IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
https://sergei-esenin.com/
unknown
malicious
https://sergei-esenin.com/9
unknown
malicious
https://sergei-esenin.com/apiZ
unknown
malicious
bathdoomgaz.store
malicious
https://sergei-esenin.com/apiBi
unknown
malicious
studennotediw.store
malicious
https://sergei-esenin.com/apiL
unknown
malicious
clearancek.site
malicious
dissapoiznw.store
malicious
https://steamcommunity.com/profiles/76561199724331900
23.199.218.33
malicious
spirittunek.store
malicious
licendfilteo.site
malicious
eaglepawnoy.store
malicious
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
malicious
mobbipenju.store
malicious
https://sergei-esenin.com/a
unknown
malicious
https://sergei-esenin.com/U
unknown
malicious
https://sergei-esenin.com/api
172.67.206.204
malicious
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
malicious
https://steamcommunity.com/my/wishlist/
unknown
https://www.cloudflare.com/learning/access-management/phishing-attack/
unknown
https://community.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL&l=
unknown
https://community.steamstatic.com/puL
unknown
https://community.steamstatic.com/public/javascript/promo/stickers.js?v=W8NP8aTVqtms&l=english
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.steamstatic.com/public/shared/css/motiva_sans.css?v=v7XTmVzbLV33&l=english
unknown
https://community.steamstatic.com/public/javascript/global.js?v=7qlUmHSJhPRN&l=english
unknown
https://community.steamstatic.com/public/css/globalv2.css?v=dQy8Omh4p9PH&l=english
unknown
https://community.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.steamstatic.com/public/javascript/applications/community/manifest.js?v=r7a4-LYcQOj
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.steamstatic.com/public/javascript/applications/community/lib
unknown
https://community.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://community.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
unknown
https://community.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://community.steamstatic.com/public/shared/css/buttons.css?v=-WV9f1LdxEjq&l=english
unknown
https://community.steamstatic.com/public/javascript/applications/community/libraries~b28b7af69.js?v=
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
unknown
https://community.steamstatic.com/public/css/applications/community/main.css?v=DVae4t4RZiHA&l=en
unknown
https://steamcommunity.com/workshop/
unknown
https://community.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://store.steampowered.com/legal/
unknown
https://community.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://licendfilteo.site/api
unknown
https://www.cloudflare.com/learning/accesa
unknown
https://community.steamstatic.c
unknown
https://community.steamstatic.com/public/javascript/profile.js?v=bbs9uq0gqJ-H&l=english
unknown
https://community.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
unknown
https://community.steamstatic.com/public/css/skin_1/header.css?v=pTvrRy1pm52p&l=english
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.steamstatic.com/public/css/skin_1/profilev2.css?v=t9xiI4DlPpEB&l=english
unknown
https://store.steampowered.com/points/shop/
unknown
https://community.steamstatic.com/public/javascript/applications/community/main.js?v=4XouecKy8sZy&am
unknown
https://store.steampowered.com/
unknown
https://community.steamstatic.com/public/shared/javascript/shared_global.js?v=7glT1n_nkVCs&l=eng
unknown
https://avatars.fastly.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://community.steamstatic.com/public/shared/css/shared_global.css?v=uF6G1wyNU-4c&l=english
unknown
https://community.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://studennotediw.store/api
unknown
https://www.cloudflare.com/5xx-error-landing
unknown
https://community.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&l=english
unknown
https://community.steamstatic.com/public/javascript/webui/clientcom.js?v=jq1jQyX1843y&l=english
unknown
https://community.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&l=engl
unknown
https://www.cloudflare.com/learning/access-management/phishing-attackH
unknown
https://community.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://community.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw
unknown
https://community.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v=pSvIAKtunf
unknown
https://community.steamstatic.com/public/shared/css/shared_responsive.css?v=kR9MtmbWSZEp&l=engli
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://steamcommunity.com/profiles/76561199724331900=
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
https://community.steamstatic.com/public/css/promo/summer2017/stickers.css?v=P8gOPraCSjV6&l=engl
unknown
https://store.steampowered.com/about/
unknown
There are 76 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
23.199.218.33
malicious
sergei-esenin.com
172.67.206.204
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious

IPs

IP
Domain
Country
Malicious
23.199.218.33
steamcommunity.com
United States
malicious
172.67.206.204
sergei-esenin.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
CC1000
unkown
page execute and read and write
malicious
FB1000
unkown
page execute and write copy
563E000
stack
page read and write
FB8000
unkown
page execute and write copy
F9A000
unkown
page execute and read and write
127F000
heap
page read and write
530D000
trusted library allocation
page read and write
502D000
stack
page read and write
1235000
heap
page read and write
58EF000
stack
page read and write
11FE000
heap
page read and write
12C8000
heap
page read and write
3DCE000
stack
page read and write
1235000
heap
page read and write
1120000
direct allocation
page read and write
4FDF000
stack
page read and write
478F000
stack
page read and write
4A11000
heap
page read and write
12CA000
heap
page read and write
4A10000
heap
page read and write
5010000
direct allocation
page execute and read and write
F2A000
unkown
page execute and read and write
525D000
stack
page read and write
E82000
unkown
page execute and read and write
4A11000
heap
page read and write
CB0000
heap
page read and write
43CF000
stack
page read and write
4FF0000
direct allocation
page execute and read and write
EB4000
unkown
page execute and write copy
350E000
stack
page read and write
123E000
heap
page read and write
4A11000
heap
page read and write
ED2000
unkown
page execute and write copy
D20000
unkown
page execute and write copy
1120000
direct allocation
page read and write
123E000
heap
page read and write
12D3000
heap
page read and write
3B0F000
stack
page read and write
126D000
heap
page read and write
54DE000
stack
page read and write
1120000
direct allocation
page read and write
3A0E000
stack
page read and write
531A000
trusted library allocation
page read and write
539F000
stack
page read and write
56AE000
stack
page read and write
454E000
stack
page read and write
39CF000
stack
page read and write
54F0000
remote allocation
page read and write
CC0000
unkown
page read and write
1251000
heap
page read and write
3C8E000
stack
page read and write
4A11000
heap
page read and write
1120000
direct allocation
page read and write
12C0000
heap
page read and write
4A11000
heap
page read and write
3C4F000
stack
page read and write
1232000
heap
page read and write
414E000
stack
page read and write
1120000
direct allocation
page read and write
FB0000
unkown
page execute and read and write
F00000
unkown
page execute and read and write
11FA000
heap
page read and write
F45000
unkown
page execute and write copy
2FCF000
stack
page read and write
12D8000
heap
page read and write
1120000
direct allocation
page read and write
4A11000
heap
page read and write
F06000
unkown
page execute and read and write
127B000
heap
page read and write
125D000
heap
page read and write
3D8F000
stack
page read and write
34CF000
stack
page read and write
4A11000
heap
page read and write
1140000
heap
page read and write
D20000
unkown
page execute and read and write
4E50000
trusted library allocation
page read and write
324F000
stack
page read and write
5324000
trusted library allocation
page read and write
F81000
unkown
page execute and read and write
5050000
direct allocation
page execute and read and write
126D000
heap
page read and write
EAB000
unkown
page execute and write copy
450F000
stack
page read and write
1251000
heap
page read and write
FC8000
unkown
page execute and write copy
4E8D000
stack
page read and write
529E000
stack
page read and write
F31000
unkown
page execute and read and write
5020000
direct allocation
page execute and read and write
F26000
unkown
page execute and write copy
2E8F000
stack
page read and write
5020000
direct allocation
page execute and read and write
FC7000
unkown
page execute and read and write
54F0000
remote allocation
page read and write
11AE000
stack
page read and write
FAE000
unkown
page execute and write copy
FA1000
unkown
page execute and write copy
127F000
heap
page read and write
388F000
stack
page read and write
1238000
heap
page read and write
1230000
heap
page read and write
FB8000
unkown
page execute and write copy
F01000
unkown
page execute and write copy
314E000
stack
page read and write
5020000
direct allocation
page execute and read and write
127B000
heap
page read and write
10DE000
stack
page read and write
3ECF000
stack
page read and write
FC7000
unkown
page execute and write copy
57AF000
stack
page read and write
47CE000
stack
page read and write
374F000
stack
page read and write
125D000
heap
page read and write
1167000
heap
page read and write
5030000
direct allocation
page execute and read and write
127F000
heap
page read and write
5020000
direct allocation
page execute and read and write
364E000
stack
page read and write
CC0000
unkown
page readonly
520C000
trusted library allocation
page read and write
1223000
heap
page read and write
1130000
heap
page read and write
12C8000
heap
page read and write
54F0000
remote allocation
page read and write
12DA000
heap
page read and write
4A11000
heap
page read and write
4A11000
heap
page read and write
1120000
direct allocation
page read and write
490E000
stack
page read and write
F57000
unkown
page execute and read and write
2ECE000
stack
page read and write
F98000
unkown
page execute and write copy
1228000
heap
page read and write
2D8F000
stack
page read and write
E85000
unkown
page execute and write copy
4A11000
heap
page read and write
125D000
heap
page read and write
12C2000
heap
page read and write
EE6000
unkown
page execute and read and write
4EA0000
direct allocation
page read and write
116D000
heap
page read and write
1120000
direct allocation
page read and write
4A11000
heap
page read and write
596E000
stack
page read and write
328E000
stack
page read and write
5332000
trusted library allocation
page read and write
11EB000
stack
page read and write
360F000
stack
page read and write
8FB000
stack
page read and write
5A6F000
stack
page read and write
468E000
stack
page read and write
404E000
stack
page read and write
38CE000
stack
page read and write
440E000
stack
page read and write
428E000
stack
page read and write
F46000
unkown
page execute and read and write
1120000
direct allocation
page read and write
5000000
direct allocation
page execute and read and write
53DE000
stack
page read and write
5040000
direct allocation
page execute and read and write
D2C000
unkown
page execute and write copy
48CF000
stack
page read and write
4A11000
heap
page read and write
123E000
heap
page read and write
EA0000
unkown
page execute and write copy
127D000
heap
page read and write
4A11000
heap
page read and write
E93000
unkown
page execute and read and write
EBA000
unkown
page execute and read and write
1135000
heap
page read and write
111E000
stack
page read and write
1120000
direct allocation
page read and write
42CE000
stack
page read and write
EA0000
unkown
page execute and read and write
12C8000
heap
page read and write
13EE000
stack
page read and write
9FB000
stack
page read and write
5020000
direct allocation
page execute and read and write
5920000
heap
page read and write
4EDB000
stack
page read and write
300E000
stack
page read and write
126D000
heap
page read and write
515D000
stack
page read and write
1120000
direct allocation
page read and write
1251000
heap
page read and write
EFE000
unkown
page execute and write copy
EAC000
unkown
page execute and read and write
4A0F000
stack
page read and write
4A11000
heap
page read and write
12C8000
heap
page read and write
378E000
stack
page read and write
CC1000
unkown
page execute and write copy
4A11000
heap
page read and write
310F000
stack
page read and write
400F000
stack
page read and write
FAE000
unkown
page execute and write copy
338F000
stack
page read and write
1232000
heap
page read and write
4EA0000
direct allocation
page read and write
14EF000
stack
page read and write
553D000
stack
page read and write
1228000
heap
page read and write
418E000
stack
page read and write
5020000
direct allocation
page execute and read and write
4A11000
heap
page read and write
F0E000
unkown
page execute and write copy
3B4E000
stack
page read and write
1120000
direct allocation
page read and write
4A11000
heap
page read and write
1160000
heap
page read and write
F5A000
unkown
page execute and write copy
1120000
direct allocation
page read and write
C60000
heap
page read and write
33CE000
stack
page read and write
F5C000
unkown
page execute and read and write
11F0000
heap
page read and write
F2B000
unkown
page execute and write copy
57EE000
stack
page read and write
F14000
unkown
page execute and read and write
F56000
unkown
page execute and write copy
C50000
heap
page read and write
3F0E000
stack
page read and write
4A11000
heap
page read and write
5065000
trusted library allocation
page read and write
127D000
heap
page read and write
1230000
heap
page read and write
464F000
stack
page read and write
4EA0000
direct allocation
page read and write
1120000
direct allocation
page read and write
There are 219 hidden memdumps, click here to show them.