IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.stor
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
bathdoomgaz.stor
malicious
dissapoiznw.stor
malicious
spirittunek.stor
malicious
eaglepawnoy.stor
malicious
clearancek.site
malicious
licendfilteo.site
malicious
https://community.akamai.st
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://community.akamai.steamstatic.
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://sergei-esenin.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://avatars.akamai.steamstatic;
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://bathdoomgaz.store:443/apiA
unknown
https://sergei-esenin.com/kI
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4Ok
unknown
https://broadcast.st.dl.ecc
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=l
unknown
https://store.ste
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://steamcommunity.com:443/profiles/76561199724331900
unknown
https://store.steampowered.com/points/shop/
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://community.akamai.steamstatic.com/publi
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://sergei-esenin.com:443/api
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=cdfm
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/as
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://login.steampowered.com/;
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://community.akamai.steamstatic.com/public/shared/ja
unknown
https://medal.tv
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://clearancek.site:443/api
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContentl
unknown
https://steamcommunity.com/workshop/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.a
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=qu55UpguGheU&l=e
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEG
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://store.stea
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://studennotediw.store:443/api
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
http://127.0.0.1:27060
unknown
https://sergei-esenin.com/CI
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_re
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
104.21.53.8
malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
104.21.53.8
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
3F1000
unkown
page execute and read and write
malicious
4FBE000
stack
page read and write
4741000
heap
page read and write
4741000
heap
page read and write
413E000
stack
page read and write
51FF000
stack
page read and write
990000
heap
page read and write
3ABF000
stack
page read and write
50FE000
stack
page read and write
437F000
stack
page read and write
3F1000
unkown
page execute and write copy
2990000
direct allocation
page read and write
EA1000
heap
page read and write
2BBF000
stack
page read and write
E55000
heap
page read and write
397F000
stack
page read and write
2990000
direct allocation
page read and write
550E000
stack
page read and write
2990000
direct allocation
page read and write
35BF000
stack
page read and write
44BF000
stack
page read and write
2E3F000
stack
page read and write
4BC0000
direct allocation
page read and write
89B000
unkown
page execute and write copy
347F000
stack
page read and write
2990000
direct allocation
page read and write
6B7000
unkown
page execute and read and write
EAE000
heap
page read and write
50BF000
stack
page read and write
44FE000
stack
page read and write
E34000
heap
page read and write
4741000
heap
page read and write
E7E000
heap
page read and write
E27000
heap
page read and write
43BE000
stack
page read and write
9F0000
heap
page read and write
2ABF000
stack
page read and write
29B7000
heap
page read and write
4BFE000
stack
page read and write
36FF000
stack
page read and write
116E000
stack
page read and write
2F7F000
stack
page read and write
4D40000
direct allocation
page execute and read and write
4D10000
direct allocation
page execute and read and write
DFA000
heap
page read and write
294E000
stack
page read and write
E82000
heap
page read and write
4CFF000
stack
page read and write
3C3E000
stack
page read and write
337E000
stack
page read and write
3D7E000
stack
page read and write
560F000
stack
page read and write
463E000
stack
page read and write
4741000
heap
page read and write
EAD000
heap
page read and write
4D40000
direct allocation
page execute and read and write
EA1000
heap
page read and write
53AE000
stack
page read and write
4D30000
direct allocation
page execute and read and write
E7E000
heap
page read and write
6FE000
unkown
page execute and write copy
45FF000
stack
page read and write
2E7E000
stack
page read and write
4D20000
direct allocation
page execute and read and write
4741000
heap
page read and write
3BFF000
stack
page read and write
4D40000
direct allocation
page execute and read and write
383F000
stack
page read and write
89A000
unkown
page execute and read and write
4BC0000
direct allocation
page read and write
3E7F000
stack
page read and write
4741000
heap
page read and write
E67000
heap
page read and write
3AFE000
stack
page read and write
323E000
stack
page read and write
4740000
heap
page read and write
4741000
heap
page read and write
3F0000
unkown
page readonly
3EBE000
stack
page read and write
427E000
stack
page read and write
6E6000
unkown
page execute and read and write
535D000
stack
page read and write
4D50000
direct allocation
page execute and read and write
6EE000
unkown
page execute and read and write
4D40000
direct allocation
page execute and read and write
3FBF000
stack
page read and write
2990000
direct allocation
page read and write
298C000
stack
page read and write
35FE000
stack
page read and write
E54000
heap
page read and write
4F7D000
stack
page read and write
E6A000
heap
page read and write
4D4D000
stack
page read and write
387E000
stack
page read and write
4BC0000
direct allocation
page read and write
2990000
direct allocation
page read and write
E3E000
heap
page read and write
5210000
remote allocation
page read and write
2BFE000
stack
page read and write
9A5000
heap
page read and write
39BE000
stack
page read and write
3F0000
unkown
page read and write
E6B000
heap
page read and write
4741000
heap
page read and write
2FBE000
stack
page read and write
333F000
stack
page read and write
E75000
heap
page read and write
2990000
direct allocation
page read and write
2990000
direct allocation
page read and write
E82000
heap
page read and write
4741000
heap
page read and write
34BE000
stack
page read and write
DFE000
heap
page read and write
102F000
stack
page read and write
4D40000
direct allocation
page execute and read and write
5611000
trusted library allocation
page read and write
2D3E000
stack
page read and write
4741000
heap
page read and write
4741000
heap
page read and write
6FD000
unkown
page execute and write copy
2990000
direct allocation
page read and write
DD0000
heap
page read and write
4840000
trusted library allocation
page read and write
E75000
heap
page read and write
30FE000
stack
page read and write
CFD000
stack
page read and write
2CFF000
stack
page read and write
450000
unkown
page execute and read and write
E51000
heap
page read and write
980000
heap
page read and write
4BBD000
stack
page read and write
9A0000
heap
page read and write
4D60000
direct allocation
page execute and read and write
423F000
stack
page read and write
2990000
direct allocation
page read and write
30BF000
stack
page read and write
4741000
heap
page read and write
4741000
heap
page read and write
2990000
direct allocation
page read and write
4741000
heap
page read and write
525E000
stack
page read and write
40FF000
stack
page read and write
EE6000
heap
page read and write
4D70000
direct allocation
page execute and read and write
2990000
direct allocation
page read and write
6FD000
unkown
page execute and read and write
54AE000
stack
page read and write
3D3F000
stack
page read and write
5CF000
unkown
page execute and read and write
DF0000
heap
page read and write
4741000
heap
page read and write
106E000
stack
page read and write
5210000
remote allocation
page read and write
E30000
heap
page read and write
3FFE000
stack
page read and write
4741000
heap
page read and write
4741000
heap
page read and write
473F000
stack
page read and write
E67000
heap
page read and write
373E000
stack
page read and write
31FF000
stack
page read and write
5210000
remote allocation
page read and write
F2E000
stack
page read and write
5610000
trusted library allocation
page read and write
92C000
stack
page read and write
4741000
heap
page read and write
4D40000
direct allocation
page execute and read and write
4E7D000
stack
page read and write
2990000
direct allocation
page read and write
4D86000
trusted library allocation
page read and write
2990000
direct allocation
page read and write
29B0000
heap
page read and write
There are 162 hidden memdumps, click here to show them.