IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
dissapoiznw.storec
malicious
studennotediw.storec
malicious
licendfilteo.sitec
malicious
clearancek.site
malicious
https://steamcommunity.com/profiles/76561199724331900
23.192.247.89
malicious
bathdoomgaz.storec
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
eaglepawnoy.storec
malicious
mobbipenju.store
malicious
spirittunek.storec
malicious
https://sergei-esenin.com/api
104.21.53.8
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=cdfm
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://sergei-esenin.com/B
unknown
https://sergei-esenin.com/apiT
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://sergei-esenin.com/apiN
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://steamcommunity.com/discussions/
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://sergei-esenin.com/apiX
unknown
https://store.steampowered.com/stats/
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://steamcommunity.com/workshop/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=qu55UpguGheU&l=e
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://store.steampowered.com/points/shop/
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://sergei-esenin.com:443/api
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://sergei-esenin.com/c
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://community.akamai.steamstatic.com/public/javascript/modalContent.js?v=f2hMA1v9Zkc8&l=engl
unknown
https://store.steampowered.com/about/
unknown
There are 66 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
104.21.53.8
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious
steamcommunity.com
23.192.247.89

IPs

IP
Domain
Country
Malicious
104.21.53.8
sergei-esenin.com
United States
malicious
23.192.247.89
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
221000
unkown
page execute and read and write
malicious
4A91000
heap
page read and write
4A91000
heap
page read and write
538000
unkown
page execute and write copy
2DD0000
direct allocation
page read and write
5060000
direct allocation
page execute and read and write
13AE000
stack
page read and write
444F000
stack
page read and write
4AA0000
heap
page read and write
2DD0000
direct allocation
page read and write
5550000
remote allocation
page read and write
11E8000
heap
page read and write
494F000
stack
page read and write
2F0F000
stack
page read and write
390F000
stack
page read and write
5050000
direct allocation
page execute and read and write
3CCF000
stack
page read and write
5080000
direct allocation
page execute and read and write
2DD0000
direct allocation
page read and write
2DD0000
direct allocation
page read and write
1190000
heap
page read and write
3D0E000
stack
page read and write
570E000
stack
page read and write
4A91000
heap
page read and write
4A91000
heap
page read and write
6DF000
unkown
page execute and read and write
4F0E000
stack
page read and write
318F000
stack
page read and write
2DCC000
stack
page read and write
358E000
stack
page read and write
3E4E000
stack
page read and write
480F000
stack
page read and write
330E000
stack
page read and write
434E000
stack
page read and write
2DF0000
direct allocation
page read and write
5070000
direct allocation
page execute and read and write
40CE000
stack
page read and write
2DD0000
direct allocation
page read and write
280000
unkown
page execute and read and write
2DD0000
direct allocation
page read and write
1235000
heap
page read and write
124E000
heap
page read and write
4A91000
heap
page read and write
4A91000
heap
page read and write
2E00000
heap
page read and write
37CF000
stack
page read and write
4A91000
heap
page read and write
11BA000
heap
page read and write
1229000
heap
page read and write
31CE000
stack
page read and write
2DD0000
direct allocation
page read and write
6E0000
unkown
page execute and write copy
5550000
remote allocation
page read and write
115E000
stack
page read and write
4A90000
heap
page read and write
4A91000
heap
page read and write
36CE000
stack
page read and write
504F000
stack
page read and write
2DD0000
direct allocation
page read and write
4A91000
heap
page read and write
553F000
stack
page read and write
4A91000
heap
page read and write
4ED0000
trusted library allocation
page read and write
4A91000
heap
page read and write
580F000
stack
page read and write
11E8000
heap
page read and write
4A8F000
stack
page read and write
559D000
stack
page read and write
569E000
stack
page read and write
220000
unkown
page readonly
521000
unkown
page execute and read and write
5550000
remote allocation
page read and write
11F1000
heap
page read and write
52FE000
stack
page read and write
4A91000
heap
page read and write
2E07000
heap
page read and write
484E000
stack
page read and write
5080000
direct allocation
page execute and read and write
111E000
stack
page read and write
E6C000
stack
page read and write
53FF000
stack
page read and write
1180000
heap
page read and write
5080000
direct allocation
page execute and read and write
508D000
stack
page read and write
3A8E000
stack
page read and write
4A91000
heap
page read and write
4F5000
unkown
page execute and read and write
5080000
direct allocation
page execute and read and write
448E000
stack
page read and write
394E000
stack
page read and write
2C8E000
stack
page read and write
1229000
heap
page read and write
470E000
stack
page read and write
50CC000
trusted library allocation
page read and write
2DD0000
direct allocation
page read and write
50B0000
direct allocation
page execute and read and write
51BD000
stack
page read and write
45CE000
stack
page read and write
2DD0000
direct allocation
page read and write
2F4E000
stack
page read and write
380E000
stack
page read and write
3F8E000
stack
page read and write
407000
unkown
page execute and read and write
420E000
stack
page read and write
344E000
stack
page read and write
2DD0000
direct allocation
page read and write
538000
unkown
page execute and read and write
5080000
direct allocation
page execute and read and write
2DF0000
direct allocation
page read and write
122C000
heap
page read and write
539000
unkown
page execute and write copy
14AF000
stack
page read and write
5090000
direct allocation
page execute and read and write
1210000
heap
page read and write
F6D000
stack
page read and write
529000
unkown
page execute and read and write
FD5000
heap
page read and write
308E000
stack
page read and write
5080000
direct allocation
page execute and read and write
124C000
heap
page read and write
2DD0000
direct allocation
page read and write
3BCE000
stack
page read and write
458F000
stack
page read and write
220000
unkown
page read and write
52BD000
stack
page read and write
2DD0000
direct allocation
page read and write
430F000
stack
page read and write
50A0000
direct allocation
page execute and read and write
543E000
stack
page read and write
340F000
stack
page read and write
4A91000
heap
page read and write
304F000
stack
page read and write
32CF000
stack
page read and write
3F4F000
stack
page read and write
124E000
heap
page read and write
11BE000
heap
page read and write
4A91000
heap
page read and write
11B0000
heap
page read and write
11F4000
heap
page read and write
FC0000
heap
page read and write
11E3000
heap
page read and write
4A91000
heap
page read and write
2D8F000
stack
page read and write
498E000
stack
page read and write
11F1000
heap
page read and write
368F000
stack
page read and write
11FE000
heap
page read and write
46CF000
stack
page read and write
4F4E000
stack
page read and write
10B0000
heap
page read and write
11F4000
heap
page read and write
122C000
heap
page read and write
3E0F000
stack
page read and write
3A4F000
stack
page read and write
1235000
heap
page read and write
129C000
heap
page read and write
1210000
heap
page read and write
4F10000
direct allocation
page read and write
408F000
stack
page read and write
11FE000
heap
page read and write
3B8F000
stack
page read and write
4A91000
heap
page read and write
128B000
heap
page read and write
41CF000
stack
page read and write
4A91000
heap
page read and write
2DD0000
direct allocation
page read and write
354F000
stack
page read and write
FD0000
heap
page read and write
4A91000
heap
page read and write
124C000
heap
page read and write
221000
unkown
page execute and write copy
There are 161 hidden memdumps, click here to show them.