IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.store
malicious
dissapoiznw.store
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
eaglepawnoy.store
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
bathdoomgaz.store
malicious
clearancek.site
malicious
spirittunek.store
malicious
licendfilteo.site
malicious
mobbipenju.store
malicious
https://sergei-esenin.com/api
172.67.206.204
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://sergei-esenin.com/api(g
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=M7aU
unknown
https://store.steampowered.com/points/shop/
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
https://sergei-esenin.com:443/apifiles/76561199724331900
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=2Ih2WOq7ErXY&a
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://avatars.akamai.steamstatic
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=Gu9gs5hf
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=IZH_ONwLX4kw&l=e
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
http://127.0.0.1:27060
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.akamai.steamstatic.com/public/shared/css/buttons.css?v=PUJIfhtcQn7W&l=english
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/profile.js?v=f3vWO7swdDqp&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalContent.js?v=f2hMA1v9Zkc8&l=engl
unknown
There are 87 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
104.102.49.254
malicious
sergei-esenin.com
172.67.206.204
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious
s-part-0036.t-0009.t-msedge.net
13.107.246.64
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States
malicious
172.67.206.204
sergei-esenin.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
EF1000
unkown
page execute and read and write
malicious
4921000
heap
page read and write
2EBF000
stack
page read and write
CB8000
heap
page read and write
CB9000
heap
page read and write
C54000
heap
page read and write
4921000
heap
page read and write
3DBF000
stack
page read and write
11B1000
unkown
page execute and read and write
4DA0000
direct allocation
page read and write
2DBE000
stack
page read and write
C30000
heap
page read and write
4921000
heap
page read and write
1393000
unkown
page execute and read and write
C79000
heap
page read and write
C28000
heap
page read and write
467F000
stack
page read and write
3B3F000
stack
page read and write
4F40000
direct allocation
page execute and read and write
3CBE000
stack
page read and write
C36000
heap
page read and write
39FF000
stack
page read and write
10CB000
unkown
page execute and read and write
42BF000
stack
page read and write
48FF000
stack
page read and write
4F20000
direct allocation
page execute and read and write
B80000
direct allocation
page read and write
46BE000
stack
page read and write
4900000
heap
page read and write
BF0000
heap
page read and write
1394000
unkown
page execute and write copy
4F20000
direct allocation
page execute and read and write
DEF000
stack
page read and write
9B0000
heap
page read and write
4F50000
direct allocation
page execute and read and write
2C3F000
stack
page read and write
BDE000
stack
page read and write
EF0000
unkown
page readonly
B80000
direct allocation
page read and write
CB9000
heap
page read and write
42FE000
stack
page read and write
4DA0000
direct allocation
page read and write
4F00000
direct allocation
page execute and read and write
CB2000
heap
page read and write
11DF000
unkown
page execute and read and write
4F20000
direct allocation
page execute and read and write
B80000
direct allocation
page read and write
417F000
stack
page read and write
B80000
direct allocation
page read and write
519E000
stack
page read and write
B80000
direct allocation
page read and write
34FF000
stack
page read and write
32BE000
stack
page read and write
367E000
stack
page read and write
C51000
heap
page read and write
4921000
heap
page read and write
A90000
heap
page read and write
43FF000
stack
page read and write
3DFE000
stack
page read and write
B80000
direct allocation
page read and write
11E7000
unkown
page execute and read and write
4F30000
direct allocation
page execute and read and write
4F6F000
trusted library allocation
page read and write
363F000
stack
page read and write
4921000
heap
page read and write
C34000
heap
page read and write
33FE000
stack
page read and write
4921000
heap
page read and write
B80000
direct allocation
page read and write
B80000
direct allocation
page read and write
353E000
stack
page read and write
4921000
heap
page read and write
BFE000
heap
page read and write
11F5000
unkown
page execute and write copy
11F6000
unkown
page execute and write copy
BFA000
heap
page read and write
4921000
heap
page read and write
505E000
stack
page read and write
CB8000
heap
page read and write
B80000
direct allocation
page read and write
4921000
heap
page read and write
53F0000
remote allocation
page read and write
4F2D000
stack
page read and write
4921000
heap
page read and write
EF0000
unkown
page read and write
56AF000
stack
page read and write
CB8000
heap
page read and write
407E000
stack
page read and write
C68000
heap
page read and write
C67000
heap
page read and write
B80000
direct allocation
page read and write
453F000
stack
page read and write
4921000
heap
page read and write
4921000
heap
page read and write
B90000
heap
page read and write
CC2000
heap
page read and write
4F20000
direct allocation
page execute and read and write
38FE000
stack
page read and write
4EF0000
direct allocation
page execute and read and write
C3F000
heap
page read and write
4EDF000
stack
page read and write
85C000
stack
page read and write
B80000
direct allocation
page read and write
C51000
heap
page read and write
4F20000
direct allocation
page execute and read and write
B5E000
stack
page read and write
4D9D000
stack
page read and write
4920000
heap
page read and write
529F000
stack
page read and write
CB2000
heap
page read and write
4DDE000
stack
page read and write
4F20000
direct allocation
page execute and read and write
53F0000
remote allocation
page read and write
C7A000
heap
page read and write
B70000
heap
page read and write
53F0000
remote allocation
page read and write
C3A000
heap
page read and write
4F10000
direct allocation
page execute and read and write
AC5000
heap
page read and write
B80000
direct allocation
page read and write
544D000
stack
page read and write
327F000
stack
page read and write
F50000
unkown
page execute and read and write
515D000
stack
page read and write
CB1000
heap
page read and write
AC0000
heap
page read and write
2FFF000
stack
page read and write
B80000
direct allocation
page read and write
B97000
heap
page read and write
303E000
stack
page read and write
3C7F000
stack
page read and write
C54000
heap
page read and write
4921000
heap
page read and write
B0E000
stack
page read and write
3B7E000
stack
page read and write
11F5000
unkown
page execute and read and write
4921000
heap
page read and write
2EFE000
stack
page read and write
4921000
heap
page read and write
4921000
heap
page read and write
EF1000
unkown
page execute and write copy
4921000
heap
page read and write
4921000
heap
page read and write
2D7F000
stack
page read and write
47BF000
stack
page read and write
38BF000
stack
page read and write
33BF000
stack
page read and write
95D000
stack
page read and write
52DE000
stack
page read and write
47FE000
stack
page read and write
EEF000
stack
page read and write
4930000
heap
page read and write
C39000
heap
page read and write
55AE000
stack
page read and write
313F000
stack
page read and write
3F3E000
stack
page read and write
554D000
stack
page read and write
53DE000
stack
page read and write
4921000
heap
page read and write
B80000
direct allocation
page read and write
3A3E000
stack
page read and write
4DA0000
direct allocation
page read and write
443E000
stack
page read and write
41BE000
stack
page read and write
4D60000
trusted library allocation
page read and write
403F000
stack
page read and write
317E000
stack
page read and write
C3F000
heap
page read and write
37BE000
stack
page read and write
457E000
stack
page read and write
3EFF000
stack
page read and write
C7A000
heap
page read and write
CB2000
heap
page read and write
4921000
heap
page read and write
377F000
stack
page read and write
2C7C000
stack
page read and write
There are 166 hidden memdumps, click here to show them.