IOC Report
buNtKcYHCa.exe

loading gif

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\buNtKcYHCa.exe
"C:\Users\user\Desktop\buNtKcYHCa.exe"
malicious
C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe
"C:\Windows\BitLockerDiscoveryVolumeContents\BitLockerToGo.exe"
malicious

URLs

Name
IP
Malicious
strikebripm.sbs
malicious
ostracizez.sbs
malicious
offybirhtdi.sbs
malicious
mediavelk.sbs
malicious
https://steamcommunity.com/profiles/76561199724331900
104.102.49.254
malicious
definitib.sbs
malicious
elaboretib.sbs
malicious
activedomest.sbs
malicious
arenbootk.sbs
malicious
https://doi.org/GTB
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://player.vimeo.com
unknown
https://community.cloudflare.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC&
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://help.steampowered.com/en/
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_global.js?v=wJD9maDpDcV
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://github.com/golang/protobuf/issues/1609):
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://www.gstatic.cn/recaptcha/
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/manifest.js?v=
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://community.cloudflare.steamstatic.com/public/css/applications/community/main.css?v=ljhW-PbGuX
unknown
https://recaptcha.net/recaptcha/;
unknown
https://community.cloudflare.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpE
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://steamcommunity.com/discussions/
unknown
https://www.youtube.com
unknown
https://liveinternet.club
unknown
https://www.google.com
unknown
https://store.steampowered.com/stats/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/global.js?v=bOP7RorZq4_W&l=englis
unknown
https://medal.tv
unknown
https://broadcast.st.dl.eccdnx.com
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0&amp
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.p
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1
unknown
https://s.ytimg.com;
unknown
https://steamcommunity.com/workshop/
unknown
https://login.steampowered.com/
unknown
https://store.steampowered.com/legal/
unknown
https://liveinternet.clubh
unknown
https://steam.tv/
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/buttons.css?v=tuNiaSwXwcYT&l=engl
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/motiva_sans.css?v=GfSjbGKcNYaQ&l=
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/main.js?v=W9BX
unknown
https://community.cloudflare.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw&
unknown
https://community.cloudflare.steamstatic.com/public/css/globalv2.css?v=pwVcIAtHNXwg&l=english&am
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/shared_responsive.css?v=eghn9DNyCY67&
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/header.css?v=vh4BMeDcNiCU&l=engli
unknown
https://store.steampowered.com/points/shop/
unknown
https://recaptcha.net
unknown
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cb4a621662dea893
unknown
https://store.steampowered.com/
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/fatalerror.css?v=wctRWaBvNt2z&l=e
unknown
https://steamcommunity.com
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/shared_global.css?v=Ff_1prscqzeu&
unknown
https://sketchfab.com
unknown
https://lv.queniujq.cn
unknown
https://www.youtube.com/
unknown
http://127.0.0.1:27060
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://cdn.cloudflare.steamstatic.com/steamcommunity/public/assets/
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://steamcommunity.com/&&
unknown
https://community.cloudflare.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://www.google.com/recaptcha/
unknown
https://checkout.steampowered.com/
unknown
https://help.steampowered.com/
unknown
https://api.steampowered.com/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/libraries~b28b
unknown
http://store.steampowered.com/account/cookiepreferences/
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://github.com/go-sql-driver/mysql/wiki/strict-modetable
unknown
https://store.steampowered.com/mobile
unknown
https://steamcommunity.com/
unknown
https://store.steampowered.com/;
unknown
https://community.cloudflare.steamstatic.com/publi
unknown
https://steamcommunity.com/x
unknown
https://store.steampowered.com/about/
unknown
https://community.cloudflare.steamstatic.com/
unknown
There are 79 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
steamcommunity.com
104.102.49.254
malicious
mediavelk.sbs
unknown
malicious
activedomest.sbs
unknown
malicious
ostracizez.sbs
unknown
malicious
definitib.sbs
unknown
malicious
strikebripm.sbs
unknown
malicious
arenbootk.sbs
unknown
malicious
offybirhtdi.sbs
unknown
malicious
elaboretib.sbs
unknown
malicious

IPs

IP
Domain
Country
Malicious
104.102.49.254
steamcommunity.com
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
3182000
direct allocation
page read and write
malicious
2E18000
direct allocation
page read and write
malicious
2DDC000
direct allocation
page read and write
2C20000
direct allocation
page read and write
2C2E000
direct allocation
page read and write
2CD2000
direct allocation
page read and write
261E000
stack
page read and write
3308000
remote allocation
page readonly
1E22000
unkown
page read and write
331B000
remote allocation
page readonly
2F28000
direct allocation
page read and write
2E96000
direct allocation
page read and write
2C68000
direct allocation
page read and write
3650000
heap
page read and write
3635000
heap
page read and write
329C000
stack
page read and write
2D90000
direct allocation
page read and write
358E000
stack
page read and write
2E8C000
direct allocation
page read and write
2C0C000
direct allocation
page read and write
3695000
heap
page read and write
13F7000
unkown
page readonly
23430000
direct allocation
page read and write
22F40000
direct allocation
page read and write
2FD1000
direct allocation
page read and write
3619000
heap
page read and write
2CBC000
direct allocation
page read and write
23130000
direct allocation
page read and write
1D66000
unkown
page write copy
2BDD000
stack
page read and write
2D4C000
direct allocation
page read and write
232ED000
stack
page read and write
2F4C000
direct allocation
page read and write
2E86000
direct allocation
page read and write
574E000
stack
page read and write
2DB2000
direct allocation
page read and write
1FEE000
stack
page read and write
1DBE000
unkown
page write copy
2D40000
direct allocation
page read and write
B00000
unkown
page readonly
2E06000
direct allocation
page read and write
3646000
heap
page read and write
2C04000
direct allocation
page read and write
B01000
unkown
page execute read
2DFC000
direct allocation
page read and write
2F14000
direct allocation
page read and write
24D0000
heap
page read and write
2F82000
direct allocation
page read and write
3664000
heap
page read and write
2CEE000
direct allocation
page read and write
526E000
stack
page read and write
2F30000
direct allocation
page read and write
2E9E000
direct allocation
page read and write
266C000
heap
page read and write
35F8000
heap
page read and write
2E80000
direct allocation
page read and write
22FD000
stack
page read and write
2F18000
direct allocation
page read and write
2D1A000
direct allocation
page read and write
24D5000
heap
page read and write
23030000
heap
page read and write
3650000
heap
page read and write
361E000
heap
page read and write
24E8000
direct allocation
page read and write
24CF000
stack
page read and write
2DDE000
direct allocation
page read and write
3654000
heap
page read and write
2EA0000
direct allocation
page read and write
2DE4000
direct allocation
page read and write
2DFE000
direct allocation
page read and write
22E3E000
stack
page read and write
2F2E000
direct allocation
page read and write
364A000
heap
page read and write
2F94000
direct allocation
page read and write
3648000
heap
page read and write
4FC0000
remote allocation
page read and write
233F0000
direct allocation
page read and write
2C4C000
direct allocation
page read and write
2C24000
direct allocation
page read and write
3650000
heap
page read and write
2DEA000
direct allocation
page read and write
2C22000
direct allocation
page read and write
2B9F000
stack
page read and write
2760000
direct allocation
page read and write
2F66000
direct allocation
page read and write
361E000
heap
page read and write
55EE000
stack
page read and write
2CC0000
direct allocation
page read and write
1E3B000
unkown
page readonly
1794000
unkown
page readonly
2C32000
direct allocation
page read and write
35F0000
heap
page read and write
330B000
remote allocation
page execute and read and write
2F90000
direct allocation
page read and write
1E31000
unkown
page read and write
502D000
stack
page read and write
3646000
heap
page read and write
2F8C000
direct allocation
page read and write
2C5E000
direct allocation
page read and write
3634000
heap
page read and write
2C06000
direct allocation
page read and write
3350000
heap
page read and write
369B000
heap
page read and write
2F52000
direct allocation
page read and write
1DE3000
unkown
page read and write
2F0E000
direct allocation
page read and write
2F6A000
direct allocation
page read and write
2D08000
direct allocation
page read and write
2DBA000
direct allocation
page read and write
3648000
heap
page read and write
2F70000
direct allocation
page read and write
1E3B000
unkown
page readonly
2F2A000
direct allocation
page read and write
22CFF000
stack
page read and write
2C0A000
direct allocation
page read and write
2F16000
direct allocation
page read and write
2F5E000
direct allocation
page read and write
2580000
direct allocation
page read and write
2D50000
direct allocation
page read and write
2C44000
direct allocation
page read and write
B00000
unkown
page readonly
2D34000
direct allocation
page read and write
1794000
unkown
page readonly
2C42000
direct allocation
page read and write
302B000
direct allocation
page read and write
2D3C000
direct allocation
page read and write
1E1B000
unkown
page read and write
4FC0000
remote allocation
page read and write
2F4E000
direct allocation
page read and write
1797000
unkown
page readonly
2F0A000
direct allocation
page read and write
2E88000
direct allocation
page read and write
2DAE000
direct allocation
page read and write
364A000
heap
page read and write
2CF8000
direct allocation
page read and write
2C64000
direct allocation
page read and write
2D52000
direct allocation
page read and write
2E00000
direct allocation
page read and write
232AF000
stack
page read and write
3180000
direct allocation
page read and write
1E3A000
unkown
page write copy
1797000
unkown
page readonly
1EA8000
unkown
page readonly
22F3F000
stack
page read and write
3480000
heap
page read and write
2C62000
direct allocation
page read and write
2DF4000
direct allocation
page read and write
2DF0000
direct allocation
page read and write
1DD5000
unkown
page write copy
3282000
direct allocation
page read and write
2F80000
direct allocation
page read and write
2D28000
direct allocation
page read and write
35CE000
stack
page read and write
2F1A000
direct allocation
page read and write
37EF000
stack
page read and write
2E98000
direct allocation
page read and write
2D68000
direct allocation
page read and write
4FC0000
remote allocation
page read and write
2F46000
direct allocation
page read and write
1D63000
unkown
page write copy
2590000
heap
page read and write
2CCA000
direct allocation
page read and write
2E6E000
direct allocation
page read and write
2D32000
direct allocation
page read and write
2F54000
direct allocation
page read and write
3654000
heap
page read and write
2F5A000
direct allocation
page read and write
B01000
unkown
page execute read
231AD000
stack
page read and write
2F8A000
direct allocation
page read and write
2A9F000
stack
page read and write
22F54000
direct allocation
page read and write
2BE0000
heap
page read and write
360C000
heap
page read and write
2DF2000
direct allocation
page read and write
56ED000
stack
page read and write
2F12000
direct allocation
page read and write
2DFA000
direct allocation
page read and write
22F44000
direct allocation
page read and write
2F32000
direct allocation
page read and write
3664000
heap
page read and write
2C5C000
direct allocation
page read and write
2DE6000
direct allocation
page read and write
2F34000
direct allocation
page read and write
2DD4000
direct allocation
page read and write
2C70000
direct allocation
page read and write
3632000
heap
page read and write
2DB4000
direct allocation
page read and write
2C2C000
direct allocation
page read and write
2DAC000
direct allocation
page read and write
2F84000
direct allocation
page read and write
265D000
stack
page read and write
2C8E000
direct allocation
page read and write
2F86000
direct allocation
page read and write
2DB8000
direct allocation
page read and write
13F7000
unkown
page readonly
2E7E000
direct allocation
page read and write
3664000
heap
page read and write
22F4F000
direct allocation
page read and write
2C34000
direct allocation
page read and write
325C000
stack
page read and write
3646000
heap
page read and write
2F1C000
direct allocation
page read and write
516D000
stack
page read and write
2F40000
direct allocation
page read and write
1FA0000
heap
page read and write
2DCE000
direct allocation
page read and write
1E3A000
unkown
page write copy
2C3E000
direct allocation
page read and write
22DFF000
stack
page read and write
2C94000
direct allocation
page read and write
2D44000
direct allocation
page read and write
2C84000
direct allocation
page read and write
512D000
stack
page read and write
2E92000
direct allocation
page read and write
2E78000
direct allocation
page read and write
32C0000
remote allocation
page execute and read and write
2F06000
direct allocation
page read and write
4FE0000
heap
page read and write
2C08000
direct allocation
page read and write
24E0000
direct allocation
page read and write
2F3E000
direct allocation
page read and write
3485000
heap
page read and write
23481000
direct allocation
page read and write
2EA6000
direct allocation
page read and write
1D6A000
unkown
page write copy
1DCE000
unkown
page read and write
22F46000
direct allocation
page read and write
233EF000
stack
page read and write
3654000
heap
page read and write
2D00000
direct allocation
page read and write
2560000
direct allocation
page read and write
2D12000
direct allocation
page read and write
2E7C000
direct allocation
page read and write
2DF8000
direct allocation
page read and write
2CFE000
direct allocation
page read and write
2C02000
direct allocation
page read and write
584F000
stack
page read and write
2F00000
direct allocation
page read and write
2C53000
direct allocation
page read and write
2C2A000
direct allocation
page read and write
2DEC000
direct allocation
page read and write
1DCC000
unkown
page write copy
2DEE000
direct allocation
page read and write
2F48000
direct allocation
page read and write
364A000
heap
page read and write
25DD000
stack
page read and write
31D8000
direct allocation
page read and write
2C12000
direct allocation
page read and write
2F1E000
direct allocation
page read and write
2DE2000
direct allocation
page read and write
2D20000
direct allocation
page read and write
1EA8000
unkown
page readonly
2D2C000
direct allocation
page read and write
2CC8000
direct allocation
page read and write
2CC6000
direct allocation
page read and write
2C5A000
direct allocation
page read and write
2DA8000
direct allocation
page read and write
1D5F000
unkown
page read and write
3632000
heap
page read and write
2D14000
direct allocation
page read and write
2C28000
direct allocation
page read and write
2E7A000
direct allocation
page read and write
22F58000
direct allocation
page read and write
1F3C000
stack
page read and write
2F44000
direct allocation
page read and write
2F56000
direct allocation
page read and write
1D5E000
unkown
page write copy
24D7000
heap
page read and write
2660000
heap
page read and write
3648000
heap
page read and write
2CF4000
direct allocation
page read and write
2D0E000
direct allocation
page read and write
2F42000
direct allocation
page read and write
1D64000
unkown
page read and write
2570000
heap
page read and write
2CB4000
direct allocation
page read and write
2E82000
direct allocation
page read and write
1D5E000
unkown
page write copy
4F90000
heap
page read and write
2F02000
direct allocation
page read and write
1D69000
unkown
page read and write
2F22000
direct allocation
page read and write
2F2C000
direct allocation
page read and write
1DBC000
unkown
page read and write
2E8A000
direct allocation
page read and write
2CD6000
direct allocation
page read and write
2F36000
direct allocation
page read and write
3617000
heap
page read and write
1DD7000
unkown
page read and write
2D55000
direct allocation
page read and write
1DC1000
unkown
page read and write
2E8E000
direct allocation
page read and write
3470000
heap
page read and write
32C1000
remote allocation
page execute read
346E000
stack
page read and write
2F6E000
direct allocation
page read and write
2C80000
direct allocation
page read and write
2F38000
direct allocation
page read and write
2CDC000
direct allocation
page read and write
2C26000
direct allocation
page read and write
30D6000
direct allocation
page read and write
There are 292 hidden memdumps, click here to show them.