IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.store
malicious
dissapoiznw.store
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com:443/profiles/76561199724331900
unknown
malicious
eaglepawnoy.store
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
bathdoomgaz.store
malicious
clearancek.site
malicious
spirittunek.store
malicious
licendfilteo.site
malicious
https://player.vimeo.com
unknown
https://avatars.akamai.steamstatic5(
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://steamcommunity.com/linkfilter/?
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
https://spirittunek.store:443/apidG
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://avatars.akamai
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://store.steTp
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=N
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://community.akamai.steamstati
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://store.steampowered.com/mo
unknown
https://broadcast.st.dl.ecc
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=M7aU
unknown
https://store.steampowered.com/points/shop/
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://avatars.akamai.s
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://sergei-esenin.com:443/api
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=2Ih2WOq7ErXY&a
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://sergei-esenin.com/apir
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://login.steampowered.com/Cp
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/as
unknown
https://community.akamai.steamstatic.com/public/c
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
https://community.akamai.steamstatic.com/pu
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/applica
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://dissapoiznw.store:443/api
unknown
https://community.akamai.steamstatic.com/public/shared/javas
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=Gu9gs5hf
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=IZH_ONwLX4kw&l=e
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
104.102.49.254
malicious
sergei-esenin.com
104.21.53.8
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious
bg.microsoft.map.fastly.net
199.232.214.172
fp2e7a.wpc.phicdn.net
192.229.221.95
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.21.53.8
sergei-esenin.com
United States
malicious
104.102.49.254
steamcommunity.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
9E1000
unkown
page execute and read and write
malicious
500000
heap
page read and write
438E000
stack
page read and write
3ACD000
stack
page read and write
4A70000
direct allocation
page execute and read and write
9E1000
unkown
page execute and write copy
26D0000
direct allocation
page read and write
26D0000
direct allocation
page read and write
3E4F000
stack
page read and write
4FAD000
stack
page read and write
370E000
stack
page read and write
697000
heap
page read and write
4A60000
direct allocation
page execute and read and write
4CFE000
stack
page read and write
384E000
stack
page read and write
6F7000
heap
page read and write
6A8000
heap
page read and write
358F000
stack
page read and write
2F8E000
stack
page read and write
734000
heap
page read and write
4491000
heap
page read and write
4F3F000
stack
page read and write
494C000
stack
page read and write
380F000
stack
page read and write
31CF000
stack
page read and write
6A4000
heap
page read and write
4ACB000
trusted library allocation
page read and write
420F000
stack
page read and write
6F7000
heap
page read and write
26D0000
direct allocation
page read and write
6C0000
heap
page read and write
560000
heap
page read and write
6CF000
heap
page read and write
26D0000
direct allocation
page read and write
3D4E000
stack
page read and write
4491000
heap
page read and write
3C0E000
stack
page read and write
434F000
stack
page read and write
66E000
heap
page read and write
448F000
stack
page read and write
4A80000
direct allocation
page execute and read and write
4491000
heap
page read and write
6EE000
heap
page read and write
4BBE000
stack
page read and write
26D0000
direct allocation
page read and write
4491000
heap
page read and write
30CE000
stack
page read and write
712000
heap
page read and write
4DFF000
stack
page read and write
660000
heap
page read and write
4491000
heap
page read and write
3FCE000
stack
page read and write
E9E000
unkown
page execute and read and write
26CB000
stack
page read and write
6EE000
heap
page read and write
4A90000
direct allocation
page execute and read and write
4491000
heap
page read and write
CB5000
unkown
page execute and read and write
330F000
stack
page read and write
2707000
heap
page read and write
6F7000
heap
page read and write
6F7000
heap
page read and write
1F0000
heap
page read and write
26F0000
direct allocation
page read and write
4A80000
direct allocation
page execute and read and write
9DF000
stack
page read and write
697000
heap
page read and write
72F000
heap
page read and write
CF8000
unkown
page execute and read and write
26D0000
direct allocation
page read and write
9E0000
unkown
page readonly
712000
heap
page read and write
737000
heap
page read and write
712000
heap
page read and write
4A8D000
stack
page read and write
4491000
heap
page read and write
4CBD000
stack
page read and write
6AE000
heap
page read and write
26D0000
direct allocation
page read and write
2E0F000
stack
page read and write
3BCE000
stack
page read and write
2A8E000
stack
page read and write
410E000
stack
page read and write
26D0000
direct allocation
page read and write
4F50000
remote allocation
page read and write
4491000
heap
page read and write
CE1000
unkown
page execute and read and write
4490000
heap
page read and write
4AA0000
direct allocation
page execute and read and write
4A80000
direct allocation
page execute and read and write
268E000
stack
page read and write
4910000
direct allocation
page read and write
734000
heap
page read and write
4E3E000
stack
page read and write
398E000
stack
page read and write
26D0000
direct allocation
page read and write
2A4F000
stack
page read and write
731000
heap
page read and write
734000
heap
page read and write
6CF000
heap
page read and write
40CF000
stack
page read and write
348E000
stack
page read and write
4491000
heap
page read and write
6C3000
heap
page read and write
6A4000
heap
page read and write
4F50000
remote allocation
page read and write
66A000
heap
page read and write
26D0000
direct allocation
page read and write
693000
heap
page read and write
2B8F000
stack
page read and write
6A9000
heap
page read and write
4A80000
direct allocation
page execute and read and write
6C4000
heap
page read and write
4AB0000
direct allocation
page execute and read and write
6A0000
heap
page read and write
26F0000
direct allocation
page read and write
394F000
stack
page read and write
6CF000
heap
page read and write
9E0000
unkown
page read and write
72C000
heap
page read and write
734000
heap
page read and write
6C0000
heap
page read and write
2E4E000
stack
page read and write
6AE000
heap
page read and write
72F000
heap
page read and write
2CCF000
stack
page read and write
550000
heap
page read and write
3F8F000
stack
page read and write
E9F000
unkown
page execute and write copy
4A50000
direct allocation
page execute and read and write
2700000
heap
page read and write
6A0000
heap
page read and write
A40000
unkown
page execute and read and write
6F3000
heap
page read and write
4491000
heap
page read and write
6F4000
heap
page read and write
424E000
stack
page read and write
4590000
trusted library allocation
page read and write
4FD000
stack
page read and write
2D0E000
stack
page read and write
294E000
stack
page read and write
4A80000
direct allocation
page execute and read and write
640000
heap
page read and write
490E000
stack
page read and write
4A4F000
stack
page read and write
734000
heap
page read and write
36CF000
stack
page read and write
44A0000
heap
page read and write
4491000
heap
page read and write
4491000
heap
page read and write
6EE000
heap
page read and write
4491000
heap
page read and write
6AE000
heap
page read and write
CF9000
unkown
page execute and write copy
CF8000
unkown
page execute and write copy
565000
heap
page read and write
6F7000
heap
page read and write
6F3000
heap
page read and write
334E000
stack
page read and write
3D0F000
stack
page read and write
26D0000
direct allocation
page read and write
2F4F000
stack
page read and write
4491000
heap
page read and write
344F000
stack
page read and write
308F000
stack
page read and write
72F000
heap
page read and write
712000
heap
page read and write
6CF000
heap
page read and write
2BCE000
stack
page read and write
26D0000
direct allocation
page read and write
320E000
stack
page read and write
740000
heap
page read and write
6C0000
heap
page read and write
50AE000
stack
page read and write
BCF000
unkown
page execute and read and write
290F000
stack
page read and write
26D0000
direct allocation
page read and write
72F000
heap
page read and write
4491000
heap
page read and write
72F000
heap
page read and write
6F7000
heap
page read and write
4F50000
remote allocation
page read and write
4491000
heap
page read and write
89F000
stack
page read and write
3E8E000
stack
page read and write
19C000
stack
page read and write
712000
heap
page read and write
4491000
heap
page read and write
35CE000
stack
page read and write
4491000
heap
page read and write
8DE000
stack
page read and write
280F000
stack
page read and write
CE8000
unkown
page execute and read and write
26D0000
direct allocation
page read and write
79E000
stack
page read and write
6EE000
heap
page read and write
3A8F000
stack
page read and write
520F000
stack
page read and write
510E000
stack
page read and write
4A80000
direct allocation
page execute and read and write
4491000
heap
page read and write
712000
heap
page read and write
There are 192 hidden memdumps, click here to show them.