stor
malicious
dissapoiznw.stor
malicious
spirittunek.stor
malicious
eaglepawnoy.stor
malicious
clearancek.site
malicious
licendfilteo.site
malicious
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://clearancek.s
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://bathdoomgaz.store:443/apii
unknown
https://store.steampowered.com/points/shop/
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://sergei-esenin.com:443/api
unknown
https://sergei-esenin.com/j
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://avatars.akamai.steamstatic
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://sergei-esenin.com/apij
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://licendfilteo.site:443/apibcryptPrimitives.dll
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://dissapoiznw.store:443/api
unknown
https://steamcommunity.com/discussions/
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=9yzMGndrVfY4&l=e
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com:443/profiles/76561199724331900y
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=AeTz
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://mobbipenju.store:443/api
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://spirittunek.store:443/api
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
172.67.206.204
malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
172.67.206.204
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
F41000
unkown
page execute and read and write
malicious
4C31000
heap
page read and write
412E000
stack
page read and write
1619000
heap
page read and write
35AF000
stack
page read and write
598D000
stack
page read and write
3E6F000
stack
page read and write
15E0000
heap
page read and write
2FEF000
stack
page read and write
E35000
heap
page read and write
4C31000
heap
page read and write
4AEF000
stack
page read and write
E30000
heap
page read and write
1642000
heap
page read and write
E20000
direct allocation
page read and write
1658000
heap
page read and write
3FEE000
stack
page read and write
1636000
heap
page read and write
1639000
heap
page read and write
51F0000
remote allocation
page read and write
45EF000
stack
page read and write
50EE000
stack
page read and write
4C40000
heap
page read and write
476E000
stack
page read and write
4C31000
heap
page read and write
4C31000
heap
page read and write
E20000
direct allocation
page read and write
5210000
direct allocation
page execute and read and write
5210000
direct allocation
page execute and read and write
472F000
stack
page read and write
44AF000
stack
page read and write
16B6000
heap
page read and write
3BEF000
stack
page read and write
E20000
direct allocation
page read and write
538D000
stack
page read and write
3FAF000
stack
page read and write
E20000
direct allocation
page read and write
4C31000
heap
page read and write
13E9000
unkown
page execute and read and write
2EC0000
direct allocation
page read and write
16AC000
heap
page read and write
1248000
unkown
page execute and read and write
4C31000
heap
page read and write
E20000
direct allocation
page read and write
346F000
stack
page read and write
51F0000
remote allocation
page read and write
F3F000
stack
page read and write
123B000
unkown
page execute and read and write
588D000
stack
page read and write
560E000
stack
page read and write
34AE000
stack
page read and write
1626000
heap
page read and write
E10000
heap
page read and write
55CF000
stack
page read and write
5220000
direct allocation
page execute and read and write
FA0000
unkown
page execute and read and write
50AD000
stack
page read and write
2E2E000
stack
page read and write
3AEE000
stack
page read and write
1642000
heap
page read and write
59DE000
stack
page read and write
36EF000
stack
page read and write
162F000
heap
page read and write
5210000
direct allocation
page execute and read and write
E20000
direct allocation
page read and write
584E000
stack
page read and write
4C31000
heap
page read and write
4C31000
heap
page read and write
336E000
stack
page read and write
16AD000
heap
page read and write
39AE000
stack
page read and write
4C2F000
stack
page read and write
31EF000
stack
page read and write
2EE7000
heap
page read and write
5210000
direct allocation
page execute and read and write
51EE000
stack
page read and write
E20000
direct allocation
page read and write
F41000
unkown
page execute and write copy
3D6E000
stack
page read and write
1124000
unkown
page execute and read and write
4C31000
heap
page read and write
1203000
unkown
page execute and read and write
51F0000
remote allocation
page read and write
E20000
direct allocation
page read and write
15C0000
heap
page read and write
574D000
stack
page read and write
1629000
heap
page read and write
4C31000
heap
page read and write
9A0000
heap
page read and write
15BE000
stack
page read and write
426E000
stack
page read and write
4C31000
heap
page read and write
396F000
stack
page read and write
4C31000
heap
page read and write
5200000
direct allocation
page execute and read and write
4C31000
heap
page read and write
1636000
heap
page read and write
2E6C000
stack
page read and write
16AE000
heap
page read and write
43AE000
stack
page read and write
486F000
stack
page read and write
9B0000
heap
page read and write
94C000
stack
page read and write
5240000
direct allocation
page execute and read and write
E0E000
stack
page read and write
5070000
trusted library allocation
page read and write
48AE000
stack
page read and write
F40000
unkown
page read and write
534D000
stack
page read and write
372E000
stack
page read and write
16BE000
heap
page read and write
1639000
heap
page read and write
2EE0000
heap
page read and write
1670000
heap
page read and write
CFD000
stack
page read and write
122F000
unkown
page execute and read and write
16AC000
heap
page read and write
51F0000
direct allocation
page execute and read and write
1656000
heap
page read and write
E20000
direct allocation
page read and write
570E000
stack
page read and write
13EA000
unkown
page execute and write copy
548D000
stack
page read and write
382F000
stack
page read and write
16AC000
heap
page read and write
30EF000
stack
page read and write
5210000
direct allocation
page execute and read and write
54CE000
stack
page read and write
2EAE000
stack
page read and write
49EE000
stack
page read and write
E20000
direct allocation
page read and write
4C31000
heap
page read and write
44EE000
stack
page read and write
162B000
heap
page read and write
1670000
heap
page read and write
4C31000
heap
page read and write
3AAF000
stack
page read and write
462E000
stack
page read and write
1249000
unkown
page execute and write copy
5210000
direct allocation
page execute and read and write
2EC0000
direct allocation
page read and write
422F000
stack
page read and write
3D2F000
stack
page read and write
50B0000
direct allocation
page read and write
E20000
direct allocation
page read and write
5255000
trusted library allocation
page read and write
4C31000
heap
page read and write
3EAE000
stack
page read and write
E20000
direct allocation
page read and write
E20000
direct allocation
page read and write
35EE000
stack
page read and write
4C30000
heap
page read and write
E20000
direct allocation
page read and write
15EA000
heap
page read and write
3C2E000
stack
page read and write
15EE000
heap
page read and write
1645000
heap
page read and write
386E000
stack
page read and write
332F000
stack
page read and write
5230000
direct allocation
page execute and read and write
F40000
unkown
page readonly
49AF000
stack
page read and write
1670000
heap
page read and write
4B2E000
stack
page read and write
1645000
heap
page read and write
436F000
stack
page read and write
322E000
stack
page read and write
4C31000
heap
page read and write
2ED0000
direct allocation
page execute and read and write
4C31000
heap
page read and write
4C31000
heap
page read and write
2DEF000
stack
page read and write
162F000
heap
page read and write
40EF000
stack
page read and write
5ADF000
stack
page read and write
1248000
unkown
page execute and write copy
There are 166 hidden memdumps, click here to show them.