IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.stor
malicious
spirittunek.stor
malicious
eaglepawnoy.stor
malicious
clearancek.site
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
licendfilteo.site
malicious
bathdoomgaz.stor
malicious
dissapoiznw.stor
malicious
https://steamcommunity.com/my/wishlist/
unknown
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=cdfm
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://steamcommunity.com/1
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://recaptcha.net/recaptcha/;
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://steamcommunity.com/discussions/
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/fatalerror.css?v=wctRWaBvNt2z&l=engli
unknown
https://store.steampowered.com/stats/
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://steamcommunity.com/q
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://store.steampowered.com/points/shop/
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://steamcommunity.com
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
There are 73 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
241000
unkown
page execute and read and write
malicious
521E000
stack
page read and write
4751000
heap
page read and write
35FE000
stack
page read and write
4850000
trusted library allocation
page read and write
296E000
stack
page read and write
F30000
heap
page read and write
511E000
stack
page read and write
FB4000
heap
page read and write
31FF000
stack
page read and write
3E7E000
stack
page read and write
473F000
stack
page read and write
4751000
heap
page read and write
108E000
stack
page read and write
2A6F000
stack
page read and write
528E000
stack
page read and write
4BCD000
stack
page read and write
2ABB000
stack
page read and write
4751000
heap
page read and write
387E000
stack
page read and write
44FE000
stack
page read and write
4740000
direct allocation
page read and write
9A0000
heap
page read and write
FB1000
heap
page read and write
F8E000
heap
page read and write
5230000
remote allocation
page read and write
428000
unkown
page execute and read and write
FDB000
heap
page read and write
4740000
direct allocation
page read and write
2FBE000
stack
page read and write
FCA000
heap
page read and write
45FF000
stack
page read and write
94C000
stack
page read and write
44BF000
stack
page read and write
36FF000
stack
page read and write
3D7E000
stack
page read and write
2D3E000
stack
page read and write
F89000
heap
page read and write
427E000
stack
page read and write
4D60000
direct allocation
page execute and read and write
383F000
stack
page read and write
373E000
stack
page read and write
2E7E000
stack
page read and write
549000
unkown
page execute and read and write
4D6D000
stack
page read and write
9B0000
heap
page read and write
4751000
heap
page read and write
F9B000
heap
page read and write
4751000
heap
page read and write
FB1000
heap
page read and write
4D70000
direct allocation
page execute and read and write
241000
unkown
page execute and write copy
DD0000
heap
page read and write
40FF000
stack
page read and write
F1F000
stack
page read and write
4D80000
direct allocation
page execute and read and write
4751000
heap
page read and write
50DF000
stack
page read and write
3D3F000
stack
page read and write
3FFE000
stack
page read and write
34BE000
stack
page read and write
FDD000
heap
page read and write
FCA000
heap
page read and write
54EF000
stack
page read and write
4740000
direct allocation
page read and write
2E3F000
stack
page read and write
347F000
stack
page read and write
4D90000
direct allocation
page execute and read and write
4D60000
direct allocation
page execute and read and write
5230000
remote allocation
page read and write
3BFF000
stack
page read and write
323E000
stack
page read and write
2A77000
heap
page read and write
4BE0000
direct allocation
page read and write
4740000
direct allocation
page read and write
30FE000
stack
page read and write
4751000
heap
page read and write
397F000
stack
page read and write
50E000
unkown
page execute and read and write
4751000
heap
page read and write
4751000
heap
page read and write
4751000
heap
page read and write
4751000
heap
page read and write
FA0000
heap
page read and write
2BFE000
stack
page read and write
4740000
direct allocation
page read and write
4740000
direct allocation
page read and write
240000
unkown
page read and write
558000
unkown
page execute and write copy
4740000
direct allocation
page read and write
F99000
heap
page read and write
43BE000
stack
page read and write
FDD000
heap
page read and write
337E000
stack
page read and write
53EE000
stack
page read and write
53F000
unkown
page execute and read and write
2A0000
unkown
page execute and read and write
463E000
stack
page read and write
4D60000
direct allocation
page execute and read and write
1019000
heap
page read and write
4740000
direct allocation
page read and write
4751000
heap
page read and write
4751000
heap
page read and write
4740000
direct allocation
page read and write
4740000
direct allocation
page read and write
F93000
heap
page read and write
437F000
stack
page read and write
4F9D000
stack
page read and write
4D60000
direct allocation
page execute and read and write
4740000
direct allocation
page read and write
4D60000
direct allocation
page execute and read and write
4750000
heap
page read and write
3C3E000
stack
page read and write
4740000
direct allocation
page read and write
F20000
heap
page read and write
2A70000
heap
page read and write
DD5000
heap
page read and write
423F000
stack
page read and write
333F000
stack
page read and write
4740000
direct allocation
page read and write
4751000
heap
page read and write
35BF000
stack
page read and write
F5E000
heap
page read and write
3FBF000
stack
page read and write
2F7F000
stack
page read and write
118E000
stack
page read and write
4E9E000
stack
page read and write
FCA000
heap
page read and write
F5A000
heap
page read and write
4751000
heap
page read and write
6FE000
unkown
page execute and read and write
4751000
heap
page read and write
413E000
stack
page read and write
4D50000
direct allocation
page execute and read and write
4D1F000
stack
page read and write
240000
unkown
page readonly
4FDE000
stack
page read and write
CFD000
stack
page read and write
4D60000
direct allocation
page execute and read and write
557000
unkown
page execute and write copy
4D40000
direct allocation
page execute and read and write
30BF000
stack
page read and write
4751000
heap
page read and write
4C1E000
stack
page read and write
39BE000
stack
page read and write
FDA000
heap
page read and write
3AFE000
stack
page read and write
1014000
heap
page read and write
4751000
heap
page read and write
FDD000
heap
page read and write
2BBF000
stack
page read and write
538D000
stack
page read and write
4751000
heap
page read and write
4BE0000
direct allocation
page read and write
5230000
remote allocation
page read and write
4D30000
direct allocation
page execute and read and write
4DA2000
trusted library allocation
page read and write
E1E000
stack
page read and write
4BE0000
direct allocation
page read and write
4740000
direct allocation
page read and write
2CFF000
stack
page read and write
3EBE000
stack
page read and write
F96000
heap
page read and write
557000
unkown
page execute and read and write
3ABF000
stack
page read and write
FDD000
heap
page read and write
FA0000
heap
page read and write
4760000
heap
page read and write
FB3000
heap
page read and write
F50000
heap
page read and write
There are 160 hidden memdumps, click here to show them.