IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.stor
malicious
spirittunek.stor
malicious
eaglepawnoy.stor
malicious
clearancek.site
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
licendfilteo.site
malicious
bathdoomgaz.stor
malicious
dissapoiznw.stor
malicious
https://steamcommunity.com/my/wishlist/
unknown
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://recaptcha.net/recaptcha/;
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://steamcommunity.com/discussions/
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/fatalerror.css?v=wctRWaBvNt2z&l=engli
unknown
https://store.steampowered.com/stats/
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=AeTz
unknown
https://s.ytimg.com;
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://store.steampowered.com/points/shop/
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://steamcommunity.com
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
There are 71 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
21000
unkown
page execute and read and write
malicious
2BAF000
stack
page read and write
39AE000
stack
page read and write
4601000
heap
page read and write
4A90000
direct allocation
page read and write
36EF000
stack
page read and write
3BEF000
stack
page read and write
45F0000
direct allocation
page read and write
4C10000
direct allocation
page execute and read and write
3D2E000
stack
page read and write
4601000
heap
page read and write
E96000
heap
page read and write
4601000
heap
page read and write
2E2F000
stack
page read and write
E54000
heap
page read and write
45F0000
direct allocation
page read and write
80000
unkown
page execute and read and write
20000
unkown
page read and write
3D6E000
stack
page read and write
4C10000
direct allocation
page execute and read and write
80000
unkown
page execute and read and write
3FEE000
stack
page read and write
3E6F000
stack
page read and write
336E000
stack
page read and write
4D4C000
stack
page read and write
7FC000
stack
page read and write
20F000
unkown
page execute and read and write
4601000
heap
page read and write
422F000
stack
page read and write
B50000
heap
page read and write
3FAF000
stack
page read and write
E7E000
heap
page read and write
2FAE000
stack
page read and write
E58000
heap
page read and write
45F0000
direct allocation
page read and write
4E8E000
stack
page read and write
4FCE000
stack
page read and write
4C10000
direct allocation
page execute and read and write
44EE000
stack
page read and write
34AE000
stack
page read and write
2830000
heap
page read and write
4610000
heap
page read and write
21000
unkown
page execute and write copy
E5A000
heap
page read and write
E7E000
heap
page read and write
4601000
heap
page read and write
4C10000
direct allocation
page execute and read and write
E5F000
heap
page read and write
E1E000
heap
page read and write
45F0000
direct allocation
page read and write
50CF000
stack
page read and write
4601000
heap
page read and write
CA5000
heap
page read and write
4BF0000
direct allocation
page execute and read and write
2D2E000
stack
page read and write
2E6E000
stack
page read and write
AFD000
stack
page read and write
30EE000
stack
page read and write
4F8E000
stack
page read and write
E71000
heap
page read and write
4601000
heap
page read and write
539F000
stack
page read and write
21000
unkown
page execute and write copy
4601000
heap
page read and write
2CEF000
stack
page read and write
2BEE000
stack
page read and write
4601000
heap
page read and write
2A6F000
stack
page read and write
50E0000
remote allocation
page read and write
3AAF000
stack
page read and write
4A90000
direct allocation
page read and write
4E4D000
stack
page read and write
EA5000
heap
page read and write
44AF000
stack
page read and write
C9E000
stack
page read and write
45F0000
direct allocation
page read and write
DAF000
stack
page read and write
45F0000
direct allocation
page read and write
E96000
heap
page read and write
45F0000
direct allocation
page read and write
45F0000
direct allocation
page read and write
4BCF000
stack
page read and write
4C40000
direct allocation
page execute and read and write
4601000
heap
page read and write
346F000
stack
page read and write
522D000
stack
page read and write
E71000
heap
page read and write
412E000
stack
page read and write
30AF000
stack
page read and write
4C20000
direct allocation
page execute and read and write
2F6F000
stack
page read and write
E5F000
heap
page read and write
3EAE000
stack
page read and write
45F0000
direct allocation
page read and write
50E0000
remote allocation
page read and write
27EE000
stack
page read and write
E1A000
heap
page read and write
33A000
unkown
page execute and write copy
329000
unkown
page execute and read and write
529E000
stack
page read and write
436F000
stack
page read and write
45F0000
direct allocation
page read and write
4C5D000
trusted library allocation
page read and write
4600000
heap
page read and write
CA0000
heap
page read and write
4BE0000
direct allocation
page execute and read and write
3C2E000
stack
page read and write
386E000
stack
page read and write
4A40000
trusted library allocation
page read and write
282C000
stack
page read and write
31EF000
stack
page read and write
4601000
heap
page read and write
E56000
heap
page read and write
E7E000
heap
page read and write
339000
unkown
page execute and write copy
4C10000
direct allocation
page execute and read and write
45EF000
stack
page read and write
20000
unkown
page readonly
20F000
unkown
page execute and read and write
2867000
heap
page read and write
45F0000
direct allocation
page read and write
C30000
heap
page read and write
E73000
heap
page read and write
382F000
stack
page read and write
4601000
heap
page read and write
E8D000
heap
page read and write
2840000
heap
page read and write
4601000
heap
page read and write
4C30000
direct allocation
page execute and read and write
2860000
heap
page read and write
296F000
stack
page read and write
E8D000
heap
page read and write
396F000
stack
page read and write
332F000
stack
page read and write
50E0000
remote allocation
page read and write
4601000
heap
page read and write
321000
unkown
page execute and read and write
2F5000
unkown
page execute and read and write
2AAE000
stack
page read and write
EDF000
heap
page read and write
4601000
heap
page read and write
EE5000
heap
page read and write
DFE000
stack
page read and write
4ACE000
stack
page read and write
E8D000
heap
page read and write
4A7D000
stack
page read and write
45F0000
direct allocation
page read and write
4A90000
direct allocation
page read and write
4DF000
unkown
page execute and read and write
3AEE000
stack
page read and write
EA4000
heap
page read and write
4E0000
unkown
page execute and write copy
4601000
heap
page read and write
4C10000
direct allocation
page execute and read and write
35AF000
stack
page read and write
E48000
heap
page read and write
27AF000
stack
page read and write
40EF000
stack
page read and write
372E000
stack
page read and write
E10000
heap
page read and write
426E000
stack
page read and write
43AE000
stack
page read and write
322E000
stack
page read and write
4601000
heap
page read and write
4601000
heap
page read and write
4C00000
direct allocation
page execute and read and write
512D000
stack
page read and write
4601000
heap
page read and write
4C1D000
stack
page read and write
45F0000
direct allocation
page read and write
339000
unkown
page execute and read and write
35EE000
stack
page read and write
45F0000
direct allocation
page read and write
E96000
heap
page read and write
E74000
heap
page read and write
There are 165 hidden memdumps, click here to show them.