IOC Report
file.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious

URLs

Name
IP
Malicious
studennotediw.store
malicious
dissapoiznw.store
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
eaglepawnoy.store
malicious
bathdoomgaz.store
malicious
clearancek.site
malicious
spirittunek.store
malicious
licendfilteo.site
malicious
mobbipenju.store
malicious
https://player.vimeo.com
unknown
https://avatars.cloudflare.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dY1
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_global.js?v=wJD9maDpDcV
unknown
https://sergei-esenin.com/
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/modalContent.js?v=UuGFpt56D9L4&l=
unknown
https://community.cloudflare.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=engli
unknown
https://community.cloudflare.steamstatic.com/public/javascript/promo/stickers.js?v=GfA42_x2_aub&
unknown
https://community.cloudflare.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpE
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://www.youtube.com
unknown
https://www.google.com
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://s.ytimg.com;
unknown
https://steam.tv/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/main.js?v=W9BX
unknown
https://cdn.cloU
unknown
https://community.cloudflare.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw&
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/shared_responsive.css?v=eghn9DNyCY67&
unknown
https://store.steampowered.com/points/shop/
unknown
https://community.cloudflare.steamstatic.com/public/css/promo/summer2017/stickers.css?v=bZKSp7oNwVPK
unknown
https://community.cloudflare.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&amp
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1&
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://steamcommunity.com/profiles/76561199724331900/inventory/
unknown
https://www.gstatic.cn/re
unknown
https://www.youtube.com/
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/webui/clientcom.js?v=qYlgdgWOD4Ng&amp
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://cdn.cloudflare.steamstatic.com/steamcommunit
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/libraries~b28b
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://community.cloudflare.steamstatic.com/public/javascript/profile.js?v=KkhJqW2NGKiM&l=engli
unknown
https://store.steampowered.com/about/
unknown
https://community.cloudflare.steamstatic.com/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC&
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://sergei-esenin.com/5
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/manifest.js?v=
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.cloudflare.steamstatic.com/public/css/applications/community/main.css?v=ljhW-PbGuX
unknown
https://recaptcha.net/recaptcha/;
unknown
https://steamcommunity.com/discussions/
unknown
https://store.steampowered.com/stats/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/global.js?v=bOP7RorZq4_W&l=englis
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0&amp
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.cloudflare.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.p
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1
unknown
https://www.google.come
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/buttons.css?v=tuNiaSwXwcYT&l=engl
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/motiva_sans.css?v=GfSjbGKcNYaQ&l=
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/profilev2.css?v=gNE3gksLVEVa&l=en
unknown
https://community.cloudflare.steamstatic.com/public/css/globalv2.css?v=pwVcIAtHNXwg&l=english&am
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/header.css?v=vh4BMeDcNiCU&l=engli
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/shared_global.css?v=Ff_1prscqzeu&
unknown
http://127.0.0.1:27060
unknown
https://community.cloudflare.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://avatars.cloudflare.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0&a
unknown
http://127.0
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
https://broadcast.st
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://store.steampowered.com/mobile
unknown
https://sergei-esenin.com/api
unknown
https://steamcommunity.com/
unknown
https://steamcommunity.com/profiles/76561199724331900/badges
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
104.102.49.254
malicious
eaglepawnoy.store
unknown
malicious
bathdoomgaz.store
unknown
malicious
spirittunek.store
unknown
malicious
licendfilteo.site
unknown
malicious
studennotediw.store
unknown
malicious
mobbipenju.store
unknown
malicious
clearancek.site
unknown
malicious
dissapoiznw.store
unknown
malicious
sergei-esenin.com
unknown

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
6B1000
unkown
page execute and read and write
malicious
ACE000
stack
page read and write
89F000
unkown
page execute and read and write
CAA000
heap
page read and write
B84000
heap
page read and write
B84000
heap
page read and write
4401000
heap
page read and write
D2C000
heap
page read and write
4D8F000
stack
page read and write
B70000
direct allocation
page read and write
4B4D000
stack
page read and write
9AA000
unkown
page execute and write copy
2777000
heap
page read and write
49D0000
direct allocation
page execute and read and write
38BF000
stack
page read and write
B84000
heap
page read and write
4BCD000
trusted library allocation
page read and write
49D0000
direct allocation
page execute and read and write
D2C000
heap
page read and write
2EFE000
stack
page read and write
B84000
heap
page read and write
367E000
stack
page read and write
3DBF000
stack
page read and write
992000
unkown
page execute and write copy
994000
unkown
page execute and write copy
B84000
heap
page read and write
4401000
heap
page read and write
273F000
stack
page read and write
B70000
direct allocation
page read and write
9AA000
unkown
page execute and write copy
88D000
unkown
page execute and read and write
630000
heap
page read and write
71A000
unkown
page execute and write copy
6B1000
unkown
page execute and write copy
363F000
stack
page read and write
4401000
heap
page read and write
D7D000
heap
page read and write
B70000
direct allocation
page read and write
49D0000
direct allocation
page execute and read and write
29BF000
stack
page read and write
32BE000
stack
page read and write
B84000
heap
page read and write
4A00000
direct allocation
page execute and read and write
875000
unkown
page execute and read and write
2AFF000
stack
page read and write
B84000
heap
page read and write
D40000
heap
page read and write
6B0000
unkown
page read and write
D37000
heap
page read and write
903000
unkown
page execute and read and write
B84000
heap
page read and write
916000
unkown
page execute and write copy
49BF000
stack
page read and write
D91000
heap
page read and write
CEA000
heap
page read and write
3CBE000
stack
page read and write
2B3E000
stack
page read and write
287F000
stack
page read and write
28BE000
stack
page read and write
327F000
stack
page read and write
2760000
direct allocation
page execute and read and write
B84000
heap
page read and write
4401000
heap
page read and write
89B000
unkown
page execute and read and write
377F000
stack
page read and write
902000
unkown
page execute and write copy
2D7F000
stack
page read and write
892000
unkown
page execute and read and write
CEF000
heap
page read and write
4840000
trusted library allocation
page read and write
2750000
direct allocation
page execute and read and write
8B2000
unkown
page execute and read and write
D00000
heap
page read and write
4F1D000
stack
page read and write
9B9000
unkown
page execute and write copy
4CD3000
trusted library allocation
page read and write
89E000
unkown
page execute and write copy
9B8000
unkown
page execute and write copy
2CC000
stack
page read and write
49F0000
direct allocation
page execute and read and write
8DE000
unkown
page execute and read and write
6B0000
unkown
page readonly
2FFF000
stack
page read and write
42FE000
stack
page read and write
D40000
heap
page read and write
909000
unkown
page execute and read and write
403F000
stack
page read and write
88F000
unkown
page execute and write copy
B84000
heap
page read and write
2770000
heap
page read and write
710000
unkown
page execute and write copy
B1E000
stack
page read and write
D02000
heap
page read and write
38FE000
stack
page read and write
D22000
heap
page read and write
4880000
direct allocation
page read and write
D37000
heap
page read and write
B70000
direct allocation
page read and write
2750000
heap
page read and write
B5B000
stack
page read and write
CE3000
heap
page read and write
CE9000
heap
page read and write
4CC2000
trusted library allocation
page read and write
B70000
direct allocation
page read and write
317E000
stack
page read and write
4401000
heap
page read and write
D03000
heap
page read and write
3A3E000
stack
page read and write
4CDD000
trusted library allocation
page read and write
B84000
heap
page read and write
D7F000
heap
page read and write
B84000
heap
page read and write
303E000
stack
page read and write
4DCE000
stack
page read and write
D2C000
heap
page read and write
8F7000
unkown
page execute and write copy
505E000
stack
page read and write
33BF000
stack
page read and write
3C7F000
stack
page read and write
43FF000
stack
page read and write
9A0000
unkown
page execute and write copy
D22000
heap
page read and write
920000
unkown
page execute and write copy
B70000
direct allocation
page read and write
37BE000
stack
page read and write
34FF000
stack
page read and write
B84000
heap
page read and write
620000
heap
page read and write
B80000
heap
page read and write
CEF000
heap
page read and write
8F4000
unkown
page execute and write copy
710000
unkown
page execute and read and write
B84000
heap
page read and write
9A0000
unkown
page execute and write copy
B70000
direct allocation
page read and write
4401000
heap
page read and write
D37000
heap
page read and write
CA0000
heap
page read and write
417F000
stack
page read and write
936000
unkown
page execute and read and write
49E0000
direct allocation
page execute and read and write
B60000
heap
page read and write
904000
unkown
page execute and write copy
92E000
unkown
page execute and write copy
71C000
unkown
page execute and write copy
3B7E000
stack
page read and write
2740000
direct allocation
page read and write
CAE000
heap
page read and write
49D0000
remote allocation
page read and write
3F3E000
stack
page read and write
89A000
unkown
page execute and write copy
29FE000
stack
page read and write
49D0000
remote allocation
page read and write
D43000
heap
page read and write
8E0000
unkown
page execute and read and write
D40000
heap
page read and write
B84000
heap
page read and write
2C7E000
stack
page read and write
974000
unkown
page execute and read and write
353E000
stack
page read and write
B84000
heap
page read and write
4401000
heap
page read and write
918000
unkown
page execute and read and write
8A3000
unkown
page execute and write copy
33FE000
stack
page read and write
9A1000
unkown
page execute and read and write
B84000
heap
page read and write
49C0000
direct allocation
page execute and read and write
D00000
heap
page read and write
925000
unkown
page execute and read and write
41BE000
stack
page read and write
B70000
direct allocation
page read and write
92C000
unkown
page execute and write copy
CD8000
heap
page read and write
69E000
stack
page read and write
C8F000
stack
page read and write
8F6000
unkown
page execute and read and write
8A5000
unkown
page execute and read and write
51BE000
stack
page read and write
313F000
stack
page read and write
2C3F000
stack
page read and write
B70000
direct allocation
page read and write
B84000
heap
page read and write
48BE000
stack
page read and write
263F000
stack
page read and write
B84000
heap
page read and write
D22000
heap
page read and write
407E000
stack
page read and write
4ECE000
stack
page read and write
42BF000
stack
page read and write
501E000
stack
page read and write
2DBE000
stack
page read and write
B70000
direct allocation
page read and write
D43000
heap
page read and write
2740000
direct allocation
page read and write
4C4D000
stack
page read and write
98F000
unkown
page execute and write copy
3B3F000
stack
page read and write
B70000
direct allocation
page read and write
49D0000
direct allocation
page execute and read and write
B84000
heap
page read and write
8AE000
unkown
page execute and write copy
B84000
heap
page read and write
4401000
heap
page read and write
9A2000
unkown
page execute and write copy
D40000
heap
page read and write
CE0000
heap
page read and write
D43000
heap
page read and write
2EBF000
stack
page read and write
52BF000
stack
page read and write
B70000
direct allocation
page read and write
3CD000
stack
page read and write
9B8000
unkown
page execute and read and write
B84000
heap
page read and write
D43000
heap
page read and write
B70000
direct allocation
page read and write
8DF000
unkown
page execute and write copy
49D0000
remote allocation
page read and write
4B0D000
stack
page read and write
B84000
heap
page read and write
71B000
unkown
page execute and read and write
4C8E000
stack
page read and write
8FA000
unkown
page execute and read and write
B84000
heap
page read and write
B84000
heap
page read and write
4CC7000
trusted library allocation
page read and write
39FF000
stack
page read and write
515D000
stack
page read and write
4CEA000
trusted library allocation
page read and write
8B5000
unkown
page execute and read and write
B70000
direct allocation
page read and write
49D0000
direct allocation
page execute and read and write
4CC5000
trusted library allocation
page read and write
8CA000
unkown
page execute and write copy
4400000
heap
page read and write
3EFF000
stack
page read and write
877000
unkown
page execute and write copy
8B4000
unkown
page execute and write copy
92D000
unkown
page execute and read and write
487D000
stack
page read and write
49D0000
direct allocation
page execute and read and write
3DFE000
stack
page read and write
4A1C000
trusted library allocation
page read and write
There are 233 hidden memdumps, click here to show them.