IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
https://sergei-esenin.com/
unknown
malicious
studennotediw.store
malicious
dissapoiznw.store
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
eaglepawnoy.store
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
bathdoomgaz.store
malicious
https://sergei-esenin.com/api3
unknown
malicious
https://sergei-esenin.com/api;
unknown
malicious
clearancek.site
malicious
spirittunek.store
malicious
licendfilteo.site
malicious
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_com
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=engli
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://steamcommunity.com/my/wish
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://community.akamai.steamstatic.com/puQ
unknown
https://store.steampowered.com/ne
unknown
https://steamcommunity.com/login/h
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akam=S
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://store.steampower
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.akam
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=M7aU
unknown
https://store.steampowered.com/points/shop/
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=2Ih2WOq7ErXY&a
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isF
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://avatars.akamai.steamstatic
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
https://community.akamai.steamstatic.com/public/javascri
unknown
https://community.akamai.steamstatic.com/pu
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://steamcommunity.com/discussions/
unknown
https://studennotediw.store/apiS
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://steamcommunity.com/Q
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steam
unknown
https://store.steampowered.com/legal/
unknown
https://community.akama0Q
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=Gu9gs5hf
unknown
https://community.akamai.steamstatic.com/public/css/p
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://store.steampowe
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=IZH_ONwLX4kw&l=e
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
104.102.49.254
malicious
sergei-esenin.com
172.67.206.204
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States
malicious
172.67.206.204
sergei-esenin.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
701000
unkown
page execute and read and write
malicious
417F000
stack
page read and write
1224000
heap
page read and write
132E000
heap
page read and write
1224000
heap
page read and write
52E0000
direct allocation
page execute and read and write
4CC1000
heap
page read and write
1340000
heap
page read and write
1224000
heap
page read and write
1361000
heap
page read and write
42BF000
stack
page read and write
3A3E000
stack
page read and write
3F3E000
stack
page read and write
3EFF000
stack
page read and write
1224000
heap
page read and write
2EE0000
direct allocation
page read and write
12BE000
stack
page read and write
2ECE000
stack
page read and write
531A000
trusted library allocation
page read and write
1343000
heap
page read and write
57CF000
stack
page read and write
4CC1000
heap
page read and write
52D0000
direct allocation
page execute and read and write
1224000
heap
page read and write
32BE000
stack
page read and write
2EE0000
direct allocation
page read and write
1224000
heap
page read and write
1318000
heap
page read and write
1383000
heap
page read and write
1224000
heap
page read and write
13B6000
heap
page read and write
4CC1000
heap
page read and write
3DFE000
stack
page read and write
2EE0000
direct allocation
page read and write
2EE0000
direct allocation
page read and write
2EE0000
direct allocation
page read and write
BC4000
unkown
page execute and read and write
16EF000
stack
page read and write
43FF000
stack
page read and write
5150000
direct allocation
page read and write
1224000
heap
page read and write
4CC1000
heap
page read and write
1224000
heap
page read and write
363F000
stack
page read and write
4CC1000
heap
page read and write
2EF7000
heap
page read and write
1240000
heap
page read and write
34FF000
stack
page read and write
1313000
heap
page read and write
403F000
stack
page read and write
407E000
stack
page read and write
46BE000
stack
page read and write
9D9000
unkown
page execute and read and write
4B7F000
stack
page read and write
2EE0000
direct allocation
page read and write
1383000
heap
page read and write
2EF0000
heap
page read and write
1318000
heap
page read and write
131F000
heap
page read and write
4CC1000
heap
page read and write
1383000
heap
page read and write
1325000
heap
page read and write
518E000
stack
page read and write
A06000
unkown
page execute and read and write
5300000
direct allocation
page execute and read and write
13C1000
heap
page read and write
1250000
heap
page read and write
38BF000
stack
page read and write
2EE0000
direct allocation
page read and write
3DBF000
stack
page read and write
453F000
stack
page read and write
52C0000
direct allocation
page execute and read and write
5140000
remote allocation
page read and write
2ED0000
heap
page read and write
1383000
heap
page read and write
2EE0000
direct allocation
page read and write
2EE0000
direct allocation
page read and write
1224000
heap
page read and write
8F8000
unkown
page execute and read and write
580E000
stack
page read and write
41BE000
stack
page read and write
467F000
stack
page read and write
1224000
heap
page read and write
A1D000
unkown
page execute and write copy
5140000
remote allocation
page read and write
528F000
stack
page read and write
1362000
heap
page read and write
A0F000
unkown
page execute and read and write
313F000
stack
page read and write
42FE000
stack
page read and write
1224000
heap
page read and write
3B3F000
stack
page read and write
1224000
heap
page read and write
700000
unkown
page read and write
443E000
stack
page read and write
590D000
stack
page read and write
1224000
heap
page read and write
303B000
stack
page read and write
52D0000
direct allocation
page execute and read and write
A1E000
unkown
page execute and write copy
1383000
heap
page read and write
52D0000
direct allocation
page execute and read and write
13C1000
heap
page read and write
A1D000
unkown
page execute and read and write
1340000
heap
page read and write
4CC1000
heap
page read and write
1224000
heap
page read and write
554D000
stack
page read and write
1220000
heap
page read and write
544D000
stack
page read and write
13BA000
heap
page read and write
13C1000
heap
page read and write
52A0000
direct allocation
page execute and read and write
39FF000
stack
page read and write
5A7F000
stack
page read and write
1224000
heap
page read and write
52F0000
direct allocation
page execute and read and write
1224000
heap
page read and write
4CC0000
heap
page read and write
353E000
stack
page read and write
5100000
heap
page read and write
2FFF000
stack
page read and write
52D0000
direct allocation
page execute and read and write
4DC0000
trusted library allocation
page read and write
BC5000
unkown
page execute and write copy
33FE000
stack
page read and write
2EE0000
direct allocation
page read and write
4CC1000
heap
page read and write
52D0000
direct allocation
page execute and read and write
3CBE000
stack
page read and write
1343000
heap
page read and write
4A3F000
stack
page read and write
2EE0000
direct allocation
page read and write
760000
unkown
page execute and read and write
12EA000
heap
page read and write
597E000
stack
page read and write
1224000
heap
page read and write
701000
unkown
page execute and write copy
4CC1000
heap
page read and write
493E000
stack
page read and write
47FE000
stack
page read and write
377F000
stack
page read and write
558E000
stack
page read and write
700000
unkown
page readonly
38FE000
stack
page read and write
37BE000
stack
page read and write
4BBE000
stack
page read and write
12EE000
heap
page read and write
FDD000
stack
page read and write
48FF000
stack
page read and write
5140000
remote allocation
page read and write
52D0000
direct allocation
page execute and read and write
3C7F000
stack
page read and write
4A7E000
stack
page read and write
1362000
heap
page read and write
15AE000
stack
page read and write
540E000
stack
page read and write
327F000
stack
page read and write
52DD000
stack
page read and write
1325000
heap
page read and write
2EE0000
direct allocation
page read and write
1329000
heap
page read and write
367E000
stack
page read and write
15EE000
stack
page read and write
56CE000
stack
page read and write
2EE0000
direct allocation
page read and write
4CBF000
stack
page read and write
12E0000
heap
page read and write
1224000
heap
page read and write
5150000
direct allocation
page read and write
1224000
heap
page read and write
568E000
stack
page read and write
1224000
heap
page read and write
317E000
stack
page read and write
2EE0000
direct allocation
page read and write
137F000
heap
page read and write
1365000
heap
page read and write
137E000
heap
page read and write
131F000
heap
page read and write
1224000
heap
page read and write
1329000
heap
page read and write
33BF000
stack
page read and write
EDC000
stack
page read and write
3B7E000
stack
page read and write
132E000
heap
page read and write
5150000
direct allocation
page read and write
47BF000
stack
page read and write
1364000
heap
page read and write
1224000
heap
page read and write
1224000
heap
page read and write
1224000
heap
page read and write
457E000
stack
page read and write
13BF000
heap
page read and write
52B0000
direct allocation
page execute and read and write
There are 184 hidden memdumps, click here to show them.