IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
https://sergei-esenin.com/
unknown
malicious
dissapoiznw.storec
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
eaglepawnoy.storec
malicious
https://sergei-esenin.com:443/api
unknown
malicious
spirittunek.storec
malicious
https://sergei-esenin.com/Z$
unknown
malicious
https://sergei-esenin.com/.
unknown
malicious
https://sergei-esenin.com/apiF
unknown
malicious
studennotediw.storec
malicious
licendfilteo.sitec
malicious
clearancek.site
malicious
bathdoomgaz.storec
malicious
https://steamcommunity.com/profiles/76561199724331900J
unknown
malicious
mobbipenju.store
malicious
https://sergei-esenin.com/api
104.21.53.8
malicious
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://store.steampowered.com/points/shop/
unknown
https://steamcommunity.com/=o
unknown
https://steamcommunity.com/=l
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://steamcommunity.com/?su
unknown
https://www.youtube.com/
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://avatars.akamai.steamstatic
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=cdfm
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=qu55UpguGheU&l=e
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
104.21.53.8
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious
steamcommunity.com
104.102.49.254

IPs

IP
Domain
Country
Malicious
104.21.53.8
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
A81000
unkown
page execute and read and write
malicious
53D0000
direct allocation
page execute and read and write
45FF000
stack
page read and write
D7D000
unkown
page execute and read and write
4880000
heap
page read and write
3BFF000
stack
page read and write
3D3F000
stack
page read and write
53F0000
direct allocation
page execute and read and write
D8C000
unkown
page execute and write copy
413E000
stack
page read and write
F2B000
unkown
page execute and write copy
15BD000
heap
page read and write
53D0000
direct allocation
page execute and read and write
4DB0000
direct allocation
page read and write
4B4E000
stack
page read and write
4DB0000
direct allocation
page read and write
4DB0000
direct allocation
page read and write
F2B000
unkown
page execute and write copy
35BF000
stack
page read and write
53DD000
stack
page read and write
397F000
stack
page read and write
4DC1000
heap
page read and write
337F000
stack
page read and write
347F000
stack
page read and write
423F000
stack
page read and write
184F000
stack
page read and write
4DC1000
heap
page read and write
4DB0000
direct allocation
page read and write
1550000
heap
page read and write
1590000
heap
page read and write
5250000
direct allocation
page read and write
A80000
unkown
page read and write
4DC1000
heap
page read and write
15E9000
heap
page read and write
15DA000
heap
page read and write
317F000
stack
page read and write
15E9000
heap
page read and write
4C8E000
stack
page read and write
3AFE000
stack
page read and write
574E000
stack
page read and write
1588000
heap
page read and write
4DC1000
heap
page read and write
44FE000
stack
page read and write
43BD000
stack
page read and write
578E000
stack
page read and write
5B5F000
stack
page read and write
4DB0000
direct allocation
page read and write
4DD0000
heap
page read and write
53D0000
direct allocation
page execute and read and write
477E000
stack
page read and write
55DD000
trusted library allocation
page read and write
53D0000
direct allocation
page execute and read and write
155A000
heap
page read and write
387E000
stack
page read and write
3070000
heap
page read and write
40FF000
stack
page read and write
39BE000
stack
page read and write
4DC1000
heap
page read and write
5250000
direct allocation
page read and write
AE0000
unkown
page execute and read and write
4B0F000
stack
page read and write
49CF000
stack
page read and write
53A0000
direct allocation
page execute and read and write
15B0000
heap
page read and write
155E000
heap
page read and write
D8B000
unkown
page execute and write copy
3D7E000
stack
page read and write
58A0000
remote allocation
page read and write
5A5E000
stack
page read and write
4C4F000
stack
page read and write
523D000
stack
page read and write
14CE000
stack
page read and write
4DC1000
heap
page read and write
12FD000
stack
page read and write
150E000
stack
page read and write
1628000
heap
page read and write
4DC1000
heap
page read and write
36FF000
stack
page read and write
4DC1000
heap
page read and write
4DC1000
heap
page read and write
538F000
stack
page read and write
15DA000
heap
page read and write
53D0000
direct allocation
page execute and read and write
1590000
heap
page read and write
53C0000
direct allocation
page execute and read and write
4DC1000
heap
page read and write
1320000
heap
page read and write
4DC1000
heap
page read and write
58A0000
remote allocation
page read and write
58EE000
stack
page read and write
427E000
stack
page read and write
35FE000
stack
page read and write
59ED000
stack
page read and write
4D90000
heap
page read and write
4DB0000
direct allocation
page read and write
4DB0000
direct allocation
page read and write
487F000
stack
page read and write
4EC0000
trusted library allocation
page read and write
A80000
unkown
page readonly
3C3E000
stack
page read and write
154B000
stack
page read and write
D75000
unkown
page execute and read and write
D46000
unkown
page execute and read and write
3EBE000
stack
page read and write
588F000
stack
page read and write
4DB0000
direct allocation
page read and write
473F000
stack
page read and write
4DC1000
heap
page read and write
53E0000
direct allocation
page execute and read and write
4DB0000
direct allocation
page read and write
550D000
stack
page read and write
4DB0000
direct allocation
page read and write
373E000
stack
page read and write
5250000
direct allocation
page read and write
138E000
stack
page read and write
58A0000
remote allocation
page read and write
4DB0000
direct allocation
page read and write
1620000
heap
page read and write
48CE000
stack
page read and write
327F000
stack
page read and write
4DC1000
heap
page read and write
1596000
heap
page read and write
1588000
heap
page read and write
4DC1000
heap
page read and write
53B0000
direct allocation
page execute and read and write
FBC000
stack
page read and write
306E000
stack
page read and write
15BD000
heap
page read and write
3E7F000
stack
page read and write
437F000
stack
page read and write
4DC1000
heap
page read and write
1310000
heap
page read and write
1596000
heap
page read and write
3FBF000
stack
page read and write
463E000
stack
page read and write
15B0000
heap
page read and write
C6C000
unkown
page execute and read and write
4A0E000
stack
page read and write
F29000
unkown
page execute and read and write
5417000
trusted library allocation
page read and write
34BE000
stack
page read and write
528E000
stack
page read and write
3ABF000
stack
page read and write
A81000
unkown
page execute and write copy
4DC1000
heap
page read and write
564E000
stack
page read and write
560D000
stack
page read and write
D8B000
unkown
page execute and read and write
4D8F000
stack
page read and write
302E000
stack
page read and write
174F000
stack
page read and write
53D0000
direct allocation
page execute and read and write
4DC1000
heap
page read and write
44BE000
stack
page read and write
4DC1000
heap
page read and write
1620000
heap
page read and write
4DC1000
heap
page read and write
159E000
heap
page read and write
4DC0000
heap
page read and write
159E000
heap
page read and write
3077000
heap
page read and write
4DB0000
direct allocation
page read and write
5400000
direct allocation
page execute and read and write
13B5000
heap
page read and write
4DB0000
direct allocation
page read and write
383F000
stack
page read and write
13B0000
heap
page read and write
4DB0000
direct allocation
page read and write
3FFE000
stack
page read and write
There are 159 hidden memdumps, click here to show them.