IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.stor
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
bathdoomgaz.stor
malicious
dissapoiznw.stor
malicious
spirittunek.stor
malicious
eaglepawnoy.stor
malicious
clearancek.site
malicious
licendfilteo.site
malicious
https://sergei-esenin.com/api
172.67.206.204
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://steamcommunity.com/p
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://store.steampowered.com/points/shop/
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstatic.com/pub
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://avatars.akamai.steamstatic
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://steamcommunity.com/r(I/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=cdfm
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
https://sergei-esenin.com/8
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://steamcommunity.com/discussions/
unknown
https://sergei-esenin.com/apiA
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=qu55UpguGheU&l=e
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalContent.js?v=f2hMA1v9Zkc8&l=engl
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
172.67.206.204
malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
172.67.206.204
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
531000
unkown
page execute and read and write
malicious
821000
unkown
page execute and read and write
AB4000
heap
page read and write
B93000
heap
page read and write
4431000
heap
page read and write
3E2E000
stack
page read and write
AB4000
heap
page read and write
28EE000
stack
page read and write
1F0000
heap
page read and write
2690000
direct allocation
page read and write
AB4000
heap
page read and write
B3E000
heap
page read and write
531000
unkown
page execute and write copy
BA8000
heap
page read and write
BF8000
heap
page read and write
432E000
stack
page read and write
4BBD000
stack
page read and write
406F000
stack
page read and write
4530000
trusted library allocation
page read and write
2690000
direct allocation
page read and write
28AF000
stack
page read and write
2690000
direct allocation
page read and write
4A50000
direct allocation
page execute and read and write
590000
unkown
page execute and read and write
4431000
heap
page read and write
264E000
stack
page read and write
AB4000
heap
page read and write
48B0000
remote allocation
page read and write
AB4000
heap
page read and write
BEE000
heap
page read and write
4A40000
direct allocation
page execute and read and write
316F000
stack
page read and write
AB4000
heap
page read and write
4F7D000
stack
page read and write
4E3E000
stack
page read and write
4A8B000
trusted library allocation
page read and write
26A7000
heap
page read and write
50EE000
stack
page read and write
507E000
stack
page read and write
AB4000
heap
page read and write
4431000
heap
page read and write
366F000
stack
page read and write
B75000
heap
page read and write
2690000
direct allocation
page read and write
B3A000
heap
page read and write
4F3E000
stack
page read and write
AB4000
heap
page read and write
2B2F000
stack
page read and write
48B0000
remote allocation
page read and write
BEC000
heap
page read and write
48C0000
direct allocation
page read and write
342E000
stack
page read and write
2DEE000
stack
page read and write
4A4E000
stack
page read and write
4431000
heap
page read and write
7EF000
unkown
page execute and read and write
2690000
direct allocation
page read and write
836000
unkown
page execute and write copy
4A40000
direct allocation
page execute and read and write
2690000
direct allocation
page read and write
AB4000
heap
page read and write
AB4000
heap
page read and write
19C000
stack
page read and write
4A70000
direct allocation
page execute and read and write
2690000
direct allocation
page read and write
2C6F000
stack
page read and write
BAF000
heap
page read and write
B73000
heap
page read and write
27AF000
stack
page read and write
2DAF000
stack
page read and write
48C0000
direct allocation
page read and write
4A60000
direct allocation
page execute and read and write
2690000
direct allocation
page read and write
48B0000
remote allocation
page read and write
AB4000
heap
page read and write
B7E000
heap
page read and write
48C0000
direct allocation
page read and write
2690000
direct allocation
page read and write
BA8000
heap
page read and write
392E000
stack
page read and write
AB4000
heap
page read and write
4431000
heap
page read and write
BEE000
heap
page read and write
AB0000
heap
page read and write
BF8000
heap
page read and write
42EF000
stack
page read and write
302F000
stack
page read and write
31AE000
stack
page read and write
B68000
heap
page read and write
48FE000
stack
page read and write
BAE000
heap
page read and write
2690000
direct allocation
page read and write
2690000
direct allocation
page read and write
4431000
heap
page read and write
4B7D000
stack
page read and write
2A2E000
stack
page read and write
837000
unkown
page execute and write copy
B91000
heap
page read and write
4DFF000
stack
page read and write
AB4000
heap
page read and write
B30000
heap
page read and write
AB4000
heap
page read and write
352F000
stack
page read and write
4CBD000
stack
page read and write
715000
unkown
page execute and read and write
2690000
direct allocation
page read and write
32EE000
stack
page read and write
3DEF000
stack
page read and write
41EE000
stack
page read and write
AB4000
heap
page read and write
AB4000
heap
page read and write
BB8000
heap
page read and write
36AE000
stack
page read and write
AB4000
heap
page read and write
AB4000
heap
page read and write
3A6E000
stack
page read and write
B94000
heap
page read and write
BA8000
heap
page read and write
4431000
heap
page read and write
B20000
heap
page read and write
530000
unkown
page readonly
530000
unkown
page read and write
B93000
heap
page read and write
836000
unkown
page execute and read and write
3A2F000
stack
page read and write
306E000
stack
page read and write
49FF000
stack
page read and write
BAF000
heap
page read and write
D2F000
stack
page read and write
500000
heap
page read and write
4431000
heap
page read and write
268C000
stack
page read and write
2690000
direct allocation
page read and write
3BAE000
stack
page read and write
38EF000
stack
page read and write
4A20000
direct allocation
page execute and read and write
442F000
stack
page read and write
4430000
heap
page read and write
3CAF000
stack
page read and write
41AF000
stack
page read and write
32AF000
stack
page read and write
2B6E000
stack
page read and write
4A40000
direct allocation
page execute and read and write
AB4000
heap
page read and write
40AE000
stack
page read and write
4431000
heap
page read and write
E6F000
stack
page read and write
9D0000
unkown
page execute and read and write
4440000
heap
page read and write
51EF000
stack
page read and write
829000
unkown
page execute and read and write
4870000
heap
page read and write
AFE000
stack
page read and write
29EF000
stack
page read and write
37EE000
stack
page read and write
4A30000
direct allocation
page execute and read and write
4431000
heap
page read and write
4FD000
stack
page read and write
3F6E000
stack
page read and write
AB4000
heap
page read and write
4A40000
direct allocation
page execute and read and write
2EEF000
stack
page read and write
37AF000
stack
page read and write
D6E000
stack
page read and write
4A10000
direct allocation
page execute and read and write
356E000
stack
page read and write
AB4000
heap
page read and write
2F2E000
stack
page read and write
AB4000
heap
page read and write
3B6F000
stack
page read and write
4A40000
direct allocation
page execute and read and write
AB4000
heap
page read and write
BF3000
heap
page read and write
AB4000
heap
page read and write
4CFE000
stack
page read and write
AB4000
heap
page read and write
4A40000
direct allocation
page execute and read and write
2690000
direct allocation
page read and write
2CAE000
stack
page read and write
3F2F000
stack
page read and write
BF9000
heap
page read and write
33EF000
stack
page read and write
26A0000
heap
page read and write
3CEE000
stack
page read and write
There are 174 hidden memdumps, click here to show them.