IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.stor
malicious
https://sergei-esenin.com/
unknown
malicious
spirittunek.stor
malicious
https://sergei-esenin.com:443/apif
unknown
malicious
eaglepawnoy.stor
malicious
clearancek.site
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
licendfilteo.site
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
bathdoomgaz.stor
malicious
dissapoiznw.stor
malicious
https://sergei-esenin.com/api
172.67.206.204
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=cdfm
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://steamcommunity.com/discussions/
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://store.steampowered.com/stats/
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://clearancek.site:443/api
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://steamcommunity.com/workshop/
unknown
https://eaglepawnoy.store:443/apiG
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=qu55UpguGheU&l=e
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://steamcommunity.com:443/profiles/76561199724331900
unknown
https://store.steampowered.com/points/shop/
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.c
unknown
https://studennotediw.store:443/api
unknown
https://mobbipenju.store:443/api
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://community.akamai.steamstatic.com/public/javascript/modalContent.js?v=f2hMA1v9Zkc8&l=engl
unknown
https://store.steampowered.com/about/
unknown
There are 68 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
172.67.206.204
malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
172.67.206.204
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
401000
unkown
page execute and read and write
malicious
F2C000
stack
page read and write
4D90000
direct allocation
page execute and read and write
504E000
stack
page read and write
300E000
stack
page read and write
3D8F000
stack
page read and write
400000
unkown
page readonly
5ED000
unkown
page execute and read and write
4791000
heap
page read and write
8B0000
unkown
page execute and write copy
E44000
heap
page read and write
478F000
stack
page read and write
401000
unkown
page execute and write copy
418E000
stack
page read and write
F3A000
heap
page read and write
388F000
stack
page read and write
2CCF000
stack
page read and write
E44000
heap
page read and write
2AA0000
direct allocation
page read and write
39CF000
stack
page read and write
4C4E000
stack
page read and write
6CD000
unkown
page execute and read and write
4BD0000
trusted library allocation
page read and write
2A90000
heap
page read and write
38CE000
stack
page read and write
CFD000
stack
page read and write
360F000
stack
page read and write
3B4E000
stack
page read and write
E44000
heap
page read and write
450F000
stack
page read and write
4791000
heap
page read and write
3C8E000
stack
page read and write
460000
unkown
page execute and read and write
DD0000
heap
page read and write
338F000
stack
page read and write
E44000
heap
page read and write
70F000
unkown
page execute and write copy
428F000
stack
page read and write
4791000
heap
page read and write
4ECE000
stack
page read and write
514F000
stack
page read and write
4791000
heap
page read and write
314E000
stack
page read and write
9F0000
heap
page read and write
2AA0000
direct allocation
page read and write
E44000
heap
page read and write
4C00000
remote allocation
page read and write
2FCF000
stack
page read and write
F90000
heap
page read and write
1009000
heap
page read and write
4D90000
direct allocation
page execute and read and write
E44000
heap
page read and write
2A0E000
stack
page read and write
4C10000
direct allocation
page read and write
551D000
stack
page read and write
2A8E000
stack
page read and write
2AA0000
direct allocation
page read and write
4DA0000
direct allocation
page execute and read and write
E44000
heap
page read and write
FC0000
heap
page read and write
FFC000
heap
page read and write
E44000
heap
page read and write
E44000
heap
page read and write
E44000
heap
page read and write
328E000
stack
page read and write
E44000
heap
page read and write
4D60000
direct allocation
page execute and read and write
F3E000
heap
page read and write
4D4F000
stack
page read and write
364E000
stack
page read and write
E44000
heap
page read and write
E44000
heap
page read and write
2AA0000
direct allocation
page read and write
4DB0000
direct allocation
page execute and read and write
404E000
stack
page read and write
F70000
heap
page read and write
500D000
stack
page read and write
FF7000
heap
page read and write
2AA0000
direct allocation
page read and write
4D90000
direct allocation
page execute and read and write
2AC7000
heap
page read and write
FBC000
heap
page read and write
3DCD000
stack
page read and write
3ECF000
stack
page read and write
E44000
heap
page read and write
F75000
heap
page read and write
42CE000
stack
page read and write
2AA0000
direct allocation
page read and write
53CE000
stack
page read and write
E44000
heap
page read and write
E44000
heap
page read and write
4791000
heap
page read and write
F93000
heap
page read and write
52CD000
stack
page read and write
F30000
heap
page read and write
468E000
stack
page read and write
4D70000
direct allocation
page execute and read and write
528E000
stack
page read and write
2AA0000
direct allocation
page read and write
2AA0000
direct allocation
page read and write
E44000
heap
page read and write
2DCF000
stack
page read and write
E44000
heap
page read and write
454E000
stack
page read and write
3F0E000
stack
page read and write
4C00000
remote allocation
page read and write
F7E000
heap
page read and write
FC0000
heap
page read and write
4791000
heap
page read and write
541D000
stack
page read and write
2AA0000
direct allocation
page read and write
E8E000
stack
page read and write
310F000
stack
page read and write
F84000
heap
page read and write
3B0F000
stack
page read and write
4790000
heap
page read and write
E44000
heap
page read and write
464F000
stack
page read and write
414F000
stack
page read and write
2AC0000
heap
page read and write
E40000
heap
page read and write
4C10000
direct allocation
page read and write
2BCF000
stack
page read and write
2AA0000
direct allocation
page read and write
440E000
stack
page read and write
3A0E000
stack
page read and write
E44000
heap
page read and write
4DD5000
trusted library allocation
page read and write
374F000
stack
page read and write
E44000
heap
page read and write
E3E000
stack
page read and write
2ECF000
stack
page read and write
122E000
stack
page read and write
EEE000
stack
page read and write
567F000
stack
page read and write
3C4F000
stack
page read and write
4BD0000
heap
page read and write
378E000
stack
page read and write
FF7000
heap
page read and write
2AA0000
direct allocation
page read and write
701000
unkown
page execute and read and write
E44000
heap
page read and write
4D90000
direct allocation
page execute and read and write
4DC0000
direct allocation
page execute and read and write
4D9E000
stack
page read and write
518E000
stack
page read and write
2AA0000
direct allocation
page read and write
4C00000
remote allocation
page read and write
E44000
heap
page read and write
2AA0000
direct allocation
page read and write
400F000
stack
page read and write
33CE000
stack
page read and write
47A0000
heap
page read and write
4791000
heap
page read and write
4C10000
direct allocation
page read and write
4D90000
direct allocation
page execute and read and write
4F0D000
stack
page read and write
4791000
heap
page read and write
6F9000
unkown
page execute and read and write
FBC000
heap
page read and write
F67000
heap
page read and write
350E000
stack
page read and write
E44000
heap
page read and write
2AA0000
direct allocation
page read and write
112F000
stack
page read and write
4D90000
direct allocation
page execute and read and write
E44000
heap
page read and write
34CF000
stack
page read and write
324F000
stack
page read and write
4D80000
direct allocation
page execute and read and write
8AF000
unkown
page execute and read and write
557E000
stack
page read and write
2A4E000
stack
page read and write
400000
unkown
page read and write
43CF000
stack
page read and write
4791000
heap
page read and write
70F000
unkown
page execute and read and write
710000
unkown
page execute and write copy
99C000
stack
page read and write
There are 169 hidden memdumps, click here to show them.