IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.stor
malicious
https://sergei-esenin.com/
unknown
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
https://sergei-esenin.com/s
unknown
malicious
https://sergei-esenin.com:443/api
unknown
malicious
bathdoomgaz.stor
malicious
dissapoiznw.stor
malicious
https://sergei-esenin.com/apiUk
unknown
malicious
https://sergei-esenin.com/3
unknown
malicious
spirittunek.stor
malicious
eaglepawnoy.stor
malicious
clearancek.site
malicious
licendfilteo.site
malicious
https://sergei-esenin.com/mk(F
unknown
malicious
https://sergei-esenin.com/api
172.67.206.204
malicious
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://spirittunek.store/api=k
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://store.steampowered.com/points/shop/
unknown
https://clearancek.site/api
unknown
https://sketchfab.com
unknown
https://dissapoiznw.store/api
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://studennotediw.store/api
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://bathdoomgaz.store/api
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=cdfm
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://licendfilteo.site/api
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=qu55UpguGheU&l=e
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
172.67.206.204
malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
172.67.206.204
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
DB1000
unkown
page execute and read and write
malicious
13E7000
heap
page read and write
3E8F000
stack
page read and write
438F000
stack
page read and write
181C000
heap
page read and write
17F1000
heap
page read and write
4D91000
heap
page read and write
576E000
stack
page read and write
474F000
stack
page read and write
17FE000
heap
page read and write
374E000
stack
page read and write
5AFF000
stack
page read and write
CA5000
heap
page read and write
5370000
direct allocation
page execute and read and write
C00000
heap
page read and write
4D91000
heap
page read and write
4D91000
heap
page read and write
334F000
stack
page read and write
184B000
heap
page read and write
54ED000
stack
page read and write
E10000
unkown
page execute and read and write
384F000
stack
page read and write
53A0000
direct allocation
page execute and read and write
13F0000
direct allocation
page read and write
1810000
heap
page read and write
DB0000
unkown
page readonly
39CE000
stack
page read and write
D90000
heap
page read and write
424F000
stack
page read and write
35CF000
stack
page read and write
34CE000
stack
page read and write
17BE000
heap
page read and write
4D91000
heap
page read and write
1837000
heap
page read and write
AAC000
stack
page read and write
5210000
direct allocation
page read and write
13F0000
direct allocation
page read and write
4C8E000
stack
page read and write
5350000
direct allocation
page execute and read and write
428E000
stack
page read and write
4DA0000
heap
page read and write
DB0000
unkown
page read and write
13DE000
stack
page read and write
CA0000
heap
page read and write
16FF000
stack
page read and write
5370000
direct allocation
page execute and read and write
5370000
direct allocation
page execute and read and write
53BE000
trusted library allocation
page read and write
4D91000
heap
page read and write
520D000
stack
page read and write
13F0000
direct allocation
page read and write
13F0000
direct allocation
page read and write
44CF000
stack
page read and write
3D4F000
stack
page read and write
13F0000
direct allocation
page read and write
4D91000
heap
page read and write
58AD000
stack
page read and write
4A0E000
stack
page read and write
BAD000
stack
page read and write
10B6000
unkown
page execute and write copy
F97000
unkown
page execute and read and write
181C000
heap
page read and write
4C4F000
stack
page read and write
4D91000
heap
page read and write
460F000
stack
page read and write
4D91000
heap
page read and write
488F000
stack
page read and write
4D91000
heap
page read and write
3B0E000
stack
page read and write
177E000
stack
page read and write
5350000
remote allocation
page read and write
1810000
heap
page read and write
C7E000
stack
page read and write
13F0000
direct allocation
page read and write
1790000
direct allocation
page read and write
13F0000
direct allocation
page read and write
3C0F000
stack
page read and write
1252000
unkown
page execute and read and write
5350000
remote allocation
page read and write
17BA000
heap
page read and write
10B7000
unkown
page execute and write copy
4D91000
heap
page read and write
17E8000
heap
page read and write
5370000
direct allocation
page execute and read and write
360E000
stack
page read and write
3ECE000
stack
page read and write
524E000
stack
page read and write
478E000
stack
page read and write
4D91000
heap
page read and write
10B6000
unkown
page execute and read and write
562D000
stack
page read and write
4E90000
trusted library allocation
page read and write
450E000
stack
page read and write
348F000
stack
page read and write
17B0000
heap
page read and write
4D91000
heap
page read and write
586F000
stack
page read and write
17A0000
direct allocation
page execute and read and write
17F1000
heap
page read and write
3C4E000
stack
page read and write
17FE000
heap
page read and write
4D91000
heap
page read and write
49CF000
stack
page read and write
5370000
direct allocation
page execute and read and write
4D90000
heap
page read and write
410F000
stack
page read and write
139E000
stack
page read and write
184B000
heap
page read and write
1889000
heap
page read and write
4B4E000
stack
page read and write
3ACF000
stack
page read and write
55EC000
stack
page read and write
173B000
stack
page read and write
59FE000
stack
page read and write
338E000
stack
page read and write
3FCF000
stack
page read and write
48CE000
stack
page read and write
1837000
heap
page read and write
13F0000
direct allocation
page read and write
C10000
heap
page read and write
5370000
direct allocation
page execute and read and write
43CE000
stack
page read and write
13F0000
direct allocation
page read and write
4D8F000
stack
page read and write
10A7000
unkown
page execute and read and write
4D91000
heap
page read and write
400E000
stack
page read and write
59AE000
stack
page read and write
4D91000
heap
page read and write
13F0000
direct allocation
page read and write
13E0000
heap
page read and write
13F0000
direct allocation
page read and write
5380000
direct allocation
page execute and read and write
17E8000
heap
page read and write
5360000
direct allocation
page execute and read and write
1894000
heap
page read and write
3D8E000
stack
page read and write
324F000
stack
page read and write
370F000
stack
page read and write
4B0F000
stack
page read and write
17F5000
heap
page read and write
1253000
unkown
page execute and write copy
4D91000
heap
page read and write
534F000
stack
page read and write
17E3000
heap
page read and write
1790000
direct allocation
page read and write
4D91000
heap
page read and write
398F000
stack
page read and write
5350000
remote allocation
page read and write
13F0000
direct allocation
page read and write
464E000
stack
page read and write
13F0000
direct allocation
page read and write
54AD000
stack
page read and write
314F000
stack
page read and write
D80000
heap
page read and write
4D91000
heap
page read and write
414E000
stack
page read and write
4D91000
heap
page read and write
388E000
stack
page read and write
10A0000
unkown
page execute and read and write
5390000
direct allocation
page execute and read and write
13F0000
direct allocation
page read and write
135E000
stack
page read and write
DB1000
unkown
page execute and write copy
17F5000
heap
page read and write
1074000
unkown
page execute and read and write
572E000
stack
page read and write
There are 157 hidden memdumps, click here to show them.