IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
https://sergei-esenin.com/
unknown
malicious
https://sergei-esenin.com/(
unknown
malicious
https://sergei-esenin.com:443/apin
unknown
malicious
bathdoomgaz.store
malicious
studennotediw.store
malicious
clearancek.site
malicious
dissapoiznw.store
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
spirittunek.store
malicious
licendfilteo.site
malicious
https://steamcommunity.com:443/profiles/76561199724331900
unknown
malicious
eaglepawnoy.store
malicious
mobbipenju.store
malicious
https://sergei-esenin.com/api
unknown
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://steamcommunity.com/my/wishlist/
unknown
https://player.vimeo.com
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7C0e3d185a3e106e7
unknown
https://community.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL&l=
unknown
https://community.steamstatic.com/public/javascript/promo/stickers.js?v=W8NP8aTVqtms&l=english
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.steamstatic.com/public/shared/css/motiva_sans.css?v=v7XTmVzbLV33&l=english
unknown
https://community.steamstatic.com/public/javascript/global.js?v=7qlUmHSJhPRN&l=english
unknown
https://community.steamstatic.com/public/css/globalv2.css?v=dQy8Omh4p9PH&l=english
unknown
https://community.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.steamstatic.com/public/javascript/applications/community/manifest.js?v=r7a4-LYcQOj
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://licendfilteo.site:443/apii
unknown
https://steamcommunity.com/discussions/
unknown
https://www.youtube.com
unknown
https://www.google.com
unknown
https://store.steampowered.com/stats/
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://community.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.steamstatic.com/public/shared/css/buttons.css?v=-WV9f1LdxEjq&l=english
unknown
https://community.steamstatic.com/public/javascript/applications/community/libraries~b28b7af69.js?v=
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://cdn.fastly.steamstatic.com/steamcommunity/public/assets/
unknown
https://avatars.fastly.steamstatic.com/fef49e7fa7e1997310d705b2a61
unknown
https://community.steamstatic.com/
unknown
https://community.steamstatic.com/public/css/applications/community/main.css?v=DVae4t4RZiHA&l=en
unknown
https://clearancek.site:443/api
unknown
https://s.ytimg.com;
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://community.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://eaglepawnoy.store:443/api
unknown
https://steam.tv/
unknown
https://community.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://community.steamstatic.com/public/javascript/profile.js?v=bbs9uq0gqJ-H&l=english
unknown
https://community.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://community.steamstatic.com/public/css/skin_1/header.css?v=pTvrRy1pm52p&l=english
unknown
https://community.steamstatic.com/public/css/skin_1/profilev2.css?v=t9xiI4DlPpEB&l=english
unknown
https://store.steampowered.com/points/shop/
unknown
https://recaptcha.net
unknown
https://community.steamstatic.com/public/javascript/applications/community/main.js?v=4XouecKy8sZy&am
unknown
https://store.steampowered.com/
unknown
https://community.steamstatic.com/public/shared/javascript/shared_global.js?v=7glT1n_nkVCs&l=eng
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://mobbipenju.store:443/api
unknown
https://www.youtube.com/
unknown
http://127.0.0.1:27060
unknown
https://avatars.fastly.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://community.steamstatic.com/public/shared/css/shared_global.css?v=uF6G1wyNU-4c&l=english
unknown
https://community.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=english
unknown
https://mobbipenju.store/api
unknown
https://community.steamstatic.com/public/javascript/webui/clientcom.js?v=jq1jQyX1843y&l=english
unknown
https://community.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&l=engl
unknown
https://spirittunek.store:443/api
unknown
https://community.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
https://community.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSvIAKtunf
unknown
https://community.steamstatic.com/public/shared/css/shared_responsive.css?v=kR9MtmbWSZEp&l=engli
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
https://store.steampowered.com/;
unknown
https://community.steamstatic.com/public/css/promo/summer2017/stickers.css?v=P8gOPraCSjV6&l=engl
unknown
https://store.steampowered.com/about/
unknown
There are 86 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
104.102.49.254
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious
sergei-esenin.com
172.67.206.204

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States
malicious
172.67.206.204
sergei-esenin.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
E71000
unkown
page execute and read and write
malicious
398F000
stack
page read and write
1069000
unkown
page execute and read and write
17FF000
heap
page read and write
54DD000
stack
page read and write
E6E000
stack
page read and write
1750000
direct allocation
page read and write
4ED1000
heap
page read and write
116D000
unkown
page execute and read and write
17A7000
heap
page read and write
5500000
direct allocation
page execute and read and write
424F000
stack
page read and write
17BE000
heap
page read and write
3ECE000
stack
page read and write
115E000
unkown
page execute and write copy
4ED1000
heap
page read and write
588E000
stack
page read and write
474F000
stack
page read and write
1750000
direct allocation
page read and write
48CE000
stack
page read and write
54D0000
direct allocation
page execute and read and write
54A0000
direct allocation
page execute and read and write
1750000
direct allocation
page read and write
4ED1000
heap
page read and write
1645000
heap
page read and write
414E000
stack
page read and write
4B4E000
stack
page read and write
4ED1000
heap
page read and write
4ED1000
heap
page read and write
1750000
direct allocation
page read and write
460F000
stack
page read and write
4D8F000
stack
page read and write
49CF000
stack
page read and write
17ED000
heap
page read and write
4ED1000
heap
page read and write
384F000
stack
page read and write
35CF000
stack
page read and write
4ED1000
heap
page read and write
1750000
direct allocation
page read and write
3FCF000
stack
page read and write
DF0000
heap
page read and write
334F000
stack
page read and write
3D8E000
stack
page read and write
57E9000
trusted library allocation
page read and write
5350000
direct allocation
page read and write
174F000
stack
page read and write
1095000
unkown
page execute and read and write
10F8000
unkown
page execute and read and write
57E2000
trusted library allocation
page read and write
10BD000
unkown
page execute and read and write
428E000
stack
page read and write
107B000
unkown
page execute and write copy
1750000
direct allocation
page read and write
56D4000
trusted library allocation
page read and write
17F5000
heap
page read and write
551E000
trusted library allocation
page read and write
E00000
heap
page read and write
111E000
unkown
page execute and write copy
5350000
direct allocation
page read and write
450D000
stack
page read and write
3ACF000
stack
page read and write
17F2000
heap
page read and write
11F0000
heap
page read and write
5C5F000
stack
page read and write
59A0000
remote allocation
page read and write
10BE000
unkown
page execute and write copy
1085000
unkown
page execute and write copy
54D0000
direct allocation
page execute and read and write
ED0000
unkown
page execute and read and write
4ED1000
heap
page read and write
400E000
stack
page read and write
54D0000
direct allocation
page execute and read and write
1750000
direct allocation
page read and write
14FD000
stack
page read and write
584E000
stack
page read and write
1042000
unkown
page execute and write copy
ED0000
unkown
page execute and write copy
10C4000
unkown
page execute and read and write
1858000
heap
page read and write
4ED1000
heap
page read and write
184B000
heap
page read and write
10F7000
unkown
page execute and write copy
44CF000
stack
page read and write
598F000
stack
page read and write
1750000
direct allocation
page read and write
177E000
heap
page read and write
17B5000
heap
page read and write
105F000
unkown
page execute and read and write
324C000
stack
page read and write
538B000
stack
page read and write
1120000
unkown
page execute and read and write
560E000
stack
page read and write
570D000
stack
page read and write
3C0F000
stack
page read and write
3B0E000
stack
page read and write
3D4F000
stack
page read and write
10CD000
unkown
page execute and write copy
438F000
stack
page read and write
4ED1000
heap
page read and write
4ED1000
heap
page read and write
574E000
stack
page read and write
4B0F000
stack
page read and write
4ED1000
heap
page read and write
54E0000
direct allocation
page execute and read and write
1100000
unkown
page execute and write copy
1184000
unkown
page execute and write copy
D9C000
stack
page read and write
10BA000
unkown
page execute and write copy
43CE000
stack
page read and write
E71000
unkown
page execute and write copy
4EE0000
heap
page read and write
1102000
unkown
page execute and read and write
59A0000
remote allocation
page read and write
1640000
heap
page read and write
5B5E000
stack
page read and write
1040000
unkown
page execute and read and write
478E000
stack
page read and write
1812000
heap
page read and write
EDA000
unkown
page execute and write copy
E70000
unkown
page readonly
59EE000
stack
page read and write
116E000
unkown
page execute and write copy
1183000
unkown
page execute and read and write
34CE000
stack
page read and write
374E000
stack
page read and write
3E8F000
stack
page read and write
15D0000
heap
page read and write
4ED1000
heap
page read and write
E70000
unkown
page read and write
4ED1000
heap
page read and write
113E000
unkown
page execute and read and write
54B0000
direct allocation
page execute and read and write
109C000
unkown
page execute and write copy
196F000
stack
page read and write
5AED000
stack
page read and write
163E000
stack
page read and write
338E000
stack
page read and write
4A0E000
stack
page read and write
54D0000
direct allocation
page execute and read and write
1054000
unkown
page execute and read and write
4ED1000
heap
page read and write
4C8E000
stack
page read and write
17D1000
heap
page read and write
1067000
unkown
page execute and write copy
388E000
stack
page read and write
410F000
stack
page read and write
17B2000
heap
page read and write
54C0000
direct allocation
page execute and read and write
464E000
stack
page read and write
370F000
stack
page read and write
107C000
unkown
page execute and read and write
4ED0000
heap
page read and write
360E000
stack
page read and write
1750000
direct allocation
page read and write
488F000
stack
page read and write
4ED1000
heap
page read and write
348F000
stack
page read and write
17D4000
heap
page read and write
59A0000
remote allocation
page read and write
10A6000
unkown
page execute and read and write
1750000
direct allocation
page read and write
EDC000
unkown
page execute and write copy
1750000
direct allocation
page read and write
54F0000
direct allocation
page execute and read and write
EDB000
unkown
page execute and read and write
10EF000
unkown
page execute and read and write
1750000
direct allocation
page read and write
57D3000
trusted library allocation
page read and write
1183000
unkown
page execute and write copy
1750000
direct allocation
page read and write
4FD0000
trusted library allocation
page read and write
15F0000
heap
page read and write
1087000
unkown
page execute and read and write
10D4000
unkown
page execute and read and write
1094000
unkown
page execute and write copy
4DCE000
stack
page read and write
320F000
stack
page read and write
39CE000
stack
page read and write
105E000
unkown
page execute and write copy
1750000
direct allocation
page read and write
54D0000
direct allocation
page execute and read and write
116D000
unkown
page execute and write copy
4ECF000
stack
page read and write
5350000
direct allocation
page read and write
57F7000
trusted library allocation
page read and write
177A000
heap
page read and write
3C4E000
stack
page read and write
1174000
unkown
page execute and write copy
1174000
unkown
page execute and write copy
4ED1000
heap
page read and write
548F000
stack
page read and write
54D0000
direct allocation
page execute and read and write
1843000
heap
page read and write
1770000
heap
page read and write
15F7000
heap
page read and write
4ED1000
heap
page read and write
4C4F000
stack
page read and write
534D000
stack
page read and write
10E8000
unkown
page execute and write copy
11CE000
stack
page read and write
4ED1000
heap
page read and write
There are 191 hidden memdumps, click here to show them.