IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
https://bathdoomgaz.store:443/api
unknown
malicious
studennotediw.stor
malicious
https://licendfilteo.site:443/apiz
unknown
malicious
spirittunek.stor
malicious
eaglepawnoy.stor
malicious
https://clearancek.site:443/api
unknown
malicious
https://eaglepawnoy.store:443/api
unknown
malicious
clearancek.site
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
licendfilteo.site
malicious
https://mobbipenju.store:443/api
unknown
malicious
https://steamcommunity.com/profiles/76561199724331900P
unknown
malicious
https://spirittunek.store:443/api
unknown
malicious
bathdoomgaz.stor
malicious
https://studennotediw.store:443/apiI
unknown
malicious
dissapoiznw.stor
malicious
https://steamcommunity.com/my/wishlist/
unknown
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://recaptcha.net/recaptcha/;
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://steamcommunity.com/discussions/
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/fatalerror.css?v=wctRWaBvNt2z&l=engli
unknown
https://store.steampowered.com/stats/
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=AeTz
unknown
https://s.ytimg.com;
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://steamcommunity.com/p
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://steamcommunity.com:443/profiles/76561199724331900
unknown
https://store.steampowered.com/points/shop/
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://steamcommunity.com
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
There are 81 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
201000
unkown
page execute and read and write
malicious
5080000
direct allocation
page execute and read and write
11F2000
heap
page read and write
11CD000
heap
page read and write
584E000
stack
page read and write
11EF000
heap
page read and write
329F000
stack
page read and write
495E000
stack
page read and write
569D000
stack
page read and write
445E000
stack
page read and write
1180000
heap
page read and write
4A60000
direct allocation
page read and write
2C10000
heap
page read and write
5550000
remote allocation
page read and write
355E000
stack
page read and write
11D0000
heap
page read and write
510000
unkown
page execute and write copy
4A60000
direct allocation
page read and write
E6C000
stack
page read and write
33DF000
stack
page read and write
559E000
stack
page read and write
301F000
stack
page read and write
50C7000
trusted library allocation
page read and write
11FE000
heap
page read and write
F6D000
stack
page read and write
51BE000
stack
page read and write
52FE000
stack
page read and write
4A71000
heap
page read and write
4A71000
heap
page read and write
3F5E000
stack
page read and write
5080000
direct allocation
page execute and read and write
4A71000
heap
page read and write
4EED000
stack
page read and write
3F1F000
stack
page read and write
119A000
heap
page read and write
508E000
stack
page read and write
4A80000
heap
page read and write
431E000
stack
page read and write
2BEE000
stack
page read and write
4A60000
direct allocation
page read and write
1241000
heap
page read and write
3CDE000
stack
page read and write
50A0000
direct allocation
page execute and read and write
491F000
stack
page read and write
4A71000
heap
page read and write
1215000
heap
page read and write
4A71000
heap
page read and write
3E1E000
stack
page read and write
57ED000
stack
page read and write
56ED000
stack
page read and write
379E000
stack
page read and write
4A71000
heap
page read and write
594F000
stack
page read and write
FC0000
heap
page read and write
4A60000
direct allocation
page read and write
3F5000
unkown
page execute and read and write
37DE000
stack
page read and write
1257000
heap
page read and write
201000
unkown
page execute and write copy
4A71000
heap
page read and write
1214000
heap
page read and write
4A71000
heap
page read and write
2BAB000
stack
page read and write
503000
unkown
page execute and read and write
38DF000
stack
page read and write
200000
unkown
page read and write
4A5F000
stack
page read and write
4A71000
heap
page read and write
4A60000
direct allocation
page read and write
4A70000
heap
page read and write
4A60000
direct allocation
page read and write
119E000
heap
page read and write
11FE000
heap
page read and write
315F000
stack
page read and write
42DF000
stack
page read and write
4FA000
unkown
page execute and read and write
11D8000
heap
page read and write
4A60000
direct allocation
page read and write
11F1000
heap
page read and write
11DA000
heap
page read and write
341E000
stack
page read and write
4CF000
unkown
page execute and read and write
5550000
remote allocation
page read and write
1241000
heap
page read and write
1241000
heap
page read and write
125B000
heap
page read and write
543E000
stack
page read and write
111E000
stack
page read and write
4F00000
direct allocation
page read and write
1250000
heap
page read and write
116E000
stack
page read and write
3B5F000
stack
page read and write
5080000
direct allocation
page execute and read and write
5550000
remote allocation
page read and write
4A60000
direct allocation
page read and write
46DE000
stack
page read and write
2E1F000
stack
page read and write
10B0000
heap
page read and write
6B1000
unkown
page execute and read and write
3C9F000
stack
page read and write
2F1F000
stack
page read and write
3B9E000
stack
page read and write
4A71000
heap
page read and write
5050000
direct allocation
page execute and read and write
365F000
stack
page read and write
409E000
stack
page read and write
441F000
stack
page read and write
260000
unkown
page execute and read and write
5090000
direct allocation
page execute and read and write
50B0000
direct allocation
page execute and read and write
10B5000
heap
page read and write
4F3E000
stack
page read and write
11FE000
heap
page read and write
4EB0000
trusted library allocation
page read and write
459E000
stack
page read and write
200000
unkown
page readonly
510000
unkown
page execute and read and write
4A60000
direct allocation
page read and write
419F000
stack
page read and write
11EF000
heap
page read and write
124F000
heap
page read and write
4A71000
heap
page read and write
11DE000
heap
page read and write
481E000
stack
page read and write
41DE000
stack
page read and write
5060000
direct allocation
page execute and read and write
305E000
stack
page read and write
369E000
stack
page read and write
4A60000
direct allocation
page read and write
4A71000
heap
page read and write
319E000
stack
page read and write
5080000
direct allocation
page execute and read and write
10A0000
heap
page read and write
3A5E000
stack
page read and write
1218000
heap
page read and write
351F000
stack
page read and write
1190000
heap
page read and write
4A71000
heap
page read and write
455F000
stack
page read and write
5080000
direct allocation
page execute and read and write
138F000
stack
page read and write
4A60000
direct allocation
page read and write
2BF0000
heap
page read and write
52BD000
stack
page read and write
2C17000
heap
page read and write
4A60000
direct allocation
page read and write
53FF000
stack
page read and write
2B6E000
stack
page read and write
4A60000
direct allocation
page read and write
4A71000
heap
page read and write
3DDF000
stack
page read and write
1218000
heap
page read and write
11D5000
heap
page read and write
503F000
stack
page read and write
11C8000
heap
page read and write
1241000
heap
page read and write
4F00000
direct allocation
page read and write
405F000
stack
page read and write
5080000
direct allocation
page execute and read and write
4A71000
heap
page read and write
5070000
direct allocation
page execute and read and write
4A60000
direct allocation
page read and write
511000
unkown
page execute and write copy
47DF000
stack
page read and write
4A71000
heap
page read and write
4A71000
heap
page read and write
391E000
stack
page read and write
4F00000
direct allocation
page read and write
4A71000
heap
page read and write
469F000
stack
page read and write
3A1F000
stack
page read and write
4A71000
heap
page read and write
1218000
heap
page read and write
11DE000
heap
page read and write
32DE000
stack
page read and write
2D1F000
stack
page read and write
1218000
heap
page read and write
553E000
stack
page read and write
There are 168 hidden memdumps, click here to show them.