| File name: | CurseForge - LP-Installer.exe |
| Full analysis: | https://app.any.run/tasks/14e322bd-b128-4ca3-91ff-664b361ede03 |
| Verdict: | Malicious activity |
| Analysis date: | November 25, 2020, 19:28:38 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 86D4C321830B6E4960288D236675A5B9 |
| SHA1: | 4985EE65E50D33588D2A8D3E23BF6CDDD29CE341 |
| SHA256: | 137A9EF28FB489C63BEE9787DBC333F63EF6A0E60F7FEDEBBE54AAEBDD23890A |
| SSDEEP: | 24576:TEtFDx3htth+z1a+w/EBmuc9gjHoeV1t3EM9IBUeLDOqBEdfewRYcn9L:QjzzM5wMkLO7oGt39aHTBq2c9 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2013:12:25 06:01:44+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 25088 |
| InitializedDataSize: | 186368 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x3229 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.156.0.3 |
| ProductVersionNumber: | 2.156.0.3 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | Overwolf Ltd. |
| FileDescription: | CurseForge |
| FileVersion: | 2.156.0.3 |
| LegalCopyright: | Copyright (C) 2019 Overwolf Ltd. All Rights Reserved. |
| LegalTrademarks: | - |
| ProductName: | CurseForge |
| ProductVersion: | 2.156.0.3 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 25-Dec-2013 05:01:44 |
| Detected languages: |
|
| Comments: | - |
| CompanyName: | Overwolf Ltd. |
| FileDescription: | CurseForge |
| FileVersion: | 2.156.0.3 |
| LegalCopyright: | Copyright (C) 2019 Overwolf Ltd. All Rights Reserved. |
| LegalTrademarks: | - |
| ProductName: | CurseForge |
| ProductVersion: | 2.156.0.3 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000C8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 25-Dec-2013 05:01:44 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0000606C | 0x00006200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.45707 |
.rdata | 0x00008000 | 0x00001460 | 0x00001600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.94596 |
.data | 0x0000A000 | 0x0002AF98 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.79535 |
.ndata | 0x00035000 | 0x00013000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x00048000 | 0x000025C8 | 0x00002600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.93913 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.27028 | 773 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 7.68368 | 1306 | UNKNOWN | English - United States | RT_ICON |
3 | 7.6577 | 1009 | UNKNOWN | English - United States | RT_ICON |
4 | 7.50771 | 705 | UNKNOWN | English - United States | RT_ICON |
5 | 7.45128 | 576 | UNKNOWN | English - United States | RT_ICON |
6 | 7.15182 | 417 | UNKNOWN | English - United States | RT_ICON |
103 | 2.69055 | 90 | UNKNOWN | English - United States | RT_GROUP_ICON |
105 | 2.66174 | 256 | UNKNOWN | English - United States | RT_DIALOG |
106 | 2.88094 | 284 | UNKNOWN | English - United States | RT_DIALOG |
111 | 2.48825 | 96 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 444 | "C:\Users\admin\AppData\Local\Temp\CurseForge - LP-Installer.exe" | C:\Users\admin\AppData\Local\Temp\CurseForge - LP-Installer.exe | explorer.exe | ||||||||||||
User: admin Company: Overwolf Ltd. Integrity Level: MEDIUM Description: CurseForge Exit code: 0 Version: 2.156.0.3 Modules
| |||||||||||||||
| 2508 | "C:\Users\admin\AppData\Local\Temp\nsi37F7.tmp\OWinstaller.exe" Partner=4047&Extension=cchhcaiapeikjbdbpfplgmpobbcdkdaphclbmkbj&Name=CurseForge&Sel=1 /UAC:2012A /NCRC -partnerCustomizationLevel 0 -customPromoPages -exepath C:\Users\admin\AppData\Local\Temp\CurseForge - LP-Installer.exe | C:\Users\admin\AppData\Local\Temp\nsi37F7.tmp\OWinstaller.exe | CurseForge - LP-Installer.exe | ||||||||||||
User: admin Company: Overwolf Integrity Level: HIGH Description: Overwolf Installer Exit code: 0 Version: 2.156.0.0 Modules
| |||||||||||||||
| 2612 | "C:\Users\admin\AppData\Local\Temp\CurseForge - LP-Installer.exe" /UAC:2012A /NCRC | C:\Users\admin\AppData\Local\Temp\CurseForge - LP-Installer.exe | CurseForge - LP-Installer.exe | ||||||||||||
User: admin Company: Overwolf Ltd. Integrity Level: HIGH Description: CurseForge Exit code: 0 Version: 2.156.0.3 Modules
| |||||||||||||||
| 3984 | "C:\Windows\System32\DxDiag.exe" /tC:\Users\admin\AppData\Local\Overwolf\Temp\DxDiagOutput.txt | C:\Windows\System32\DxDiag.exe | OWinstaller.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft DirectX Diagnostic Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2612) CurseForge - LP-Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2612) CurseForge - LP-Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A5000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2612) CurseForge - LP-Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2612) CurseForge - LP-Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2612) CurseForge - LP-Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2612) CurseForge - LP-Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2612) CurseForge - LP-Installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2508) OWinstaller.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2508) OWinstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54 |
| Operation: | write | Name: | Blob |
Value: 0400000001000000100000008EADB501AA4D81E48C1DD1E1140095190F000000010000002000000017FE16F394EC70A5BB0C6784CAB40B1E61025AE9D50ECAA0531D6B4D997BBC590300000001000000140000003679CA35668772304D30A5FB873B0FA77BB70D547E00000001000000080000000040D0D1B0FFD4017F000000010000000C000000300A06082B060105050703011D0000000100000010000000439B4D52906DF7A01771D729528723B3140000000100000014000000B677FA6948479F5312D5C2EA07327607D19707196200000001000000200000002399561127A57125DE8CEFEA610DDF2FA078B5C8067F4E828290BFB860E84B3C53000000010000002500000030233021060B6086480186F8450107170630123010060A2B0601040182373C0101030200C0090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703080B000000010000006000000056006500720069005300690067006E00200055006E006900760065007200730061006C00200052006F006F0074002000430065007200740069006600690063006100740069006F006E00200041007500740068006F0072006900740079000000190000000100000010000000AD6D6FF31B24013151F279E26A8C33242000000001000000BD040000308204B9308203A1A0030201020210401AC46421B31321030EBBE4121AC51D300D06092A864886F70D01010B05003081BD310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313A3038060355040B1331286329203230303820566572695369676E2C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79313830360603550403132F566572695369676E20556E6976657273616C20526F6F742043657274696669636174696F6E20417574686F72697479301E170D3038303430323030303030305A170D3337313230313233353935395A3081BD310B300906035504061302555331173015060355040A130E566572695369676E2C20496E632E311F301D060355040B1316566572695369676E205472757374204E6574776F726B313A3038060355040B1331286329203230303820566572695369676E2C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79313830360603550403132F566572695369676E20556E6976657273616C20526F6F742043657274696669636174696F6E20417574686F7269747930820122300D06092A864886F70D01010105000382010F003082010A0282010100C761375EB10134DB62D7159BFF585A8C2323D6608E91D79098837AE65819388CC5F6E56485B4A271FBEDBDB9DACD4D00B4C82D73A5C76971951F393CB244079CE80EFA4D4AC421DF29618F32226182C5871F6E8C7C5F16205144D1704F57EAE31CE3CC79EE58D80EC2B34593C02CE79A172B7B00377A413378E133E2F3101A7F872CBEF6F5F742E2E5BF8762895F004BDFC5DDE4754432413A1E716E69CB0B754608D1CAD22B95D0CFFBB9406B648C574DFC13117984ED5E54F6349F0801F3102506174ADAF11D7A666B986066A4D9EFD22E82F1F0EF09EA44C9156AE2036E33D3AC9F5500C7F6086A94B95FDCE033F18460F95B2711B4FC16F2BB566A80258D0203010001A381B23081AF300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106306D06082B0601050507010C0461305FA15DA05B3059305730551609696D6167652F6769663021301F300706052B0E03021A04148FE5D31A86AC8D8E6BC3CF806AD448182C7B192E30251623687474703A2F2F6C6F676F2E766572697369676E2E636F6D2F76736C6F676F2E676966301D0603551D0E04160414B677FA6948479F5312D5C2EA07327607D1970719300D06092A864886F70D01010B050003820101004AF8F8B003E62C677BE4947763CC6E4CF97D0E0DDCC8B935B9704F63FA24FA6C838C479D3B63F39AF976329591B177BCAC9ABEB1E43121C68195565A0EB1C2D4B1A659ACF163CBB84C1D59904AEF9016281F5AAE10FB8150380C6CCCF13DC3F563E3B3E321C92439E9FD156646F41B11D04D73A37D46F93DEDA85F62D4F13FF8E074572B189D81B4C428DA9497A570EBAC1DBE0711F0D5DBDDE58CF0D532B083E657E28FBFBEA1AABF3D1DB5D438EAD7B05C3A4F6A3F8FC0666C63AAE9D9A416F481D195140E7DCD9534D9D28F7073817B9C7EBD9861D845879890C5EB8630C635BFF0FFC35588834BEF05920671F2B89893B7ECCD8261F138E64F97982A5A8D | |||
| (PID) Process: | (2508) OWinstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 |
| Operation: | write | Name: | Blob |
Value: 04000000010000001000000087CE0B7B2A0E4900E158719B37A893720F00000001000000140000006DCA5BD00DCF1C0F327059D374B29CA6E3C50AA60300000001000000140000000563B8630D62D75ABBC8AB1E4BDFB5A899B24D431D00000001000000100000004F5F106930398D09107B40C3C7CA8F1C0B000000010000001200000044006900670069004300650072007400000014000000010000001400000045EBA2AFF492CB82312D518BA7A7219DF36DC80F6200000001000000200000003E9099B5015E8F486C00BCEA9D111EE721FABA355A89BCF1DF69561E3DC6325C5300000001000000230000003021301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308190000000100000010000000749966CECC95C1874194CA7203F9B6202000000001000000BB030000308203B73082029FA00302010202100CE7E0E517D846FE8FE560FC1BF03039300D06092A864886F70D01010505003065310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D312430220603550403131B4469676943657274204173737572656420494420526F6F74204341301E170D3036313131303030303030305A170D3331313131303030303030305A3065310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D312430220603550403131B4469676943657274204173737572656420494420526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100AD0E15CEE443805CB187F3B760F97112A5AEDC269488AAF4CEF520392858600CF880DAA9159532613CB5B128848A8ADC9F0A0C83177A8F90AC8AE779535C31842AF60F98323676CCDEDD3CA8A2EF6AFB21F25261DF9F20D71FE2B1D9FE1864D2125B5FF9581835BC47CDA136F96B7FD4B0383EC11BC38C33D9D82F18FE280FB3A783D6C36E44C061359616FE599C8B766DD7F1A24B0D2BFF0B72DA9E60D08E9035C678558720A1CFE56D0AC8497C3198336C22E987D0325AA2BA138211ED39179D993A72A1E6FAA4D9D5173175AE857D22AE3F014686F62879C8B1DAE45717C47E1C0EB0B492A656B3BDB297EDAAA7F0B7C5A83F9516D0FFA196EB085F18774F0203010001A3633061300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF301D0603551D0E0416041445EBA2AFF492CB82312D518BA7A7219DF36DC80F301F0603551D2304183016801445EBA2AFF492CB82312D518BA7A7219DF36DC80F300D06092A864886F70D01010505000382010100A20EBCDFE2EDF0E372737A6494BFF77266D832E4427562AE87EBF2D5D9DE56B39FCCCE1428B90D97605C124C58E4D33D834945589735691AA847EA56C679AB12D8678184DF7F093C94E6B8262C20BD3DB32889F75FFF22E297841FE965EF87E0DFC16749B35DEBB2092AEB26ED78BE7D3F2BF3B726356D5F8901B6495B9F01059BAB3D25C1CCB67FC2F16F86C6FA6468EB812D94EB42B7FA8C1EDD62F1BE5067B76CBDF3F11F6B0C3607167F377CA95B6D7AF112466083D72704BE4BCE97BEC3672A6811DF80E70C3366BF130D146EF37F1F63101EFA8D1B256D6C8FA5B76101B1D2A326A110719DADE2C3F9C39951B72B0708CE2EE650B2A7FA0A452FA2F0F2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2612 | CurseForge - LP-Installer.exe | C:\Users\admin\AppData\Local\Temp\nsi37F7.tmp\utils.dll | executable | |
MD5:AAD3F2ECC74DDF65E84DCB62CF6A77CD | SHA256:1CC004FCCE92824FA27565B31299B532733C976671AC6CF5DBD1E0465C0E47E8 | |||
| 2612 | CurseForge - LP-Installer.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Counter[1] | text | |
MD5:99914B932BD37A50B983C5E7C90AE93B | SHA256:44136FA355B3678A1146AD16F7E8649E94FB4FC21FE77E8310C060F61CAAFF8A | |||
| 2612 | CurseForge - LP-Installer.exe | C:\Users\admin\AppData\Local\Temp\nsi37F7.tmp\nsis7z.dll | executable | |
MD5:C14EC45E78D9CB3CFBAEA923A1A13B20 | SHA256:5BDB67BD31266E05927C42E6B098F6462B40AB6DBA2AE39FA1C14F2FE9F838C3 | |||
| 2612 | CurseForge - LP-Installer.exe | C:\Users\admin\AppData\Local\Temp\nsi37F7.tmp\app\cmp.html | html | |
MD5:F86A5FCC1A4571E07DA1643E35C355E4 | SHA256:63BE4AF3233394C6B8EFAA16DC8C6C68C13CF09B102FF7424DBE06DF1B3E1CAE | |||
| 2612 | CurseForge - LP-Installer.exe | C:\Users\admin\AppData\Local\Temp\nsi37F7.tmp\app\progress.html | html | |
MD5:BAA1EC5A1832EED48FE04EE731F22E43 | SHA256:52D120576A0CE22D4B81CDA28C18103E808D9F8A0201ED31C71EAF6D133C53B2 | |||
| 2612 | CurseForge - LP-Installer.exe | C:\Users\admin\AppData\Local\Temp\nsi37F7.tmp\uac.dll | executable | |
MD5:ADB29E6B186DAA765DC750128649B63D | SHA256:2F7F8FC05DC4FD0D5CDA501B47E4433357E887BBFED7292C028D99C73B52DC08 | |||
| 2612 | CurseForge - LP-Installer.exe | C:\Users\admin\AppData\Local\Temp\nsi37F7.tmp\INetC.dll | executable | |
MD5:640BFF73A5F8E37B202D911E4749B2E9 | SHA256:C1E568E25EC111184DEB1B87CFDA4BFEC529B1ABEAB39B66539D998012F33502 | |||
| 2612 | CurseForge - LP-Installer.exe | C:\Users\admin\AppData\Local\Temp\nsi37F7.tmp\System.dll | executable | |
MD5:7399323923E3946FE9140132AC388132 | SHA256:5A1C20A3E2E2EB182976977669F2C5D9F3104477E98F74D69D2434E79B92FDC3 | |||
| 2612 | CurseForge - LP-Installer.exe | C:\Users\admin\AppData\Local\Temp\nsi37F7.tmp\UserInfo.dll | executable | |
MD5:9301577FF4D229347FE33259B43EF3B2 | SHA256:090C4BC8DC534E97B3877BD5115EB58B3E181495F29F231479F540BAB5C01EDC | |||
| 2612 | CurseForge - LP-Installer.exe | C:\Users\admin\AppData\Local\Temp\nsi37F7.tmp\OWInstaller.exe.config | xml | |
MD5:4BF2A039CD2CF37CF37C19F2912996E0 | SHA256:EC7C6BC4205712A0A78C68F7F0F762AC7E62276720A61A6877A94F6A573F0AA7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2508 | OWinstaller.exe | GET | 200 | 65.9.70.213:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | US | der | 1.51 Kb | whitelisted |
2508 | OWinstaller.exe | GET | 200 | 69.16.175.10:80 | http://analyticsnew.overwolf.com/analytics/Counter?CurrentVersion=2.156.0.0&PartnerID=4047&Name=installer_cancel_before_download&Value=1&UserName=&GameSessionId=&owver=0.156.0.12&MUID=1cb5fad4-a11c-4f67-bbc6-24c4c9e7f185 | US | text | 2 b | malicious |
2612 | CurseForge - LP-Installer.exe | GET | 200 | 69.16.175.10:80 | http://analyticsnew.overwolf.com/analytics/Counter?Name=installer_uac_action&Value=1&Extra=%5b%7b%22Name%22%3a%22installer_version%22%2c%22Value%22%3a%222.156.0.3%22%7d%5d | US | text | 2 b | malicious |
2508 | OWinstaller.exe | GET | 200 | 69.16.175.10:80 | http://analyticsnew.overwolf.com/analytics/Counter?CurrentVersion=2.156.0.0&PartnerID=4047&Name=Manual_Funnel2_Installer_Launched&Value=1&UserName=&GameSessionId=&owver=0.156.0.12&MUID=1cb5fad4-a11c-4f67-bbc6-24c4c9e7f185 | US | text | 2 b | malicious |
2508 | OWinstaller.exe | GET | 200 | 69.16.175.10:80 | http://analyticsnew.overwolf.com/analytics/Counter?CurrentVersion=2.156.0.0&PartnerID=4047&Name=Manual_Installer_Installer_Exit&Value=1&UserName=&GameSessionId=&owver=0.156.0.12&MUID=1cb5fad4-a11c-4f67-bbc6-24c4c9e7f185 | US | text | 2 b | malicious |
2508 | OWinstaller.exe | GET | 200 | 172.217.22.46:80 | http://www.google-analytics.com/__utm.gif?utmwv=4.7.2&utmn=752841560&utmhn=&utmcs=UTF-8&utmsr=-&utmsc=-&utmul=-&utmje=0&utmfl=-&utmdt=&utmhid=997402442&utmr=/&utmp=/&utmac=UA-80584726-1&utmcc=__utma%3D0.1228179180.1606332543.1606332543.1606332543.2%3B%2B__utmz%3D0.1606332543.1.1.utmcsr%3D(direct)%7Cutmccn%3D%7Cutmcmd%3D%3B&utme=5(Funnel2*Installer%20Launched*2.0.50727%20SP2%2C%203.0%20SP2%2C%203.5%20SP1%2C%204%20Client%2C%204%20Full%2C%204.0%20Client)()&gaq=1&utmt=event | US | image | 35 b | whitelisted |
2508 | OWinstaller.exe | GET | 200 | 69.16.175.10:80 | http://analyticsnew.overwolf.com/analytics/Counter?CurrentVersion=2.156.0.0&PartnerID=4047&Name=Manual_Installer_Launched&Value=1&UserName=&GameSessionId=&owver=0.156.0.12&MUID=1cb5fad4-a11c-4f67-bbc6-24c4c9e7f185 | US | text | 2 b | malicious |
2508 | OWinstaller.exe | GET | 200 | 172.217.22.46:80 | http://www.google-analytics.com/__utm.gif?utmwv=4.7.2&utmn=34402498&utmhn=&utmcs=UTF-8&utmsr=-&utmsc=-&utmul=-&utmje=0&utmfl=-&utmdt=&utmhid=779474596&utmr=/&utmp=/&utmac=UA-80584726-1&utmcc=__utma%3D0.1228179180.1606332543.1606332543.1606332543.2%3B%2B__utmz%3D0.1606332543.1.1.utmcsr%3D(direct)%7Cutmccn%3D%7Cutmcmd%3D%3B&utme=5(Installer*Installer%20Exit*Cancelled%20before%20download)()&gaq=1&utmt=event | US | image | 35 b | whitelisted |
2508 | OWinstaller.exe | GET | 200 | 172.217.22.46:80 | http://www.google-analytics.com/__utm.gif?utmwv=4.7.2&utmn=21139408&utmhn=&utmcs=UTF-8&utmsr=-&utmsc=-&utmul=-&utmje=0&utmfl=-&utmdt=&utmhid=724081919&utmr=/&utmp=/&utmac=UA-18298709-8&utmcc=__utma%3D0.1228179180.1606332543.1606332543.1606332543.2%3B%2B__utmz%3D0.1606332543.1.1.utmcsr%3D(direct)%7Cutmccn%3D%7Cutmcmd%3D%3B&utme=5(Funnel2*Installer%20Launched*2.0.50727%20SP2%2C%203.0%20SP2%2C%203.5%20SP1%2C%204%20Client%2C%204%20Full%2C%204.0%20Client)()&gaq=1&utmt=event | US | image | 35 b | whitelisted |
2508 | OWinstaller.exe | GET | 200 | 69.16.175.10:80 | http://analyticsnew.overwolf.com/analytics/Counter?CurrentVersion=2.156.0.0&PartnerID=4047&Name=installer_error_message&Value=22012&UserName=&GameSessionId=&Extra=%255b%257b%2522Name%2522%253a%2522state%2522%252c%2522Value%2522%253anull%257d%252c%257b%2522Name%2522%253a%2522sel_app%2522%252c%2522Value%2522%253a%2522cchhcaiapeikjbdbpfplgmpobbcdkdaphclbmkbj%2522%257d%255d&owver=0.156.0.12&MUID=1cb5fad4-a11c-4f67-bbc6-24c4c9e7f185 | US | text | 2 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2508 | OWinstaller.exe | 69.16.175.10:80 | analyticsnew.overwolf.com | Highwinds Network Group, Inc. | US | malicious |
2508 | OWinstaller.exe | 172.217.22.46:80 | www.google-analytics.com | Google Inc. | US | whitelisted |
3984 | DxDiag.exe | 93.184.221.240:80 | www.download.windowsupdate.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2508 | OWinstaller.exe | 65.9.70.213:80 | ocsp.rootg2.amazontrust.com | AT&T Services, Inc. | US | whitelisted |
2508 | OWinstaller.exe | 65.9.70.156:80 | o.ss2.us | AT&T Services, Inc. | US | unknown |
— | — | 65.9.70.213:80 | ocsp.rootg2.amazontrust.com | AT&T Services, Inc. | US | whitelisted |
2508 | OWinstaller.exe | 65.9.68.39:443 | www.overwolf.com | AT&T Services, Inc. | US | suspicious |
2612 | CurseForge - LP-Installer.exe | 69.16.175.10:80 | analyticsnew.overwolf.com | Highwinds Network Group, Inc. | US | malicious |
2508 | OWinstaller.exe | 65.9.68.20:443 | storeapi.overwolf.com | AT&T Services, Inc. | US | unknown |
2508 | OWinstaller.exe | 65.9.68.13:443 | content.overwolf.com | AT&T Services, Inc. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
analyticsnew.overwolf.com |
| malicious |
www.google-analytics.com |
| whitelisted |
content.overwolf.com |
| whitelisted |
o.ss2.us |
| whitelisted |
www.download.windowsupdate.com |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
storeapi.overwolf.com |
| shared |
www.overwolf.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2612 | CurseForge - LP-Installer.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
2612 | CurseForge - LP-Installer.exe | Misc activity | SUSPICIOUS [PTsecurity] HTTP header - Sometimes used by hostile installer |