File name:

Battle.net-Setup.exe

Full analysis: https://app.any.run/tasks/2664ea51-a099-4af7-ad37-9236142c6537
Verdict: Malicious activity
Analysis date: March 29, 2026, 07:21:20
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
evasion
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

22021F3A3C589E9A29F6528040C83BC9

SHA1:

6587619B3976004EB5CC3479509A4D1476E693F5

SHA256:

2FBA59599487DBD92C86E0BEC15A47BE75CA0BC5AAA99478025EE32594E2D494

SSDEEP:

98304:BLoEOs4A7dZOS13u4Nk9xSi8hpAWXuhgHjnwxiWicGWYQAw1ilOBxvT4nlJF2YLR:PqWek

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks for external IP

      • Battle.net-Setup.exe (PID: 8008)
      • Battle.net-Setup.exe (PID: 5660)
    • Potential Corporate Privacy Violation

      • Battle.net-Setup.exe (PID: 8008)
      • Battle.net-Setup.exe (PID: 5660)
    • Application launched itself

      • Battle.net-Setup.exe (PID: 8008)
    • Executable content was dropped or overwritten

      • AgentHelper.exe (PID: 2324)
      • Battle.net-Setup.exe (PID: 5660)
      • Agent.exe (PID: 6856)
    • The process drops C-runtime libraries

      • Agent.exe (PID: 6856)
  • INFO

    • Checks supported languages

      • Battle.net-Setup.exe (PID: 8008)
      • Battle.net-Setup.exe (PID: 5660)
      • AgentHelper.exe (PID: 2324)
      • Agent.exe (PID: 1776)
      • Agent.exe (PID: 6856)
    • Reads the computer name

      • Battle.net-Setup.exe (PID: 8008)
      • Battle.net-Setup.exe (PID: 5660)
      • AgentHelper.exe (PID: 2324)
      • Agent.exe (PID: 1776)
      • Agent.exe (PID: 6856)
    • Reads the machine GUID from the registry

      • Battle.net-Setup.exe (PID: 8008)
      • Battle.net-Setup.exe (PID: 5660)
      • AgentHelper.exe (PID: 2324)
      • Agent.exe (PID: 6856)
    • Reads security settings of Internet Explorer

      • Battle.net-Setup.exe (PID: 8008)
      • Agent.exe (PID: 6856)
      • AgentHelper.exe (PID: 2324)
      • Battle.net-Setup.exe (PID: 5660)
      • Agent.exe (PID: 1776)
    • Creates files or folders in the user directory

      • Battle.net-Setup.exe (PID: 8008)
      • Agent.exe (PID: 6856)
    • The sample compiled with english language support

      • Agent.exe (PID: 6856)
      • AgentHelper.exe (PID: 2324)
      • Battle.net-Setup.exe (PID: 5660)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:09:17 01:00:24+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.15
CodeSize: 2917376
InitializedDataSize: 1967616
UninitializedDataSize: -
EntryPoint: 0x1388a6
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.19.0.3190
ProductVersionNumber: 1.19.0.3190
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
LegalCopyright: © 2005-2025 Blizzard Entertainment Inc.
InternalName: Battle.net Setup
FileVersion: 1.19.0.3190
CompanyName: Blizzard Entertainment
ProductName: Battle.net Setup
ProductVersion: 1.19.0.3190
FileDescription: Battle.net Setup
OriginalFileName: Battle.net-Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
7
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start battle.net-setup.exe battle.net-setup.exe agent.exe no specs agent.exe conhost.exe no specs agenthelper.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1776"C:\ProgramData\Battle.net\Agent\Agent.exe" --locale=enUS --session=14888713414312203981C:\ProgramData\Battle.net\Agent\Agent.exeBattle.net-Setup.exe
User:
admin
Company:
Blizzard Entertainment
Integrity Level:
HIGH
Description:
Battle.net File Switcher
Exit code:
0
Version:
2.39.5.9414
Modules
Images
c:\programdata\battle.net\agent\agent.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2324"C:\ProgramData\Battle.net\Agent\AgentHelper.exe" --install --target=C:/ProgramData/Battle.net_components/battlenet_helpersvc/AgentHelper.exeC:\ProgramData\Battle.net\Agent\AgentHelper.exe
Agent.exe
User:
admin
Company:
Blizzard Entertainment
Integrity Level:
HIGH
Description:
Battle.net Admin Agent
Exit code:
0
Version:
2.39.5.9414
Modules
Images
c:\programdata\battle.net\agent\agenthelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2420\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAgentHelper.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5660"C:\Users\admin\AppData\Local\Temp\Battle.net-Setup.exe" --cmdver=2 --elevated --locale=enUS --mode=setup --session=14888713414312203981C:\Users\admin\AppData\Local\Temp\Battle.net-Setup.exe
Battle.net-Setup.exe
User:
admin
Company:
Blizzard Entertainment
Integrity Level:
HIGH
Description:
Battle.net Setup
Version:
1.19.0.3190
Modules
Images
c:\users\admin\appdata\local\temp\battle.net-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\rpcrt4.dll
6856"C:\ProgramData\Battle.net\Agent\Agent.9414\Agent.exe" --locale=enUS --session=14888713414312203981C:\ProgramData\Battle.net\Agent\Agent.9414\Agent.exe
Agent.exe
User:
admin
Company:
Blizzard Entertainment
Integrity Level:
HIGH
Description:
Battle.net Update Agent
Version:
2.39.5.9414
Modules
Images
c:\programdata\battle.net\agent\agent.9414\agent.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\wintrust.dll
7508\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAgent.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8008"C:\Users\admin\AppData\Local\Temp\Battle.net-Setup.exe" C:\Users\admin\AppData\Local\Temp\Battle.net-Setup.exe
explorer.exe
User:
admin
Company:
Blizzard Entertainment
Integrity Level:
MEDIUM
Description:
Battle.net Setup
Exit code:
0
Version:
1.19.0.3190
Modules
Images
c:\users\admin\appdata\local\temp\battle.net-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\rpcrt4.dll
Total events
15 140
Read events
15 138
Write events
2
Delete events
0

Modification events

(PID) Process:(8008) Battle.net-Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Blizzard Entertainment\Blizzard Error
Operation:writeName:UserUUID
Value:
E311B485-09A1-4657-90C6-C023C2707864
(PID) Process:(8008) Battle.net-Setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Blizzard Entertainment\Launcher
Operation:writeName:Locale
Value:
enUS
Executable files
151
Suspicious files
514
Text files
41
Unknown types
0

Dropped files

PID
Process
Filename
Type
5660Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\.Blizzard Uninstaller.exe.13.5660.tempexecutable
MD5:8EA343B30C477CABD0D05FC187EDC382
SHA256:84BD6E776DA568BC002218890058ECD9A359777389A58D4147468563D1ABE3C0
5660Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\..Blizzard Uninstaller.exe.11.5660.temp.12.5660.temp.tempexecutable
MD5:8EA343B30C477CABD0D05FC187EDC382
SHA256:84BD6E776DA568BC002218890058ECD9A359777389A58D4147468563D1ABE3C0
8008Battle.net-Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_F54D7F30A60C319C43969E40DAF830E1binary
MD5:3DDD72CDC3FC1DE03A13CFCF0A6C030A
SHA256:8FEE479687421FD87C66C46CBE22DC3A48260E433307B18691237EDAA81459E2
5660Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\.LICENSES.14.5660.tempbinary
MD5:A7279912EBA47364A179ABF6F247E929
SHA256:44C68CDCDCB51EA109D9979F2A812F30757E4A20EFAF12DE95F769BADB7DBD76
5660Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\..BlizzardError.exe.20.5660.temp.21.5660.tempexecutable
MD5:A44A76265F9F22258D7665FFA5262CB6
SHA256:BE2394FF7880E403A92AD773C675295A47E9FAFE330F01DF21FC886F5383B21A
5660Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\..LICENSES.14.5660.temp.15.5660.temptext
MD5:835AE7FB6E7733264A44F792CA33FB2B
SHA256:7CB852F64FB8C7BDE31B53CF7BD5C68EC50EBA128054DD3646C8A2C73B331162
8008Battle.net-Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:EF14E5B0CBD036F4A57F2B3A19842493
SHA256:BCC6E52F00F6896CE5D29384A882A7F9863ABB8ED3D0B77B7C252FF2AFBBA75B
5660Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\Agent.9414\.Agent.exe.23.5660.tempbinary
MD5:B90517B04A2F38A648AC2F1DE63BCA67
SHA256:40FA21A46BC130329C8296263F95C86E41A4AB000174F8B5FBEC2ADDABE3DEC2
5660Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\Agent.9414\..Agent.exe.23.5660.temp.24.5660.tempexecutable
MD5:93EC35ADAC581B4A2A31214E91A64AEC
SHA256:994EEFA6F4AA1FF5DFB39DF180CD324A557E475660C710D345F6AFFCDCF1BDCC
5660Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\Agent.9414\..Agent.exe.23.5660.temp.24.5660.temp.tempexecutable
MD5:93EC35ADAC581B4A2A31214E91A64AEC
SHA256:994EEFA6F4AA1FF5DFB39DF180CD324A557E475660C710D345F6AFFCDCF1BDCC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
288
TCP/UDP connections
115
DNS requests
28
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
unknown
whitelisted
8008
Battle.net-Setup.exe
GET
204
52.209.93.215:80
http://nydus.battle.net/geoip
unknown
unknown
808
lsass.exe
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
8008
Battle.net-Setup.exe
POST
202
137.221.105.232:443
https://telemetry-in.battle.net/data
unknown
unknown
808
lsass.exe
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEAwanXGnnuIMUDb5ZrMniYw%3D
unknown
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
40.127.240.158:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
unknown
whitelisted
8008
Battle.net-Setup.exe
POST
202
137.221.105.232:443
https://telemetry-in.battle.net/data
unknown
unknown
5316
svchost.exe
POST
200
40.126.32.138:443
https://login.live.com/RST2.srf
unknown
xml
1.24 Kb
whitelisted
5316
svchost.exe
POST
400
40.126.32.138:443
https://login.live.com/ppsecure/deviceaddcredential.srf
unknown
203 b
whitelisted
5316
svchost.exe
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
7424
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
128.24.231.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
8008
Battle.net-Setup.exe
52.209.93.215:80
nydus.battle.net
AMAZON-02
US
suspicious
8008
Battle.net-Setup.exe
137.221.105.232:443
telemetry-in.battle.net
BLIZZARD
US
whitelisted
808
lsass.exe
23.11.41.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
3428
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
40.126.32.138:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
activation-v2.sls.microsoft.com
  • 128.24.231.64
whitelisted
google.com
  • 142.251.37.14
whitelisted
nydus.battle.net
  • 52.209.93.215
  • 54.75.26.207
unknown
telemetry-in.battle.net
  • 137.221.105.232
whitelisted
ocsp.digicert.com
  • 23.11.41.157
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.32.138
  • 40.126.32.72
  • 40.126.32.140
  • 20.190.160.5
  • 40.126.32.136
  • 40.126.32.133
  • 20.190.160.67
  • 20.190.160.132
whitelisted
crl.microsoft.com
  • 23.216.77.36
  • 23.216.77.22
  • 23.216.77.19
  • 23.216.77.6
  • 23.216.77.42
whitelisted
www.microsoft.com
  • 23.59.18.102
whitelisted

Threats

PID
Process
Class
Message
8008
Battle.net-Setup.exe
Potential Corporate Privacy Violation
ET INFO GeoIP Lookup (nydus.battle.net)
7424
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
5660
Battle.net-Setup.exe
Potential Corporate Privacy Violation
ET INFO GeoIP Lookup (nydus.battle.net)
No debug info