IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.stor
malicious
spirittunek.stor
malicious
eaglepawnoy.stor
malicious
clearancek.site
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
licendfilteo.site
malicious
bathdoomgaz.stor
malicious
dissapoiznw.stor
malicious
https://steamcommunity.com/my/wishlist/
unknown
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://recaptcha.net/recaptcha/;
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://steamcommunity.com/discussions/
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/fatalerror.css?v=wctRWaBvNt2z&l=engli
unknown
https://store.steampowered.com/stats/
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://clearancek.site:443/api
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=AeTz
unknown
https://s.ytimg.com;
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://eaglepawnoy.store:443/api
unknown
https://store.steampowered.com/legal/
unknown
https://steam.tv/
unknown
https://licendfilteo.site:443/api
unknown
https://studennotediw.store:443/api&
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://steamcommunity.com:443/profiles/76561199724331900
unknown
https://store.steampowered.com/points/shop/
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://steamcommunity.com
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
https://clearancek.site:443/apiiY
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
There are 77 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
4C1000
unkown
page execute and read and write
malicious
DB4000
heap
page read and write
E38000
heap
page read and write
535F000
stack
page read and write
45FE000
stack
page read and write
549E000
stack
page read and write
3FBE000
stack
page read and write
2CFE000
stack
page read and write
DB4000
heap
page read and write
520000
unkown
page execute and read and write
3D3E000
stack
page read and write
447F000
stack
page read and write
4E1F000
stack
page read and write
4C0000
unkown
page readonly
40BF000
stack
page read and write
37FF000
stack
page read and write
DB4000
heap
page read and write
4CE0000
direct allocation
page read and write
125F000
stack
page read and write
952000
unkown
page execute and write copy
E54000
heap
page read and write
2CBF000
stack
page read and write
4FDE000
stack
page read and write
4E60000
direct allocation
page execute and read and write
7BC000
unkown
page execute and read and write
511E000
stack
page read and write
101E000
stack
page read and write
2F7E000
stack
page read and write
4851000
heap
page read and write
DB4000
heap
page read and write
4840000
direct allocation
page read and write
4CE0000
direct allocation
page read and write
DB4000
heap
page read and write
4E70000
direct allocation
page execute and read and write
DB4000
heap
page read and write
E8E000
heap
page read and write
E7A000
heap
page read and write
4E60000
direct allocation
page execute and read and write
E3A000
heap
page read and write
E61000
heap
page read and write
4950000
trusted library allocation
page read and write
DB4000
heap
page read and write
3ABE000
stack
page read and write
D6D000
stack
page read and write
111E000
stack
page read and write
2DFF000
stack
page read and write
DB4000
heap
page read and write
DB4000
heap
page read and write
7BC000
unkown
page execute and write copy
7BD000
unkown
page execute and write copy
E61000
heap
page read and write
E7D000
heap
page read and write
423E000
stack
page read and write
4E60000
direct allocation
page execute and read and write
4851000
heap
page read and write
383E000
stack
page read and write
3F7E000
stack
page read and write
4851000
heap
page read and write
4851000
heap
page read and write
4CD0000
remote allocation
page read and write
2B7F000
stack
page read and write
4840000
direct allocation
page read and write
36BF000
stack
page read and write
4851000
heap
page read and write
778000
unkown
page execute and read and write
DB4000
heap
page read and write
4851000
heap
page read and write
4840000
direct allocation
page read and write
473E000
stack
page read and write
4851000
heap
page read and write
347E000
stack
page read and write
393F000
stack
page read and write
2A30000
heap
page read and write
E73000
heap
page read and write
7A6000
unkown
page execute and read and write
2F3F000
stack
page read and write
44BE000
stack
page read and write
2A7E000
stack
page read and write
DB4000
heap
page read and write
DFA000
heap
page read and write
698000
unkown
page execute and read and write
DFE000
heap
page read and write
3E7E000
stack
page read and write
DB4000
heap
page read and write
E8A000
heap
page read and write
397E000
stack
page read and write
E35000
heap
page read and write
4860000
heap
page read and write
DB4000
heap
page read and write
36FE000
stack
page read and write
30BE000
stack
page read and write
483F000
stack
page read and write
4840000
direct allocation
page read and write
3A7F000
stack
page read and write
4E60000
direct allocation
page execute and read and write
E8E000
heap
page read and write
4840000
direct allocation
page read and write
DB4000
heap
page read and write
45BF000
stack
page read and write
4840000
direct allocation
page read and write
E3F000
heap
page read and write
2BBB000
stack
page read and write
4E50000
direct allocation
page execute and read and write
EC8000
heap
page read and write
DB4000
heap
page read and write
4850000
heap
page read and write
4E30000
direct allocation
page execute and read and write
DB4000
heap
page read and write
E8B000
heap
page read and write
DF0000
heap
page read and write
951000
unkown
page execute and write copy
4840000
direct allocation
page read and write
41FF000
stack
page read and write
550E000
stack
page read and write
35BE000
stack
page read and write
DB4000
heap
page read and write
4E60000
direct allocation
page execute and read and write
31BF000
stack
page read and write
2A20000
heap
page read and write
4840000
direct allocation
page read and write
DB4000
heap
page read and write
4E90000
direct allocation
page execute and read and write
4EAC000
trusted library allocation
page read and write
2E3E000
stack
page read and write
40FE000
stack
page read and write
E8E000
heap
page read and write
E7E000
heap
page read and write
46FF000
stack
page read and write
4851000
heap
page read and write
E77000
heap
page read and write
115E000
stack
page read and write
4E60000
direct allocation
page execute and read and write
4840000
direct allocation
page read and write
3BBF000
stack
page read and write
4CE0000
direct allocation
page read and write
433F000
stack
page read and write
EC2000
heap
page read and write
DE0000
heap
page read and write
4840000
direct allocation
page read and write
4840000
direct allocation
page read and write
7AD000
unkown
page execute and read and write
357F000
stack
page read and write
DB4000
heap
page read and write
4C1000
unkown
page execute and write copy
333E000
stack
page read and write
4840000
direct allocation
page read and write
DB4000
heap
page read and write
50DD000
stack
page read and write
E29000
heap
page read and write
4D1E000
stack
page read and write
307F000
stack
page read and write
E54000
heap
page read and write
DB4000
heap
page read and write
4CD0000
remote allocation
page read and write
4851000
heap
page read and write
4E40000
direct allocation
page execute and read and write
343F000
stack
page read and write
3CFF000
stack
page read and write
DD0000
heap
page read and write
E3F000
heap
page read and write
525E000
stack
page read and write
2A37000
heap
page read and write
E73000
heap
page read and write
DB0000
heap
page read and write
4E6E000
stack
page read and write
DB4000
heap
page read and write
31FE000
stack
page read and write
521F000
stack
page read and write
560F000
stack
page read and write
DB4000
heap
page read and write
4851000
heap
page read and write
4E80000
direct allocation
page execute and read and write
3E3F000
stack
page read and write
E30000
heap
page read and write
4840000
direct allocation
page read and write
DB4000
heap
page read and write
3BFE000
stack
page read and write
32FF000
stack
page read and write
E7A000
heap
page read and write
4CD0000
remote allocation
page read and write
437E000
stack
page read and write
C6C000
stack
page read and write
4C90000
heap
page read and write
4840000
direct allocation
page read and write
951000
unkown
page execute and read and write
E8A000
heap
page read and write
539D000
stack
page read and write
4C0000
unkown
page read and write
E77000
heap
page read and write
4F9D000
stack
page read and write
DB4000
heap
page read and write
There are 181 hidden memdumps, click here to show them.