IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
bathdoomgaz.store
malicious
studennotediw.store
malicious
clearancek.site
malicious
dissapoiznw.store
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
spirittunek.store
malicious
licendfilteo.site
malicious
eaglepawnoy.store
malicious
mobbipenju.store
malicious
https://sergei-esenin.com/api
172.67.206.204
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://steamcommunity.com/my/wishlist/
unknown
https://player.vimeo.com
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7C0e3d185a3e106e7
unknown
https://community.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL&l=
unknown
https://community.steamstatic.com/public/javascript/promo/stickers.js?v=W8NP8aTVqtms&l=english
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.steamstatic.com/public/shared/css/motiva_sans.css?v=v7XTmVzbLV33&l=english
unknown
https://community.steamstatic.com/public/javascript/global.js?v=7qlUmHSJhPRN&l=english
unknown
https://sergei-esenin.com/
unknown
https://community.steamstatic.com/public/css/globalv2.css?v=dQy8Omh4p9PH&l=english
unknown
https://community.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.steamstatic.com/public/javascript/applications/community/manifest.js?v=r7a4-LYcQOj
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://steamcommunity.com/discussions/
unknown
https://www.youtube.com
unknown
https://www.google.com
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://community.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.steamstatic.com/public/shared/css/buttons.css?v=-WV9f1LdxEjq&l=english
unknown
https://community.steamstatic.com/public/javascript/applications/community/libraries~b28b7af69.js?v=
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steamcommunity.com/K
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://cdn.fastly.steamstatic.com/steamcommunity/public/assets/
unknown
https://avatars.fastly.steamstatic.com/fef49e7fa7e1997310d705b2a61
unknown
https://community.steamstatic.com/
unknown
https://community.steamstatic.com/public/css/applications/community/main.css?v=DVae4t4RZiHA&l=en
unknown
https://s.ytimg.com;
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://community.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://steam.tv/
unknown
https://community.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.steamstatic.com/public/javascript/profile.js?v=bbs9uq0gqJ-H&l=english
unknown
https://community.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://community.steamstatic.com/public/css/skin_1/header.css?v=pTvrRy1pm52p&l=english
unknown
https://community.steamstatic.com/public/css/skin_1/profilev2.css?v=t9xiI4DlPpEB&l=english
unknown
https://store.steampowered.com/points/shop/
unknown
https://recaptcha.net
unknown
https://community.steamstatic.com/public/javascript/applications/community/main.js?v=4XouecKy8sZy&am
unknown
https://store.steampowered.com/
unknown
https://community.steamstatic.com/public/shared/javascript/shared_global.js?v=7glT1n_nkVCs&l=eng
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
http://127.0.0.1:27060
unknown
https://avatars.fastly.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://community.steamstatic.com/public/shared/css/shared_global.css?v=uF6G1wyNU-4c&l=english
unknown
https://community.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=english
unknown
https://community.steamstatic.com/public/javascript/webui/clientcom.js?v=jq1jQyX1843y&l=english
unknown
https://community.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&l=engl
unknown
https://community.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
https://community.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSvIAKtunf
unknown
https://community.steamstatic.com/public/shared/css/shared_responsive.css?v=kR9MtmbWSZEp&l=engli
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
https://store.steampowered.com/;
unknown
https://community.steamstatic.com/public/css/promo/summer2017/stickers.css?v=P8gOPraCSjV6&l=engl
unknown
https://store.steampowered.com/about/
unknown
There are 78 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
104.102.49.254
malicious
sergei-esenin.com
172.67.206.204
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States
malicious
172.67.206.204
sergei-esenin.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
481000
unkown
page execute and read and write
malicious
41E0000
heap
page read and write
460000
heap
page read and write
480000
unkown
page read and write
4E0000
unkown
page execute and read and write
704000
unkown
page execute and write copy
355F000
stack
page read and write
359E000
stack
page read and write
659000
unkown
page execute and read and write
4820000
direct allocation
page execute and read and write
B2E000
stack
page read and write
4820000
direct allocation
page execute and read and write
4211000
heap
page read and write
3D1E000
stack
page read and write
4211000
heap
page read and write
771000
unkown
page execute and read and write
802000
heap
page read and write
87A000
heap
page read and write
4820000
direct allocation
page execute and read and write
4EAE000
stack
page read and write
495E000
stack
page read and write
77B000
unkown
page execute and write copy
7D9000
heap
page read and write
450000
heap
page read and write
6D3000
unkown
page execute and write copy
4211000
heap
page read and write
66B000
unkown
page execute and write copy
4200000
direct allocation
page read and write
80E000
heap
page read and write
41DF000
stack
page read and write
240E000
stack
page read and write
1FD000
stack
page read and write
682000
unkown
page execute and read and write
2517000
heap
page read and write
789000
unkown
page execute and write copy
395E000
stack
page read and write
68B000
unkown
page execute and read and write
4211000
heap
page read and write
4200000
direct allocation
page read and write
7EE000
heap
page read and write
4211000
heap
page read and write
669000
unkown
page execute and write copy
771000
unkown
page execute and write copy
279F000
stack
page read and write
830000
heap
page read and write
4650000
trusted library allocation
page read and write
717000
unkown
page execute and write copy
FC000
stack
page read and write
743000
unkown
page execute and read and write
4211000
heap
page read and write
4FAF000
stack
page read and write
2CDE000
stack
page read and write
4200000
direct allocation
page read and write
2B9E000
stack
page read and write
7EE000
heap
page read and write
309E000
stack
page read and write
666000
unkown
page execute and write copy
3CDF000
stack
page read and write
2510000
heap
page read and write
2A5E000
stack
page read and write
2F5E000
stack
page read and write
830000
heap
page read and write
32DF000
stack
page read and write
6C1000
unkown
page execute and write copy
4E0000
unkown
page execute and write copy
255B000
stack
page read and write
3BDE000
stack
page read and write
4211000
heap
page read and write
4830000
direct allocation
page execute and read and write
4B1A000
trusted library allocation
page read and write
7E8000
heap
page read and write
4B27000
trusted library allocation
page read and write
3A5F000
stack
page read and write
800000
heap
page read and write
480000
unkown
page readonly
4820000
direct allocation
page execute and read and write
667000
unkown
page execute and read and write
80E000
heap
page read and write
2F1F000
stack
page read and write
830000
heap
page read and write
803000
heap
page read and write
3E1F000
stack
page read and write
4820000
direct allocation
page execute and read and write
6CF000
unkown
page execute and write copy
772000
unkown
page execute and write copy
3F9E000
stack
page read and write
31DE000
stack
page read and write
3B9F000
stack
page read and write
4211000
heap
page read and write
6E8000
unkown
page execute and write copy
7E9000
heap
page read and write
482E000
stack
page read and write
341F000
stack
page read and write
4200000
direct allocation
page read and write
4CDF000
stack
page read and write
7F3000
heap
page read and write
861000
heap
page read and write
830000
heap
page read and write
4CF0000
remote allocation
page read and write
36DE000
stack
page read and write
345E000
stack
page read and write
409F000
stack
page read and write
65C000
unkown
page execute and write copy
647000
unkown
page execute and read and write
2C9F000
stack
page read and write
6FC000
unkown
page execute and read and write
68A000
unkown
page execute and write copy
7E4000
heap
page read and write
4211000
heap
page read and write
66D000
unkown
page execute and read and write
2DDF000
stack
page read and write
7AA000
heap
page read and write
4200000
direct allocation
page read and write
6AA000
unkown
page execute and read and write
46A0000
direct allocation
page read and write
764000
unkown
page execute and write copy
4220000
heap
page read and write
70F000
unkown
page execute and write copy
7AE000
heap
page read and write
4211000
heap
page read and write
468D000
stack
page read and write
4820000
direct allocation
page execute and read and write
46DE000
stack
page read and write
710000
unkown
page execute and read and write
4200000
direct allocation
page read and write
4211000
heap
page read and write
391F000
stack
page read and write
47DF000
stack
page read and write
4200000
direct allocation
page read and write
800000
heap
page read and write
7A0000
heap
page read and write
4211000
heap
page read and write
6C7000
unkown
page execute and read and write
830000
heap
page read and write
4211000
heap
page read and write
4D4D000
stack
page read and write
6EC000
unkown
page execute and read and write
4200000
direct allocation
page read and write
66E000
unkown
page execute and write copy
7EE000
heap
page read and write
4200000
direct allocation
page read and write
4A1C000
trusted library allocation
page read and write
3A9E000
stack
page read and write
3E5E000
stack
page read and write
66A000
unkown
page execute and read and write
7DF000
heap
page read and write
8C0000
heap
page read and write
28DF000
stack
page read and write
4B31000
trusted library allocation
page read and write
4A9E000
stack
page read and write
369F000
stack
page read and write
381E000
stack
page read and write
4211000
heap
page read and write
481000
unkown
page execute and write copy
4200000
direct allocation
page read and write
4CF0000
remote allocation
page read and write
37DF000
stack
page read and write
4211000
heap
page read and write
46A0000
direct allocation
page read and write
82B000
heap
page read and write
2B5F000
stack
page read and write
788000
unkown
page execute and write copy
77B000
unkown
page execute and write copy
250F000
stack
page read and write
265F000
stack
page read and write
6EA000
unkown
page execute and write copy
46A0000
direct allocation
page read and write
305F000
stack
page read and write
4200000
direct allocation
page read and write
82B000
heap
page read and write
4850000
direct allocation
page execute and read and write
671000
unkown
page execute and read and write
6F5000
unkown
page execute and write copy
4840000
direct allocation
page execute and read and write
681000
unkown
page execute and write copy
4211000
heap
page read and write
9EE000
stack
page read and write
80E000
heap
page read and write
6E9000
unkown
page execute and read and write
869000
heap
page read and write
4A5D000
stack
page read and write
82B000
heap
page read and write
800000
heap
page read and write
291E000
stack
page read and write
4810000
direct allocation
page execute and read and write
4B9F000
stack
page read and write
486F000
trusted library allocation
page read and write
696000
unkown
page execute and write copy
706000
unkown
page execute and read and write
802000
heap
page read and write
6D8000
unkown
page execute and read and write
718000
unkown
page execute and read and write
4800000
direct allocation
page execute and read and write
47F0000
direct allocation
page execute and read and write
4BDE000
stack
page read and write
40DE000
stack
page read and write
4200000
direct allocation
page read and write
65E000
unkown
page execute and read and write
C2E000
stack
page read and write
80E000
heap
page read and write
82A000
heap
page read and write
8D5000
heap
page read and write
269E000
stack
page read and write
4211000
heap
page read and write
4200000
direct allocation
page read and write
4E4D000
stack
page read and write
8D0000
heap
page read and write
4210000
heap
page read and write
6D2000
unkown
page execute and read and write
AEE000
stack
page read and write
4EC000
unkown
page execute and write copy
788000
unkown
page execute and read and write
4CF0000
remote allocation
page read and write
863000
heap
page read and write
2A1F000
stack
page read and write
80E000
heap
page read and write
331E000
stack
page read and write
4211000
heap
page read and write
4B3D000
trusted library allocation
page read and write
27DE000
stack
page read and write
872000
heap
page read and write
7E9000
heap
page read and write
3F5F000
stack
page read and write
4200000
direct allocation
page read and write
2E1E000
stack
page read and write
4211000
heap
page read and write
649000
unkown
page execute and write copy
319F000
stack
page read and write
There are 218 hidden memdumps, click here to show them.