IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.store
malicious
dissapoiznw.store
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
https://steamcommunity.com:443/profiles/76561199724331900
unknown
malicious
eaglepawnoy.store
malicious
bathdoomgaz.store
malicious
clearancek.site
malicious
spirittunek.store
malicious
licendfilteo.site
malicious
https://player.vimeo.com
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://eaglepawnoy.store:443/apiy
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_global.js?v=wJD9maDpDcV
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/modalContent.js?v=UuGFpt56D9L4&l=
unknown
https://community.cloudflare.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=engli
unknown
https://community.cloudflare.steamstatic.com/public/javascript/promo/stickers.js?v=GfA42_x2_aub&
unknown
https://community.cloudflare.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpE
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://www.google.com
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://steamcommunity.com/profiles/76561199724331900r
unknown
https://licendfilteo.site:443/api
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/main.js?v=W9BX
unknown
https://community.cloudflare.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw&
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/shared_responsive.css?v=eghn9DNyCY67&
unknown
https://store.steampowered.com/points/shop/
unknown
https://community.cloudflare.steamstatic.com/public/css/promo/summer2017/stickers.css?v=bZKSp7oNwVPK
unknown
https://community.cloudflare.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&amp
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1&
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
https://www.youtube.com/
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://sergei-esenin.com/t
unknown
https://cdn.cloudflare.steamstatic.com/steamcommunity/public/assets/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/webui/clientcom.js?v=qYlgdgWOD4Ng&amp
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://sergei-esenin.com:443/api
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/libraries~b28b
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://store.steampowered.com/;
unknown
https://community.cloudflare.steamstatic.com/public/javascript/profile.js?v=KkhJqW2NGKiM&l=engli
unknown
https://store.steampowered.com/about/
unknown
https://community.cloudflare.steamstatic.com/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://sergei-esenin.com/K
unknown
https://steamcommunity.com/2
unknown
https://avatars.cloudflare.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8d
unknown
https://community.cloudflare.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC&
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/manifest.js?v=
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.cloudflare.steamstatic.com/public/css/applications/community/main.css?v=ljhW-PbGuX
unknown
https://recaptcha.net/recaptcha/;
unknown
https://dissapoiznw.store:443/api
unknown
https://steamcommunity.com/discussions/
unknown
https://sergei-esenin.com/apiA
unknown
https://steamcommunity.com/L
unknown
https://store.steampowered.com/stats/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/global.js?v=bOP7RorZq4_W&l=englis
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0&amp
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.cloudflare.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v
unknown
https://sergei-esenin.com/apiK
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.p
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.cloudflare.steamstatic.com/public/css/
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/buttons.css?v=tuNiaSwXwcYT&l=engl
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/motiva_sans.css?v=GfSjbGKcNYaQ&l=
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/profilev2.css?v=gNE3gksLVEVa&l=en
unknown
https://community.cloudflare.steamstatic.com/public/css/globalv2.css?v=pwVcIAtHNXwg&l=english&am
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/header.css?v=vh4BMeDcNiCU&l=engli
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://clearancek.site:443/apiX
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/shared_global.css?v=Ff_1prscqzeu&
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7C42cb6563c5fec81
unknown
http://127.0.0.1:27060
unknown
https://community.cloudflare.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
104.102.49.254
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious
sergei-esenin.com
unknown

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
DC1000
unkown
page execute and read and write
malicious
10CE000
unkown
page execute and write copy
FBA000
unkown
page execute and read and write
FA3000
unkown
page execute and read and write
2EDB000
stack
page read and write
451F000
stack
page read and write
5160000
direct allocation
page execute and read and write
FDE000
unkown
page execute and write copy
4B61000
heap
page read and write
329E000
stack
page read and write
100F000
unkown
page execute and write copy
10B5000
unkown
page execute and read and write
E2C000
unkown
page execute and write copy
DC0000
unkown
page readonly
13D0000
heap
page read and write
F88000
unkown
page execute and read and write
1264000
heap
page read and write
102F000
unkown
page execute and read and write
1068000
unkown
page execute and write copy
415F000
stack
page read and write
1031000
unkown
page execute and write copy
103F000
unkown
page execute and read and write
4B61000
heap
page read and write
38DE000
stack
page read and write
13D7000
heap
page read and write
4B70000
heap
page read and write
1264000
heap
page read and write
DC1000
unkown
page execute and write copy
1264000
heap
page read and write
FE9000
unkown
page execute and read and write
511F000
stack
page read and write
DB0000
heap
page read and write
441E000
stack
page read and write
375F000
stack
page read and write
14DD000
heap
page read and write
13C0000
heap
page read and write
4FD0000
remote allocation
page read and write
546E000
trusted library allocation
page read and write
34DF000
stack
page read and write
1264000
heap
page read and write
379E000
stack
page read and write
3D9F000
stack
page read and write
3EDF000
stack
page read and write
2FDF000
stack
page read and write
FF2000
unkown
page execute and read and write
DA0000
heap
page read and write
4FE0000
direct allocation
page read and write
1264000
heap
page read and write
14C4000
heap
page read and write
108A000
unkown
page execute and read and write
140A000
heap
page read and write
351E000
stack
page read and write
10CD000
unkown
page execute and write copy
1046000
unkown
page execute and write copy
13E0000
direct allocation
page read and write
401F000
stack
page read and write
1264000
heap
page read and write
325F000
stack
page read and write
1463000
heap
page read and write
104B000
unkown
page execute and read and write
13E0000
direct allocation
page read and write
1264000
heap
page read and write
3C9E000
stack
page read and write
5180000
direct allocation
page execute and read and write
1457000
heap
page read and write
465F000
stack
page read and write
10BE000
unkown
page execute and write copy
101D000
unkown
page execute and write copy
10A7000
unkown
page execute and write copy
E2B000
unkown
page execute and read and write
1264000
heap
page read and write
10BE000
unkown
page execute and write copy
14CC000
heap
page read and write
405E000
stack
page read and write
4A1F000
stack
page read and write
1264000
heap
page read and write
590F000
stack
page read and write
4B60000
heap
page read and write
33DE000
stack
page read and write
1441000
heap
page read and write
13E0000
direct allocation
page read and write
419D000
stack
page read and write
1488000
heap
page read and write
555E000
stack
page read and write
1264000
heap
page read and write
10B5000
unkown
page execute and write copy
365E000
stack
page read and write
1466000
heap
page read and write
429F000
stack
page read and write
144B000
heap
page read and write
1264000
heap
page read and write
47DE000
stack
page read and write
1264000
heap
page read and write
5140000
direct allocation
page execute and read and write
1488000
heap
page read and write
339F000
stack
page read and write
5465000
trusted library allocation
page read and write
1264000
heap
page read and write
120E000
stack
page read and write
565F000
stack
page read and write
148A000
heap
page read and write
148A000
heap
page read and write
579D000
stack
page read and write
5160000
direct allocation
page execute and read and write
3A1E000
stack
page read and write
455E000
stack
page read and write
1466000
heap
page read and write
1449000
heap
page read and write
1457000
heap
page read and write
311F000
stack
page read and write
5457000
trusted library allocation
page read and write
5170000
direct allocation
page execute and read and write
13E0000
direct allocation
page read and write
580E000
stack
page read and write
5190000
direct allocation
page execute and read and write
102C000
unkown
page execute and read and write
13E0000
direct allocation
page read and write
4B61000
heap
page read and write
1069000
unkown
page execute and read and write
F8A000
unkown
page execute and write copy
1487000
heap
page read and write
1264000
heap
page read and write
3DDE000
stack
page read and write
4FE0000
direct allocation
page read and write
42DE000
stack
page read and write
10CD000
unkown
page execute and read and write
14DD000
heap
page read and write
FB9000
unkown
page execute and write copy
43DF000
stack
page read and write
14D6000
heap
page read and write
1264000
heap
page read and write
4FA0000
heap
page read and write
3F1E000
stack
page read and write
1450000
heap
page read and write
C5C000
stack
page read and write
551E000
stack
page read and write
5150000
direct allocation
page execute and read and write
4B61000
heap
page read and write
5160000
direct allocation
page execute and read and write
3B1F000
stack
page read and write
51A9000
trusted library allocation
page read and write
1264000
heap
page read and write
13E0000
direct allocation
page read and write
1036000
unkown
page execute and read and write
1264000
heap
page read and write
1264000
heap
page read and write
E20000
unkown
page execute and read and write
FA4000
unkown
page execute and write copy
4FE0000
direct allocation
page read and write
535E000
trusted library allocation
page read and write
FAE000
unkown
page execute and write copy
148A000
heap
page read and write
5160000
direct allocation
page execute and read and write
1400000
heap
page read and write
13E0000
direct allocation
page read and write
1260000
heap
page read and write
4B61000
heap
page read and write
48DF000
stack
page read and write
4A5E000
stack
page read and write
5130000
direct allocation
page execute and read and write
14DD000
heap
page read and write
569E000
stack
page read and write
140E000
heap
page read and write
102D000
unkown
page execute and write copy
10A1000
unkown
page execute and read and write
4B61000
heap
page read and write
109E000
unkown
page execute and write copy
13E0000
direct allocation
page read and write
479F000
stack
page read and write
1264000
heap
page read and write
14CC000
heap
page read and write
469E000
stack
page read and write
4B5F000
stack
page read and write
4B61000
heap
page read and write
124E000
stack
page read and write
148A000
heap
page read and write
136F000
stack
page read and write
FEA000
unkown
page execute and write copy
1264000
heap
page read and write
FAE000
unkown
page execute and read and write
13E0000
direct allocation
page read and write
13E0000
direct allocation
page read and write
E20000
unkown
page execute and write copy
1264000
heap
page read and write
5160000
direct allocation
page execute and read and write
52DD000
stack
page read and write
1438000
heap
page read and write
516D000
stack
page read and write
D5D000
stack
page read and write
DC0000
unkown
page read and write
4FA0000
trusted library allocation
page read and write
361F000
stack
page read and write
53DD000
stack
page read and write
2E9F000
stack
page read and write
315E000
stack
page read and write
1446000
heap
page read and write
13BE000
stack
page read and write
547C000
trusted library allocation
page read and write
1463000
heap
page read and write
13E0000
direct allocation
page read and write
4B61000
heap
page read and write
13E0000
direct allocation
page read and write
1014000
unkown
page execute and read and write
1015000
unkown
page execute and write copy
5160000
direct allocation
page execute and read and write
14D5000
heap
page read and write
529E000
stack
page read and write
10B6000
unkown
page execute and write copy
1264000
heap
page read and write
103D000
unkown
page execute and write copy
FA5000
unkown
page execute and read and write
301E000
stack
page read and write
39DF000
stack
page read and write
4FD0000
remote allocation
page read and write
1264000
heap
page read and write
101C000
unkown
page execute and read and write
389F000
stack
page read and write
3C5F000
stack
page read and write
3B5E000
stack
page read and write
13E0000
direct allocation
page read and write
501E000
stack
page read and write
E2A000
unkown
page execute and write copy
1264000
heap
page read and write
15FF000
stack
page read and write
1022000
unkown
page execute and read and write
4FD0000
remote allocation
page read and write
102A000
unkown
page execute and write copy
541E000
stack
page read and write
1450000
heap
page read and write
1264000
heap
page read and write
491E000
stack
page read and write
13E0000
direct allocation
page read and write
4B61000
heap
page read and write
There are 223 hidden memdumps, click here to show them.