IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
dissapoiznw.storec
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
eaglepawnoy.storec
malicious
spirittunek.storec
malicious
https://steamcommunity.com/profiles/76561199724331900qt
unknown
malicious
studennotediw.storec
malicious
licendfilteo.sitec
malicious
clearancek.site
malicious
bathdoomgaz.storec
malicious
mobbipenju.store
malicious
https://sergei-esenin.com/api
104.21.53.8
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://store.steampowered.com/points/shop/
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
unknown
https://sergei-esenin.com:443/apifiles/76561199724331900
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://avatars.akamai.steamstatic
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=cdfm
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://sergei-esenin.com/api3
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=qu55UpguGheU&l=e
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=10oP_O2R
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
http://crl.micros0
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalContent.js?v=f2hMA1v9Zkc8&l=engl
unknown
There are 89 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sergei-esenin.com
104.21.53.8
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious
steamcommunity.com
104.102.49.254

IPs

IP
Domain
Country
Malicious
104.21.53.8
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
B01000
unkown
page execute and read and write
malicious
499E000
stack
page read and write
4AB0000
direct allocation
page read and write
4AC1000
heap
page read and write
4A9F000
stack
page read and write
46DF000
stack
page read and write
4F50000
direct allocation
page read and write
FA0000
unkown
page execute and read and write
309E000
stack
page read and write
31DE000
stack
page read and write
305F000
stack
page read and write
2CD7000
heap
page read and write
4AB0000
direct allocation
page read and write
AE6000
heap
page read and write
3BDE000
stack
page read and write
431F000
stack
page read and write
55B0000
remote allocation
page read and write
409F000
stack
page read and write
1345000
heap
page read and write
3A9E000
stack
page read and write
5110000
direct allocation
page execute and read and write
134F000
heap
page read and write
4AB0000
direct allocation
page read and write
4AC1000
heap
page read and write
391F000
stack
page read and write
3D1E000
stack
page read and write
133C000
heap
page read and write
5100000
direct allocation
page execute and read and write
B01000
unkown
page execute and write copy
345E000
stack
page read and write
3E5E000
stack
page read and write
549E000
stack
page read and write
355F000
stack
page read and write
1346000
heap
page read and write
B60000
unkown
page execute and read and write
4AB0000
direct allocation
page read and write
DF6000
unkown
page execute and read and write
3B9F000
stack
page read and write
50D0000
direct allocation
page execute and read and write
50F0000
direct allocation
page execute and read and write
2CD0000
heap
page read and write
A70000
heap
page read and write
A60000
heap
page read and write
4AB0000
direct allocation
page read and write
1280000
heap
page read and write
3A5F000
stack
page read and write
50D0000
direct allocation
page execute and read and write
50D0000
direct allocation
page execute and read and write
CE0000
unkown
page execute and read and write
50B0000
direct allocation
page execute and read and write
421E000
stack
page read and write
4F8C000
stack
page read and write
3F5F000
stack
page read and write
40DE000
stack
page read and write
4F50000
direct allocation
page read and write
50A0000
direct allocation
page execute and read and write
A3C000
stack
page read and write
4AC1000
heap
page read and write
130E000
heap
page read and write
12B8000
heap
page read and write
13BE000
stack
page read and write
45DE000
stack
page read and write
2DDF000
stack
page read and write
4AB0000
direct allocation
page read and write
36DE000
stack
page read and write
2E1B000
stack
page read and write
12E2000
heap
page read and write
341F000
stack
page read and write
508F000
stack
page read and write
1309000
heap
page read and write
12C6000
heap
page read and write
130E000
heap
page read and write
B00000
unkown
page read and write
576E000
stack
page read and write
128E000
heap
page read and write
485E000
stack
page read and write
449E000
stack
page read and write
459F000
stack
page read and write
2F1F000
stack
page read and write
4AB0000
direct allocation
page read and write
133F000
heap
page read and write
545E000
stack
page read and write
ADE000
stack
page read and write
381E000
stack
page read and write
319F000
stack
page read and write
435E000
stack
page read and write
12F9000
heap
page read and write
560D000
stack
page read and write
50E0000
direct allocation
page execute and read and write
E06000
unkown
page execute and write copy
50C0000
direct allocation
page execute and read and write
B00000
unkown
page readonly
12D3000
heap
page read and write
369F000
stack
page read and write
50D0000
direct allocation
page execute and read and write
2CAE000
stack
page read and write
E05000
unkown
page execute and read and write
3F9E000
stack
page read and write
41DF000
stack
page read and write
4AB0000
direct allocation
page read and write
495F000
stack
page read and write
12DF000
heap
page read and write
586F000
stack
page read and write
4AB0000
direct allocation
page read and write
12D0000
heap
page read and write
127F000
stack
page read and write
128A000
heap
page read and write
4AB0000
direct allocation
page read and write
DEF000
unkown
page execute and read and write
AE0000
heap
page read and write
14BF000
stack
page read and write
55B0000
remote allocation
page read and write
535D000
stack
page read and write
4F3D000
stack
page read and write
4AB0000
direct allocation
page read and write
1309000
heap
page read and write
445F000
stack
page read and write
395E000
stack
page read and write
559F000
stack
page read and write
531F000
stack
page read and write
570D000
stack
page read and write
4BC0000
trusted library allocation
page read and write
55B0000
remote allocation
page read and write
50DE000
stack
page read and write
2F5E000
stack
page read and write
50D0000
direct allocation
page execute and read and write
3E1F000
stack
page read and write
359E000
stack
page read and write
521D000
stack
page read and write
331E000
stack
page read and write
4F50000
direct allocation
page read and write
3CDF000
stack
page read and write
512A000
trusted library allocation
page read and write
4AB0000
direct allocation
page read and write
2CB0000
heap
page read and write
E05000
unkown
page execute and write copy
10AD000
stack
page read and write
37DF000
stack
page read and write
4AC0000
heap
page read and write
1342000
heap
page read and write
50D0000
direct allocation
page execute and read and write
4AA0000
heap
page read and write
4AB0000
direct allocation
page read and write
481F000
stack
page read and write
471E000
stack
page read and write
DC4000
unkown
page execute and read and write
4AB0000
direct allocation
page read and write
32DF000
stack
page read and write
There are 138 hidden memdumps, click here to show them.