IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
dissapoiznw.storec
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
eaglepawnoy.storec
malicious
spirittunek.storec
malicious
studennotediw.storec
malicious
licendfilteo.sitec
malicious
clearancek.site
malicious
bathdoomgaz.storec
malicious
mobbipenju.store
malicious
https://sergei-esenin.com/api
172.67.206.204
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://licendfilteo.site:443/api
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://steamcommunity.com:443/profiles/76561199724331900
unknown
https://store.steampowered.com/points/shop/
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://sergei-esenin.com:443/api
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=cdfm
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=eng
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://licendfilteo.site/api
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=qu55UpguGheU&l=e
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://spirittunek.store:443/api
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalContent.js?v=f2hMA1v9Zkc8&l=engl
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
172.67.206.204
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious
steamcommunity.com
104.102.49.254
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
84.201.210.22
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
172.67.206.204
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
E31000
unkown
page execute and read and write
malicious
3FFE000
stack
page read and write
981000
heap
page read and write
981000
heap
page read and write
53AF000
stack
page read and write
413E000
stack
page read and write
4611000
heap
page read and write
987000
heap
page read and write
347F000
stack
page read and write
4600000
direct allocation
page read and write
397F000
stack
page read and write
86E000
stack
page read and write
9D1000
heap
page read and write
4600000
direct allocation
page read and write
3E7F000
stack
page read and write
423F000
stack
page read and write
4611000
heap
page read and write
4C20000
direct allocation
page execute and read and write
986000
heap
page read and write
9C4000
heap
page read and write
4611000
heap
page read and write
3ABF000
stack
page read and write
4BF0000
direct allocation
page execute and read and write
97C000
heap
page read and write
93E000
heap
page read and write
92F000
heap
page read and write
9A1000
heap
page read and write
8D0000
heap
page read and write
6FD000
stack
page read and write
4611000
heap
page read and write
45FF000
stack
page read and write
97C000
heap
page read and write
36FF000
stack
page read and write
4C50000
direct allocation
page execute and read and write
E30000
unkown
page readonly
4E9D000
stack
page read and write
4611000
heap
page read and write
9C1000
heap
page read and write
4600000
direct allocation
page read and write
973000
heap
page read and write
9C4000
heap
page read and write
8C0000
heap
page read and write
387E000
stack
page read and write
4611000
heap
page read and write
AEF000
stack
page read and write
9A1000
heap
page read and write
3B0000
heap
page read and write
4611000
heap
page read and write
9A1000
heap
page read and write
820000
heap
page read and write
43BE000
stack
page read and write
1139000
unkown
page execute and read and write
4600000
direct allocation
page read and write
4F9F000
stack
page read and write
50F0000
remote allocation
page read and write
4C00000
direct allocation
page execute and read and write
4C20000
direct allocation
page execute and read and write
9CE000
heap
page read and write
928000
heap
page read and write
30FE000
stack
page read and write
972000
heap
page read and write
35BF000
stack
page read and write
50DF000
stack
page read and write
4611000
heap
page read and write
31FF000
stack
page read and write
4C40000
direct allocation
page execute and read and write
427E000
stack
page read and write
4C20000
direct allocation
page execute and read and write
97C000
heap
page read and write
4611000
heap
page read and write
E90000
unkown
page execute and read and write
9C4000
heap
page read and write
44BF000
stack
page read and write
35C000
stack
page read and write
4611000
heap
page read and write
4610000
heap
page read and write
34BE000
stack
page read and write
2F7F000
stack
page read and write
3EBE000
stack
page read and write
2BFE000
stack
page read and write
12D7000
unkown
page execute and read and write
39BE000
stack
page read and write
979000
heap
page read and write
52AE000
stack
page read and write
8B0000
heap
page read and write
4600000
direct allocation
page read and write
3D7E000
stack
page read and write
4AA0000
direct allocation
page read and write
50F0000
remote allocation
page read and write
2FBE000
stack
page read and write
4AA0000
direct allocation
page read and write
3FBF000
stack
page read and write
4600000
direct allocation
page read and write
E30000
unkown
page read and write
8FE000
heap
page read and write
953000
heap
page read and write
BEF000
stack
page read and write
2E3F000
stack
page read and write
9A1000
heap
page read and write
373E000
stack
page read and write
4C30000
direct allocation
page execute and read and write
825000
heap
page read and write
2CFF000
stack
page read and write
8FA000
heap
page read and write
9C4000
heap
page read and write
4E5D000
stack
page read and write
4611000
heap
page read and write
4C20000
direct allocation
page execute and read and write
35FE000
stack
page read and write
2BBF000
stack
page read and write
4BDF000
stack
page read and write
987000
heap
page read and write
987000
heap
page read and write
4ADE000
stack
page read and write
44FE000
stack
page read and write
E31000
unkown
page execute and write copy
4D5E000
stack
page read and write
333F000
stack
page read and write
3C3E000
stack
page read and write
4600000
direct allocation
page read and write
10F9000
unkown
page execute and read and write
4600000
direct allocation
page read and write
323E000
stack
page read and write
953000
heap
page read and write
9CF000
heap
page read and write
383F000
stack
page read and write
4611000
heap
page read and write
50F0000
remote allocation
page read and write
297F000
stack
page read and write
4C66000
trusted library allocation
page read and write
1139000
unkown
page execute and write copy
4A8D000
stack
page read and write
4600000
direct allocation
page read and write
80E000
stack
page read and write
1123000
unkown
page execute and read and write
92F000
heap
page read and write
4FDE000
stack
page read and write
4611000
heap
page read and write
8C7000
heap
page read and write
4611000
heap
page read and write
2A7F000
stack
page read and write
933000
heap
page read and write
113A000
unkown
page execute and write copy
4C10000
direct allocation
page execute and read and write
523C000
stack
page read and write
9A1000
heap
page read and write
93E000
heap
page read and write
4C20000
direct allocation
page execute and read and write
933000
heap
page read and write
935000
heap
page read and write
3D3F000
stack
page read and write
12D8000
unkown
page execute and write copy
8AE000
stack
page read and write
4600000
direct allocation
page read and write
950000
heap
page read and write
97E000
heap
page read and write
E2C000
stack
page read and write
4611000
heap
page read and write
923000
heap
page read and write
979000
heap
page read and write
4600000
direct allocation
page read and write
8F0000
heap
page read and write
3C0000
heap
page read and write
337E000
stack
page read and write
3AFE000
stack
page read and write
1018000
unkown
page execute and read and write
2E7E000
stack
page read and write
4611000
heap
page read and write
4600000
direct allocation
page read and write
4AA0000
direct allocation
page read and write
4611000
heap
page read and write
950000
heap
page read and write
4710000
trusted library allocation
page read and write
9C4000
heap
page read and write
437F000
stack
page read and write
112C000
unkown
page execute and read and write
4C20000
direct allocation
page execute and read and write
513E000
stack
page read and write
40FF000
stack
page read and write
935000
heap
page read and write
2ABE000
stack
page read and write
4620000
heap
page read and write
3BFF000
stack
page read and write
4C2D000
stack
page read and write
9CF000
heap
page read and write
4611000
heap
page read and write
4600000
direct allocation
page read and write
2D3E000
stack
page read and write
928000
heap
page read and write
4611000
heap
page read and write
972000
heap
page read and write
30BF000
stack
page read and write
4600000
direct allocation
page read and write
There are 183 hidden memdumps, click here to show them.