IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.stor
malicious
spirittunek.stor
malicious
eaglepawnoy.stor
malicious
clearancek.site
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
licendfilteo.site
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
bathdoomgaz.stor
malicious
dissapoiznw.stor
malicious
https://sergei-esenin.com/api
172.67.206.204
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://mobbipenju.store:443/api2
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://steamcommunity.com/discussions/
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=9yzMGndrVfY4&l=e
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://store.steampowered.com/stats/
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://studennotediw.store:443/api:A
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=AeTz
unknown
https://steamcommunity.com/workshop/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://licendfilteo.site:443/api
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://steamcommunity.com:443/profiles/76561199724331900
unknown
https://store.steampowered.com/points/shop/
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://sergei-esenin.com/apiJ4~
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://sergei-esenin.com:443/api
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://spirittunek.store:443/api
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://sergei-esenin.com/Z4~
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://community.akamai.steamstatic.com/public/javascript/modalContent.js?v=f2hMA1v9Zkc8&l=engl
unknown
https://store.steampowered.com/about/
unknown
There are 69 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
172.67.206.204
malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
172.67.206.204
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
F91000
unkown
page execute and read and write
malicious
2A97000
heap
page read and write
A99000
heap
page read and write
341F000
stack
page read and write
46DF000
stack
page read and write
1181000
unkown
page execute and read and write
4D14000
trusted library allocation
page read and write
A30000
direct allocation
page read and write
3BDE000
stack
page read and write
1264000
unkown
page execute and read and write
521D000
stack
page read and write
FF0000
unkown
page execute and read and write
B26000
heap
page read and write
8C4000
heap
page read and write
2B9F000
stack
page read and write
12AB000
unkown
page execute and write copy
4E4D000
stack
page read and write
46E1000
heap
page read and write
4CE0000
direct allocation
page execute and read and write
4CA0000
direct allocation
page execute and read and write
55BF000
stack
page read and write
50CE000
stack
page read and write
508F000
stack
page read and write
A30000
direct allocation
page read and write
4B20000
trusted library allocation
page read and write
8C4000
heap
page read and write
840000
heap
page read and write
A30000
direct allocation
page read and write
8C4000
heap
page read and write
46E1000
heap
page read and write
AAE000
heap
page read and write
46E1000
heap
page read and write
B0E000
heap
page read and write
445F000
stack
page read and write
1452000
unkown
page execute and read and write
46E1000
heap
page read and write
9CF000
stack
page read and write
31DE000
stack
page read and write
421E000
stack
page read and write
4CC0000
direct allocation
page execute and read and write
8C4000
heap
page read and write
3E1F000
stack
page read and write
4CD0000
direct allocation
page execute and read and write
8C4000
heap
page read and write
3CDF000
stack
page read and write
355F000
stack
page read and write
8C0000
heap
page read and write
8C4000
heap
page read and write
46E0000
heap
page read and write
8C4000
heap
page read and write
A30000
direct allocation
page read and write
A4A000
heap
page read and write
3A5F000
stack
page read and write
46E1000
heap
page read and write
3E5E000
stack
page read and write
3A9E000
stack
page read and write
319F000
stack
page read and write
40DE000
stack
page read and write
45DE000
stack
page read and write
AA2000
heap
page read and write
4CF0000
direct allocation
page execute and read and write
54BE000
stack
page read and write
545D000
stack
page read and write
37DF000
stack
page read and write
1292000
unkown
page execute and read and write
4F8E000
stack
page read and write
4CD0000
direct allocation
page execute and read and write
4CDD000
stack
page read and write
4B50000
remote allocation
page read and write
A30000
direct allocation
page read and write
A20000
heap
page read and write
1453000
unkown
page execute and write copy
46E1000
heap
page read and write
8C4000
heap
page read and write
391F000
stack
page read and write
2E1E000
stack
page read and write
449E000
stack
page read and write
3F9E000
stack
page read and write
4CD0000
direct allocation
page execute and read and write
4B50000
remote allocation
page read and write
8C4000
heap
page read and write
8AE000
stack
page read and write
8C4000
heap
page read and write
381E000
stack
page read and write
46F0000
heap
page read and write
A30000
direct allocation
page read and write
2A90000
heap
page read and write
46E1000
heap
page read and write
AC1000
heap
page read and write
8C4000
heap
page read and write
4CD0000
direct allocation
page execute and read and write
4B50000
remote allocation
page read and write
73D000
stack
page read and write
F90000
unkown
page read and write
8C4000
heap
page read and write
8C4000
heap
page read and write
A30000
direct allocation
page read and write
46E1000
heap
page read and write
51CE000
stack
page read and write
A30000
direct allocation
page read and write
A30000
direct allocation
page read and write
2A9C000
heap
page read and write
395E000
stack
page read and write
63C000
stack
page read and write
3F5F000
stack
page read and write
A86000
heap
page read and write
4CD0000
direct allocation
page execute and read and write
2C9F000
stack
page read and write
369F000
stack
page read and write
A30000
direct allocation
page read and write
B19000
heap
page read and write
4CB0000
direct allocation
page execute and read and write
2A80000
direct allocation
page read and write
409F000
stack
page read and write
8C4000
heap
page read and write
431F000
stack
page read and write
A84000
heap
page read and write
2CDE000
stack
page read and write
12AA000
unkown
page execute and read and write
435E000
stack
page read and write
531E000
stack
page read and write
8C4000
heap
page read and write
F0E000
stack
page read and write
2DDF000
stack
page read and write
345E000
stack
page read and write
2A80000
direct allocation
page read and write
46E1000
heap
page read and write
331E000
stack
page read and write
A4E000
heap
page read and write
A30000
direct allocation
page read and write
F8E000
stack
page read and write
8C4000
heap
page read and write
129B000
unkown
page execute and read and write
4B20000
heap
page read and write
A40000
heap
page read and write
359E000
stack
page read and write
A0E000
stack
page read and write
309E000
stack
page read and write
A30000
direct allocation
page read and write
12AA000
unkown
page execute and write copy
4CD0000
direct allocation
page execute and read and write
4F4D000
stack
page read and write
F91000
unkown
page execute and write copy
A79000
heap
page read and write
8C4000
heap
page read and write
F90000
unkown
page readonly
3D1E000
stack
page read and write
535E000
stack
page read and write
AC7000
heap
page read and write
2F5E000
stack
page read and write
F4B000
stack
page read and write
41DF000
stack
page read and write
459F000
stack
page read and write
4D00000
direct allocation
page execute and read and write
8C4000
heap
page read and write
8C4000
heap
page read and write
4B60000
direct allocation
page read and write
760000
heap
page read and write
8C4000
heap
page read and write
4B9E000
stack
page read and write
A96000
heap
page read and write
3B9F000
stack
page read and write
8C4000
heap
page read and write
4E0E000
stack
page read and write
8C4000
heap
page read and write
A8F000
heap
page read and write
2F1F000
stack
page read and write
8C4000
heap
page read and write
2A6F000
stack
page read and write
305F000
stack
page read and write
8C4000
heap
page read and write
8C4000
heap
page read and write
A30000
direct allocation
page read and write
32DF000
stack
page read and write
A30000
direct allocation
page read and write
36DE000
stack
page read and write
296F000
stack
page read and write
4C9F000
stack
page read and write
There are 168 hidden memdumps, click here to show them.