IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.store
malicious
dissapoiznw.store
malicious
https://steamcommunity.com/profiles/76561199724331900
23.192.247.89
malicious
https://steamcommunity.com:443/profiles/76561199724331900
unknown
malicious
eaglepawnoy.store
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
bathdoomgaz.store
malicious
clearancek.site
malicious
spirittunek.store
malicious
licendfilteo.site
malicious
https://player.vimeo.com
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://store.steampowered.com/;Persis
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://www.google.com
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://licendfilteo.site:443/api
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=M7aU
unknown
https://store.steampowered.com/points/shop/
unknown
https://store.stx
unknown
https://sketchfab.com
unknown
https://bathdoomgaz.store:443/apiT
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://cdn.akam
unknown
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://sergei-esenin.com:443/api
unknown
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=2Ih2WOq7ErXY&a
unknown
https://sergei-esenin.com/i
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
unknown
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://avatars.akamai.steamstatic
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
unknown
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://store.steampowered.com/;
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://sergei-esenin.com/apib
unknown
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
unknown
https://help.steampowered.com/en/
unknown
https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.akamai.steamstatic.com/
unknown
https://sergei-esenin.com/apif
unknown
https://help.steampowe
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://sergei-esenin.com/apiY
unknown
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://help.steampo
unknown
https://steambroadcast.f
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.akamai.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=e
unknown
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=Gu9gs5hf
unknown
https://community.akamai.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSv
unknown
https://community.akamai.steamstatic.com/public/shared/css/motiva_sans.css?v=-DH0xTYpnVe2&l=engl
unknown
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=IZH_ONwLX4kw&l=e
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.akamai.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://studennotediw.store:443/api
unknown
https://community.akamai.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
http://127.0.0.1:27060
unknown
https://clearancek.site:443/apii
unknown
https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://spirittunek.store:443/api
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
23.192.247.89
malicious
sergei-esenin.com
172.67.206.204
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious

IPs

IP
Domain
Country
Malicious
23.192.247.89
steamcommunity.com
United States
malicious
172.67.206.204
sergei-esenin.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
B91000
unkown
page execute and read and write
malicious
58BD000
stack
page read and write
5200000
direct allocation
page execute and read and write
AD4000
heap
page read and write
11F0000
direct allocation
page read and write
50A0000
direct allocation
page read and write
5210000
direct allocation
page execute and read and write
4C21000
heap
page read and write
15F5000
heap
page read and write
163C000
heap
page read and write
AD4000
heap
page read and write
3F9F000
stack
page read and write
AD4000
heap
page read and write
54FE000
stack
page read and write
11F0000
direct allocation
page read and write
AD0000
heap
page read and write
349F000
stack
page read and write
3ADE000
stack
page read and write
5080000
remote allocation
page read and write
4C21000
heap
page read and write
1035000
unkown
page execute and write copy
1662000
heap
page read and write
5060000
trusted library allocation
page read and write
15BA000
heap
page read and write
1662000
heap
page read and write
411E000
stack
page read and write
35DE000
stack
page read and write
3D1F000
stack
page read and write
E4E000
unkown
page execute and read and write
3090000
heap
page read and write
51DF000
stack
page read and write
5220000
direct allocation
page execute and read and write
11E0000
heap
page read and write
421F000
stack
page read and write
A5D000
stack
page read and write
40DF000
stack
page read and write
AD4000
heap
page read and write
15E7000
heap
page read and write
5200000
direct allocation
page execute and read and write
573F000
stack
page read and write
59BD000
stack
page read and write
11DE000
stack
page read and write
3BDF000
stack
page read and write
4C1F000
stack
page read and write
11F0000
direct allocation
page read and write
153E000
stack
page read and write
399E000
stack
page read and write
36DF000
stack
page read and write
15FE000
heap
page read and write
167A000
heap
page read and write
AD4000
heap
page read and write
1034000
unkown
page execute and read and write
E96000
unkown
page execute and write copy
329F000
stack
page read and write
168A000
heap
page read and write
AD4000
heap
page read and write
527D000
stack
page read and write
167A000
heap
page read and write
1614000
heap
page read and write
395F000
stack
page read and write
B90000
unkown
page readonly
5230000
direct allocation
page execute and read and write
51E0000
direct allocation
page execute and read and write
3097000
heap
page read and write
3FDE000
stack
page read and write
E97000
unkown
page execute and write copy
11F0000
direct allocation
page read and write
4B1E000
stack
page read and write
3A9F000
stack
page read and write
1662000
heap
page read and write
11F0000
direct allocation
page read and write
54BD000
stack
page read and write
BF0000
unkown
page execute and read and write
425E000
stack
page read and write
AD4000
heap
page read and write
11F0000
direct allocation
page read and write
E87000
unkown
page execute and read and write
5200000
direct allocation
page execute and read and write
AD4000
heap
page read and write
1672000
heap
page read and write
1590000
direct allocation
page read and write
1678000
heap
page read and write
381F000
stack
page read and write
4C21000
heap
page read and write
449F000
stack
page read and write
4C21000
heap
page read and write
563E000
stack
page read and write
3D5E000
stack
page read and write
1614000
heap
page read and write
587E000
stack
page read and write
5200000
direct allocation
page execute and read and write
B7E000
stack
page read and write
1611000
heap
page read and write
524A000
trusted library allocation
page read and write
115E000
stack
page read and write
AD4000
heap
page read and write
4C30000
heap
page read and write
AD4000
heap
page read and write
304F000
stack
page read and write
AD4000
heap
page read and write
339F000
stack
page read and write
44DE000
stack
page read and write
AB0000
heap
page read and write
AD4000
heap
page read and write
308E000
stack
page read and write
14FF000
stack
page read and write
15FE000
heap
page read and write
4C21000
heap
page read and write
53BD000
stack
page read and write
E96000
unkown
page execute and read and write
11F0000
direct allocation
page read and write
4C21000
heap
page read and write
15F2000
heap
page read and write
D71000
unkown
page execute and read and write
15BE000
heap
page read and write
385E000
stack
page read and write
439E000
stack
page read and write
AC0000
heap
page read and write
E7D000
unkown
page execute and read and write
AD4000
heap
page read and write
359F000
stack
page read and write
475E000
stack
page read and write
537E000
stack
page read and write
B90000
unkown
page read and write
11F0000
direct allocation
page read and write
51F0000
direct allocation
page execute and read and write
15B0000
heap
page read and write
11F0000
direct allocation
page read and write
5060000
heap
page read and write
5200000
direct allocation
page execute and read and write
471F000
stack
page read and write
AD4000
heap
page read and write
11F0000
direct allocation
page read and write
11F0000
direct allocation
page read and write
AD4000
heap
page read and write
119B000
stack
page read and write
11F0000
direct allocation
page read and write
577D000
stack
page read and write
461E000
stack
page read and write
15A0000
direct allocation
page execute and read and write
55FF000
stack
page read and write
50DE000
stack
page read and write
5080000
remote allocation
page read and write
17AF000
stack
page read and write
AD4000
heap
page read and write
AD4000
heap
page read and write
B91000
unkown
page execute and write copy
485F000
stack
page read and write
4ADF000
stack
page read and write
AD4000
heap
page read and write
4C21000
heap
page read and write
3E9E000
stack
page read and write
B3E000
stack
page read and write
AD4000
heap
page read and write
59FE000
stack
page read and write
4C21000
heap
page read and write
AD4000
heap
page read and write
4C21000
heap
page read and write
AD4000
heap
page read and write
371E000
stack
page read and write
5080000
remote allocation
page read and write
AD4000
heap
page read and write
5200000
direct allocation
page execute and read and write
3E5F000
stack
page read and write
1682000
heap
page read and write
5AFF000
stack
page read and write
499F000
stack
page read and write
AD4000
heap
page read and write
11F0000
direct allocation
page read and write
435F000
stack
page read and write
AD4000
heap
page read and write
1590000
direct allocation
page read and write
95C000
stack
page read and write
3C1E000
stack
page read and write
4C20000
heap
page read and write
49DE000
stack
page read and write
AD4000
heap
page read and write
15F2000
heap
page read and write
319F000
stack
page read and write
11F0000
direct allocation
page read and write
15E3000
heap
page read and write
45DF000
stack
page read and write
1611000
heap
page read and write
489E000
stack
page read and write
15E7000
heap
page read and write
15F5000
heap
page read and write
157E000
stack
page read and write
There are 177 hidden memdumps, click here to show them.