IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.store
malicious
dissapoiznw.store
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com/profiles/765611997243319009U
unknown
malicious
eaglepawnoy.store
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
bathdoomgaz.store
malicious
clearancek.site
malicious
spirittunek.store
malicious
licendfilteo.site
malicious
mobbipenju.store
malicious
https://sergei-esenin.com/api
172.67.206.204
malicious
https://community.akamai.steamstatic.com/public/css/skin_1/heade
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://community.akas#
unknown
https://eaglepawnoy.store:443/api
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbc
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_globa
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.akam
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=M7aU
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_san
unknown
https://store.steampowered.com/points/shop/
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://community.akamai.steamstatic.com/publi
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://sergei-esenin.com:443/api
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=2Ih2WOq7ErXY&a
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://community.akamai.steamstw&
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://avatars.akamai.steamstatic
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://sergei-esenin.com/S
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://mobbipenju.store/apiE
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/public/javascript/g&
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://sergei-esenin.com/apiU
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.akamai.steamstatic.co
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.akaw$
unknown
https://steamcommunity.com/workshop/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=Gu9gs5hf
unknown
https://community.akamai.steamstatic.com/public/sharel#
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://steamcommunity.c
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=IZH_ONwLX4kw&l=e
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://avatars.akamai.
unknown
https://studennotediw.store:443/api
unknown
https://community.aka
unknown
https://mobbipenju.store:443/api
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://steamcommunity.com/QR_
unknown
https://clearancek.site:443/apii
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://spirittunek.store:443/api
unknown
https://steamcommunity.com:443/profiles/76561199724331900g;
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
https://dissapoiznw.store:443/api::
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
104.102.49.254
malicious
sergei-esenin.com
172.67.206.204
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States
malicious
172.67.206.204
sergei-esenin.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
1001000
unkown
page execute and read and write
malicious
4B40000
direct allocation
page execute and read and write
4B00000
direct allocation
page execute and read and write
49A0000
direct allocation
page read and write
942000
heap
page read and write
5000000
remote allocation
page read and write
12F9000
unkown
page execute and read and write
428F000
stack
page read and write
2BCF000
stack
page read and write
4511000
heap
page read and write
1311000
unkown
page execute and write copy
4B30000
direct allocation
page execute and read and write
310F000
stack
page read and write
3ECF000
stack
page read and write
388F000
stack
page read and write
324F000
stack
page read and write
FDE000
stack
page read and write
F5E000
stack
page read and write
4EEE000
stack
page read and write
4511000
heap
page read and write
4AF0000
direct allocation
page execute and read and write
45C000
stack
page read and write
E8B000
stack
page read and write
314E000
stack
page read and write
3C8E000
stack
page read and write
4511000
heap
page read and write
8B0000
direct allocation
page read and write
8B0000
direct allocation
page read and write
514E000
stack
page read and write
8CE000
heap
page read and write
4511000
heap
page read and write
89E000
stack
page read and write
4B20000
direct allocation
page execute and read and write
440E000
stack
page read and write
5000000
remote allocation
page read and write
4511000
heap
page read and write
328E000
stack
page read and write
49DE000
stack
page read and write
4B20000
direct allocation
page execute and read and write
4B20000
direct allocation
page execute and read and write
3C4F000
stack
page read and write
4511000
heap
page read and write
1001000
unkown
page execute and write copy
94D000
heap
page read and write
4B50000
direct allocation
page execute and read and write
450F000
stack
page read and write
360F000
stack
page read and write
8B0000
direct allocation
page read and write
8CA000
heap
page read and write
4511000
heap
page read and write
945000
heap
page read and write
ECE000
stack
page read and write
F0E000
stack
page read and write
94C000
heap
page read and write
8B0000
direct allocation
page read and write
4511000
heap
page read and write
34CF000
stack
page read and write
2DCF000
stack
page read and write
414F000
stack
page read and write
4D6D000
stack
page read and write
338F000
stack
page read and write
8B0000
direct allocation
page read and write
ABE000
stack
page read and write
51BE000
stack
page read and write
1311000
unkown
page execute and read and write
3B4E000
stack
page read and write
400F000
stack
page read and write
1301000
unkown
page execute and read and write
951000
heap
page read and write
4510000
heap
page read and write
956000
heap
page read and write
4511000
heap
page read and write
1312000
unkown
page execute and write copy
49A0000
direct allocation
page read and write
4511000
heap
page read and write
85E000
stack
page read and write
4EAE000
stack
page read and write
5000000
remote allocation
page read and write
8B0000
direct allocation
page read and write
4B20000
direct allocation
page execute and read and write
8B0000
direct allocation
page read and write
4511000
heap
page read and write
4DAE000
stack
page read and write
4610000
trusted library allocation
page read and write
4C6D000
stack
page read and write
39CF000
stack
page read and write
8B0000
direct allocation
page read and write
12CD000
unkown
page execute and read and write
4511000
heap
page read and write
3F0E000
stack
page read and write
4511000
heap
page read and write
404E000
stack
page read and write
2FCF000
stack
page read and write
680000
heap
page read and write
378E000
stack
page read and write
8B0000
direct allocation
page read and write
8A0000
heap
page read and write
F9E000
stack
page read and write
2ECF000
stack
page read and write
1000000
unkown
page readonly
715000
heap
page read and write
4520000
heap
page read and write
14B2000
unkown
page execute and read and write
11E6000
unkown
page execute and read and write
4511000
heap
page read and write
43CF000
stack
page read and write
8FE000
heap
page read and write
4ADF000
stack
page read and write
14B3000
unkown
page execute and write copy
930000
heap
page read and write
33CE000
stack
page read and write
F17000
heap
page read and write
8B0000
direct allocation
page read and write
1060000
unkown
page execute and read and write
905000
heap
page read and write
4B20000
direct allocation
page execute and read and write
8B0000
direct allocation
page read and write
4511000
heap
page read and write
921000
heap
page read and write
300E000
stack
page read and write
4511000
heap
page read and write
2ACF000
stack
page read and write
364E000
stack
page read and write
8B0000
direct allocation
page read and write
3DCE000
stack
page read and write
4B10000
direct allocation
page execute and read and write
498D000
stack
page read and write
29CF000
stack
page read and write
4511000
heap
page read and write
4511000
heap
page read and write
4B73000
trusted library allocation
page read and write
418E000
stack
page read and write
38CE000
stack
page read and write
8F9000
heap
page read and write
8B0000
direct allocation
page read and write
3D8F000
stack
page read and write
4B60000
direct allocation
page execute and read and write
55D000
stack
page read and write
6EE000
stack
page read and write
9AC000
heap
page read and write
9A0000
heap
page read and write
42CE000
stack
page read and write
4511000
heap
page read and write
504D000
stack
page read and write
710000
heap
page read and write
1000000
unkown
page read and write
52BF000
stack
page read and write
902000
heap
page read and write
2CCF000
stack
page read and write
374F000
stack
page read and write
49A0000
direct allocation
page read and write
FE0000
heap
page read and write
350E000
stack
page read and write
8C0000
heap
page read and write
F10000
heap
page read and write
5A0000
heap
page read and write
4B2D000
stack
page read and write
81F000
stack
page read and write
90E000
heap
page read and write
8B0000
direct allocation
page read and write
3A0E000
stack
page read and write
3B0F000
stack
page read and write
956000
heap
page read and write
951000
heap
page read and write
4B20000
direct allocation
page execute and read and write
4FEF000
stack
page read and write
There are 156 hidden memdumps, click here to show them.