IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
dissapoiznw.storec
malicious
studennotediw.storec
malicious
licendfilteo.sitec
malicious
clearancek.site
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
bathdoomgaz.storec
malicious
eaglepawnoy.storec
malicious
mobbipenju.store
malicious
spirittunek.storec
malicious
https://steamcommunity.com/my/wishlist/
unknown
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=cdfm
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://recaptcha.net/recaptcha/;
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://steamcommunity.com/discussions/
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/fatalerror.css?v=wctRWaBvNt2z&l=engli
unknown
https://store.steampowered.com/stats/
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://store.steampowered.com/points/shop/
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://steamcommunity.com
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
There are 71 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious
steamcommunity.com
104.102.49.254

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
251000
unkown
page execute and read and write
malicious
4861000
heap
page read and write
2D1F000
stack
page read and write
4861000
heap
page read and write
100D000
heap
page read and write
F80000
direct allocation
page read and write
DB4000
heap
page read and write
DB4000
heap
page read and write
309F000
stack
page read and write
3F9F000
stack
page read and write
DB4000
heap
page read and write
2AFE000
stack
page read and write
4E30000
direct allocation
page execute and read and write
F0E000
stack
page read and write
4E50000
direct allocation
page execute and read and write
FE0000
heap
page read and write
250000
unkown
page read and write
F80000
direct allocation
page read and write
4861000
heap
page read and write
4CA0000
heap
page read and write
45DF000
stack
page read and write
2B17000
heap
page read and write
250000
unkown
page readonly
4861000
heap
page read and write
4E20000
direct allocation
page execute and read and write
F80000
direct allocation
page read and write
54FE000
stack
page read and write
DB4000
heap
page read and write
475E000
stack
page read and write
DC0000
heap
page read and write
35DE000
stack
page read and write
4E80000
direct allocation
page execute and read and write
1065000
heap
page read and write
55C000
unkown
page execute and read and write
349E000
stack
page read and write
381F000
stack
page read and write
345F000
stack
page read and write
4E5D000
stack
page read and write
102C000
heap
page read and write
DB4000
heap
page read and write
4CD0000
remote allocation
page read and write
2A7E000
stack
page read and write
55C000
unkown
page execute and write copy
F80000
direct allocation
page read and write
321E000
stack
page read and write
485F000
stack
page read and write
548E000
stack
page read and write
DB4000
heap
page read and write
4860000
heap
page read and write
DB4000
heap
page read and write
4E60000
direct allocation
page execute and read and write
385E000
stack
page read and write
371E000
stack
page read and write
395F000
stack
page read and write
31DF000
stack
page read and write
FAE000
heap
page read and write
2E5E000
stack
page read and write
4861000
heap
page read and write
54D000
unkown
page execute and read and write
DB4000
heap
page read and write
DB4000
heap
page read and write
1002000
heap
page read and write
4FCD000
stack
page read and write
50CD000
stack
page read and write
DB4000
heap
page read and write
461E000
stack
page read and write
D5D000
stack
page read and write
449F000
stack
page read and write
421F000
stack
page read and write
3C1E000
stack
page read and write
435F000
stack
page read and write
F80000
direct allocation
page read and write
102A000
heap
page read and write
471F000
stack
page read and write
F80000
direct allocation
page read and write
520F000
stack
page read and write
F80000
direct allocation
page read and write
F80000
direct allocation
page read and write
6FD000
unkown
page execute and read and write
FEE000
heap
page read and write
4F8D000
stack
page read and write
36DF000
stack
page read and write
438000
unkown
page execute and read and write
510E000
stack
page read and write
546000
unkown
page execute and read and write
4E70000
direct allocation
page execute and read and write
538D000
stack
page read and write
335E000
stack
page read and write
119F000
stack
page read and write
1000000
heap
page read and write
439E000
stack
page read and write
4E1F000
stack
page read and write
102C000
heap
page read and write
129E000
stack
page read and write
4870000
heap
page read and write
518000
unkown
page execute and read and write
251000
unkown
page execute and write copy
4861000
heap
page read and write
DB4000
heap
page read and write
F80000
direct allocation
page read and write
2B00000
direct allocation
page read and write
FEA000
heap
page read and write
4E50000
direct allocation
page execute and read and write
FD8000
heap
page read and write
F80000
direct allocation
page read and write
4CD0000
remote allocation
page read and write
DB4000
heap
page read and write
4861000
heap
page read and write
100D000
heap
page read and write
2B00000
direct allocation
page read and write
425E000
stack
page read and write
DB4000
heap
page read and write
2F9E000
stack
page read and write
102A000
heap
page read and write
3A9F000
stack
page read and write
44DE000
stack
page read and write
102C000
heap
page read and write
6FE000
unkown
page execute and write copy
DB4000
heap
page read and write
30DE000
stack
page read and write
4E50000
direct allocation
page execute and read and write
4E50000
direct allocation
page execute and read and write
DB4000
heap
page read and write
4E50000
direct allocation
page execute and read and write
2F5F000
stack
page read and write
FA0000
heap
page read and write
DB0000
heap
page read and write
FAA000
heap
page read and write
3BDF000
stack
page read and write
3D1F000
stack
page read and write
1000000
heap
page read and write
1003000
heap
page read and write
4861000
heap
page read and write
C5C000
stack
page read and write
2ABB000
stack
page read and write
DB4000
heap
page read and write
3E9E000
stack
page read and write
FE5000
heap
page read and write
1060000
heap
page read and write
F80000
direct allocation
page read and write
524E000
stack
page read and write
4861000
heap
page read and write
331F000
stack
page read and write
DB4000
heap
page read and write
4861000
heap
page read and write
F70000
heap
page read and write
2E1F000
stack
page read and write
40DF000
stack
page read and write
F80000
direct allocation
page read and write
3ADE000
stack
page read and write
100D000
heap
page read and write
4CD0000
remote allocation
page read and write
DB4000
heap
page read and write
DB4000
heap
page read and write
55FF000
stack
page read and write
DB4000
heap
page read and write
F80000
direct allocation
page read and write
3FDE000
stack
page read and write
359F000
stack
page read and write
2B0000
unkown
page execute and read and write
3E5F000
stack
page read and write
DB4000
heap
page read and write
55D000
unkown
page execute and write copy
4E50000
direct allocation
page execute and read and write
4E40000
direct allocation
page execute and read and write
4CA0000
trusted library allocation
page read and write
534F000
stack
page read and write
3D5E000
stack
page read and write
102A000
heap
page read and write
DB4000
heap
page read and write
DB4000
heap
page read and write
F80000
direct allocation
page read and write
399E000
stack
page read and write
4CE0000
direct allocation
page read and write
2B10000
heap
page read and write
F4E000
stack
page read and write
DB4000
heap
page read and write
4E9A000
trusted library allocation
page read and write
2C1F000
stack
page read and write
411E000
stack
page read and write
4D1E000
stack
page read and write
DB4000
heap
page read and write
EA0000
heap
page read and write
FE8000
heap
page read and write
FEE000
heap
page read and write
There are 175 hidden memdumps, click here to show them.