IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.stor
malicious
https://sergei-esenin.com/
unknown
malicious
mobbipenju.stor
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://sergei-esenin.com/p
unknown
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
https://sergei-esenin.com:443/apifiles/76561199724331900
unknown
malicious
https://sergei-esenin.com/g
unknown
malicious
https://sergei-esenin.com/_
unknown
malicious
bathdoomgaz.stor
malicious
dissapoiznw.stor
malicious
https://sergei-esenin.com/apih
unknown
malicious
spirittunek.stor
malicious
eaglepawnoy.stor
malicious
clearancek.site
malicious
https://sergei-esenin.com/api?e
unknown
malicious
https://sergei-esenin.com/api$
unknown
malicious
licendfilteo.site
malicious
https://sergei-esenin.com/api
172.67.206.204
malicious
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://store.steampowered.com/points/shop/
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://avatars.akamai.steamstatic
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=cdfm
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=qu55UpguGheU&l=e
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
172.67.206.204
malicious
licendfilteo.site
unknown
malicious
clearancek.site
unknown
malicious
steamcommunity.com
104.102.49.254
eaglepawnoy.store
unknown
bathdoomgaz.store
unknown
spirittunek.store
unknown
studennotediw.store
unknown
mobbipenju.store
unknown
dissapoiznw.store
unknown

IPs

IP
Domain
Country
Malicious
172.67.206.204
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
781000
unkown
page execute and read and write
malicious
1104000
heap
page read and write
3A3F000
stack
page read and write
3F3F000
stack
page read and write
C23000
unkown
page execute and read and write
1207000
heap
page read and write
498E000
stack
page read and write
3E3E000
stack
page read and write
1104000
heap
page read and write
4AA1000
heap
page read and write
4A90000
direct allocation
page read and write
50F8000
trusted library allocation
page read and write
4AA1000
heap
page read and write
32FE000
stack
page read and write
1104000
heap
page read and write
4AA1000
heap
page read and write
1104000
heap
page read and write
55AF000
stack
page read and write
506F000
stack
page read and write
11E8000
heap
page read and write
51ED000
stack
page read and write
2E7F000
stack
page read and write
7E0000
unkown
page execute and read and write
50B0000
direct allocation
page execute and read and write
4F30000
direct allocation
page read and write
11D3000
heap
page read and write
407F000
stack
page read and write
4A90000
direct allocation
page read and write
A7A000
unkown
page execute and read and write
1104000
heap
page read and write
1104000
heap
page read and write
DBD000
stack
page read and write
367F000
stack
page read and write
343E000
stack
page read and write
50A0000
direct allocation
page execute and read and write
2CEB000
stack
page read and write
480F000
stack
page read and write
1104000
heap
page read and write
11B2000
heap
page read and write
3A7E000
stack
page read and write
50B0000
direct allocation
page execute and read and write
55ED000
stack
page read and write
4A90000
direct allocation
page read and write
443F000
stack
page read and write
11F2000
heap
page read and write
357E000
stack
page read and write
1259000
heap
page read and write
1170000
heap
page read and write
11F2000
heap
page read and write
317F000
stack
page read and write
1104000
heap
page read and write
5090000
direct allocation
page execute and read and write
1104000
heap
page read and write
4F30000
direct allocation
page read and write
40BE000
stack
page read and write
2D77000
heap
page read and write
11F2000
heap
page read and write
3BBE000
stack
page read and write
A72000
unkown
page execute and read and write
1104000
heap
page read and write
494F000
stack
page read and write
A88000
unkown
page execute and read and write
470E000
stack
page read and write
32BF000
stack
page read and write
1104000
heap
page read and write
522E000
stack
page read and write
10F0000
heap
page read and write
11D0000
heap
page read and write
4AA1000
heap
page read and write
433E000
stack
page read and write
4AA1000
heap
page read and write
536E000
stack
page read and write
C24000
unkown
page execute and write copy
50B0000
direct allocation
page execute and read and write
1104000
heap
page read and write
1104000
heap
page read and write
41FE000
stack
page read and write
4F20000
remote allocation
page read and write
2D70000
heap
page read and write
4AA1000
heap
page read and write
585F000
stack
page read and write
3CBF000
stack
page read and write
307F000
stack
page read and write
4AA1000
heap
page read and write
116E000
stack
page read and write
11BE000
heap
page read and write
CBC000
stack
page read and write
1104000
heap
page read and write
4AA0000
heap
page read and write
3B7F000
stack
page read and write
1104000
heap
page read and write
A88000
unkown
page execute and write copy
1104000
heap
page read and write
37FE000
stack
page read and write
4F6E000
stack
page read and write
54AE000
stack
page read and write
484E000
stack
page read and write
589E000
stack
page read and write
56EE000
stack
page read and write
50BD000
stack
page read and write
1215000
heap
page read and write
4EE0000
heap
page read and write
4A90000
direct allocation
page read and write
781000
unkown
page execute and write copy
4A90000
direct allocation
page read and write
11A8000
heap
page read and write
1207000
heap
page read and write
4F30000
direct allocation
page read and write
4A90000
direct allocation
page read and write
4A90000
direct allocation
page read and write
11B0000
heap
page read and write
969000
unkown
page execute and read and write
4A90000
direct allocation
page read and write
599F000
stack
page read and write
4A90000
direct allocation
page read and write
1104000
heap
page read and write
124E000
heap
page read and write
11B4000
heap
page read and write
5080000
direct allocation
page execute and read and write
50B0000
direct allocation
page execute and read and write
1100000
heap
page read and write
4A90000
direct allocation
page read and write
37BF000
stack
page read and write
4A90000
direct allocation
page read and write
4A8F000
stack
page read and write
1104000
heap
page read and write
1104000
heap
page read and write
2F7F000
stack
page read and write
4580000
heap
page read and write
50E0000
direct allocation
page execute and read and write
1215000
heap
page read and write
780000
unkown
page read and write
14AF000
stack
page read and write
41BF000
stack
page read and write
38FF000
stack
page read and write
31BE000
stack
page read and write
780000
unkown
page readonly
117E000
heap
page read and write
50B0000
direct allocation
page execute and read and write
1261000
heap
page read and write
46CF000
stack
page read and write
3F7E000
stack
page read and write
1207000
heap
page read and write
11E8000
heap
page read and write
1104000
heap
page read and write
447E000
stack
page read and write
575E000
stack
page read and write
42FF000
stack
page read and write
50C0000
direct allocation
page execute and read and write
3DFF000
stack
page read and write
50B0000
direct allocation
page execute and read and write
1207000
heap
page read and write
2CAE000
stack
page read and write
4F20000
remote allocation
page read and write
4EE0000
trusted library allocation
page read and write
4A90000
direct allocation
page read and write
3CFE000
stack
page read and write
36BE000
stack
page read and write
2D6E000
stack
page read and write
13AE000
stack
page read and write
1248000
heap
page read and write
A89000
unkown
page execute and write copy
546F000
stack
page read and write
532D000
stack
page read and write
1215000
heap
page read and write
4A90000
direct allocation
page read and write
4F20000
remote allocation
page read and write
117A000
heap
page read and write
457F000
stack
page read and write
1104000
heap
page read and write
4AA1000
heap
page read and write
1104000
heap
page read and write
4A90000
direct allocation
page read and write
1104000
heap
page read and write
45CE000
stack
page read and write
1104000
heap
page read and write
1010000
heap
page read and write
1104000
heap
page read and write
2D2E000
stack
page read and write
353F000
stack
page read and write
1215000
heap
page read and write
136E000
stack
page read and write
50D0000
direct allocation
page execute and read and write
393E000
stack
page read and write
33FF000
stack
page read and write
11F7000
heap
page read and write
A46000
unkown
page execute and read and write
There are 177 hidden memdumps, click here to show them.