IOC Report
file.exe

loading gif

Files

File Path
Type
Category
Malicious
file.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\AKFIDHDG
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\ProgramData\CFIEGDAE
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
modified
C:\ProgramData\DAKJDAAFBKFHIEBFCFBK
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\ProgramData\GCFHDAKE
SQLite 3.x database, last written using SQLite version 3042000, file counter 4, database pages 39, cookie 0x20, schema 4, UTF-8, version-valid-for 4
dropped
C:\ProgramData\GIIIECBGDHJJKFIDAKJDHJJKEB
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\ProgramData\JEBFIIIE
SQLite 3.x database, last written using SQLite version 3035005, file counter 2, database pages 31, cookie 0x18, schema 4, UTF-8, version-valid-for 2
dropped
C:\ProgramData\JJJEBGDAFHJEBGDGIJDH
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, Windows 2000/XP setup, 69993 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
dropped
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\76561199680449169[1].htm
HTML document, Unicode text, UTF-8 text, with very long lines (3041), with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\YLNGKWRH\sqlx[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
There are 2 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\file.exe
"C:\Users\user\Desktop\file.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
malicious

URLs

Name
IP
Malicious
https://duckduckgo.com/chrome_newtab
unknown
https://duckduckgo.com/ac/?q=
unknown
https://community.cloudflare.steamstatic.com/public/javascript/webui/clientcom.js?v=gzzYk5pkHqW6&amp
unknown
https://95.217.245.42:9000softokn3.dll0_15_7)
unknown
https://steamcommunity.com/?subsection=broadcasts
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_global.js?v=wJD9maDpDcV
unknown
https://95.217.245.42:9000/mozglue.dll
unknown
https://store.steampowered.com/subscriber_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=engli
unknown
https://community.cloudflare.steamstatic.com/public/javascript/promo/stickers.js?v=GfA42_x2_aub&
unknown
https://steamcommunity.com/profiles/76561199680449169
104.105.90.131
https://95.217.245.42:9000/msvcp140.dlldge
unknown
https://ch.search.yahoo.com/favicon.icohttps://ch.sea
unknown
https://95.217.245.42:9000
unknown
https://community.cloudflare.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpE
unknown
http://www.valvesoftware.com/legal.htm
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/main.js?v=roSu
unknown
https://95.217.245.42:9000/.245.42:9000/freebl3.dll
unknown
https://95.217.245.42:9000/softokn3.dllQy
unknown
https://95.217.245.42/o
unknown
https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17rer.exe
unknown
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
unknown
https://95.217.245.42:9000/ng
unknown
https://95.217.245.42:9000l
unknown
https://95.217.245.42:9000/soft
unknown
https://95.217.245.42:9000/U
unknown
https://95.217.245.42:9000/nss3.dllH
unknown
https://95.217.245.42:9000/freebl3.dllu~(
unknown
https://95.217.245.42:9000/vcruntime140.dllE
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/modalContent.css?v=.TP5s6TzX6LLh&
unknown
https://95.217.245.42/f
unknown
https://95.217.245.42:9000/nss3.dllft
unknown
https://community.cloudflare.steamstatic.com/public/javascript/modalContent.js?v=Wd0kCESeJquW&l=
unknown
https://steamcommunity.com/r
unknown
https://community.cloudflare.steamstatic.com/public/javascript/prototype-1.7.js?v=.55t44gwuwgvw&
unknown
https://store.steampowered.com/e
unknown
http://store.steampowered.com/privacy_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/css/applications/community/main.css?v=tIrWyaxi8A
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/shared_responsive.css?v=eghn9DNyCY67&
unknown
https://store.steampowered.com/points/shop/
unknown
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
unknown
https://95.217.245.42:9000/~rQ
unknown
https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016
unknown
https://community.cloudflare.steamstatic.com/public/css/promo/summer2017/stickers.css?v=bZKSp7oNwVPK
unknown
https://community.cloudflare.steamstatic.com/public/javascript/reportedcontent.js?v=dAtjbcZMWhSe&amp
unknown
https://steamcommunity.com/profiles/76561199680449169/badges
unknown
https://www.ecosia.org/newtab/
unknown
https://store.steampowered.com/privacy_agreement/
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/shared_global.css?v=2VoZa2M8Wh3k&
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
unknown
https://ch.search.yahoo.com/sugg/chrom
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/libraries~b28b
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_logo.png
unknown
https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016Examples
unknown
https://95.217.245.42:9000/mozglue.dllome
unknown
https://store.steampowered.com/about/
unknown
https://steamcommunity.com/my/wishlist/
unknown
https://community.cloudflare.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC&
unknown
https://help.steampowered.com/en/
unknown
https://steamcommunity.com/market/
unknown
https://store.steampowered.com/news/
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/toolt
unknown
https://community.cloudflare.steamstatic.com/public/javascript/global.js?v=PyuRtGtUpR0t&l=englis
unknown
https://steamcommunity.com/profiles/76561199680449169#BT
unknown
https://95.217.245.42:9000/nss3.dll
unknown
https://95.217.245.42:9000/freebl3.dllEdge
unknown
https://95.217.245.42:9000el
unknown
https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
unknown
http://store.steampowered.com/subscriber_agreement/
unknown
https://steamcommunity.com/login/home/?goto=profiles%2F76561199680449169
unknown
https://community.cloudflare.steamstatic.com/public/javascript/applications/community/manifest.js?v=
unknown
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
unknown
https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17
unknown
https://95.217.245.42:9000/softokn3.dll$y
unknown
https://95.217.245.42:9000/sqlx.dll:
unknown
https://steamcommunity.com/discussions/
unknown
https://t.me/r1g1o
unknown
https://store.steampowered.com/stats/
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0&amp
unknown
https://store.steampowered.com/steam_refunds/
unknown
https://community.cloudflare.steamstatic.com/public/images/skin_1/arrowDn9x5.gif
unknown
https://community.cloudflare.steamstatic.com/public/shared/javascript/shared_responsive_adapter.js?v
unknown
https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17Install
unknown
https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
unknown
https://community.cloudflare.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.p
unknown
https://95.217.245.42:9000/msvcp140.dll
unknown
https://steamcommunity.com/workshop/
unknown
https://store.steampowered.com/legal/
unknown
http://www.sqlite.org/copyright.html.
unknown
https://95.217.245.42:9000/B
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/buttons.css?v=tuNiaSwXwcYT&l=engl
unknown
https://community.cloudflare.steamstatic.com/public/shared/css/motiva_sans.css?v=GfSjbGKcNYaQ&l=
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/profilev2.css?v=gNE3gksLVEVa&l=en
unknown
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
unknown
https://community.cloudflare.steamstatic.com/public/css/globalv2.css?v=pwVcIAtHNXwg&l=english&am
unknown
https://community.cloudflare.steamstatic.com/public/css/skin_1/header.css?v=vh4BMeDcNiCU&l=engli
unknown
https://95.217.245.42:9000/vcruntime140.dllUser
unknown
https://store.steampowered.com/
unknown
https://95.217.245.42:9000/5
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
steamcommunity.com
104.105.90.131

IPs

IP
Domain
Country
Malicious
95.217.245.42
unknown
Germany
104.105.90.131
steamcommunity.com
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
400000
remote allocation
page execute and read and write
malicious
B5000
unkown
page read and write
malicious
14F2000
heap
page read and write
malicious
14D5000
heap
page read and write
ED8F000
stack
page read and write
12FE000
stack
page read and write
12F5000
stack
page read and write
A13F000
stack
page read and write
5BC000
stack
page read and write
163F4000
heap
page read and write
525000
remote allocation
page execute and read and write
16709000
heap
page read and write
1C678000
direct allocation
page readonly
1579000
heap
page read and write
AEA000
heap
page read and write
AC000
unkown
page readonly
3C25000
heap
page read and write
606000
remote allocation
page execute and read and write
431000
remote allocation
page execute and read and write
8FD000
stack
page read and write
FDF000
stack
page read and write
90000
unkown
page readonly
1430000
heap
page read and write
A03E000
stack
page read and write
164FD000
heap
page read and write
15E2000
heap
page read and write
158D000
heap
page read and write
EC3D000
stack
page read and write
910000
heap
page read and write
EA000
unkown
page read and write
EA000
unkown
page write copy
A17D000
stack
page read and write
C6BC000
stack
page read and write
15D5000
heap
page read and write
B7000
unkown
page write copy
3C2D000
heap
page read and write
920000
heap
page read and write
156F000
heap
page read and write
13D5000
heap
page read and write
AE0000
heap
page read and write
90000
unkown
page readonly
1589000
heap
page read and write
EDFD000
stack
page read and write
1656000
heap
page read and write
1C460000
direct allocation
page execute and read and write
1350000
heap
page read and write
435000
remote allocation
page execute and read and write
9A0000
heap
page read and write
1395B000
unkown
page read and write
1133E000
stack
page read and write
163F6000
heap
page read and write
15D1000
heap
page read and write
CDF000
stack
page read and write
1C66F000
direct allocation
page readonly
1C6AA000
direct allocation
page readonly
E8000
unkown
page readonly
96E000
stack
page read and write
16662000
heap
page read and write
1340000
heap
page read and write
113BE000
stack
page read and write
1670B000
heap
page read and write
16644000
heap
page read and write
ABE000
stack
page read and write
AC000
unkown
page readonly
1C6AD000
direct allocation
page readonly
15A0000
heap
page read and write
15E7000
heap
page read and write
13AAE000
stack
page read and write
1C461000
direct allocation
page execute read
147A000
heap
page read and write
1575000
heap
page read and write
63C000
remote allocation
page execute and read and write
1C6A2000
direct allocation
page read and write
163F0000
heap
page read and write
AEE000
heap
page read and write
16DC000
heap
page read and write
160F0000
heap
page read and write
16D1000
heap
page read and write
3C20000
heap
page read and write
16EB000
heap
page read and write
52E000
remote allocation
page execute and read and write
162E0000
heap
page read and write
2680000
heap
page read and write
C6FD000
stack
page read and write
1C468000
direct allocation
page execute read
1587000
heap
page read and write
1470000
heap
page read and write
528000
remote allocation
page execute and read and write
E8000
unkown
page readonly
91000
unkown
page execute read
91000
unkown
page execute read
15FEE000
stack
page read and write
16504000
heap
page read and write
B5000
unkown
page write copy
1C5C6000
direct allocation
page execute read
13D0000
heap
page read and write
FDC000
stack
page read and write
163FC000
heap
page read and write
13C0000
heap
page read and write
160EC000
stack
page read and write
EC8E000
stack
page read and write
56C000
remote allocation
page execute and read and write
15BC000
heap
page read and write
1C6AF000
direct allocation
page readonly
1C66D000
direct allocation
page execute read
138FF000
stack
page read and write
E6000
unkown
page execute and read and write
162F9000
heap
page read and write
There are 98 hidden memdumps, click here to show them.