URL:

https://es.idcgames.com:443/launcher/IDCUpdater.exe

Full analysis: https://app.any.run/tasks/c7c351ed-5a77-47fb-a0a7-2e15f8737155
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: January 23, 2020, 12:13:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
Indicators:
MD5:

395183EF5F3900A06D613E2AA0491181

SHA1:

E040E1A8544F5791D6DC479370902376B9663253

SHA256:

41105119E7B38DE5077EE65DAFE26CD943BF82A2D06CDA6E92EA4A873493164E

SSDEEP:

3:N81+E0cw8nwjY:2Jck

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • IDCUpdater.exe (PID: 3020)
      • IDCUpdater.exe (PID: 3328)
      • launcherUpdate.exe (PID: 2496)
      • AppIDC.exe (PID: 3800)
      • CefSharp.BrowserSubprocess.exe (PID: 2556)
      • CefSharp.BrowserSubprocess.exe (PID: 1640)
      • CefSharp.BrowserSubprocess.exe (PID: 3412)
    • Loads dropped or rewritten executable

      • launcherUpdate.exe (PID: 2496)
      • AppIDC.exe (PID: 3800)
      • CefSharp.BrowserSubprocess.exe (PID: 2556)
      • CefSharp.BrowserSubprocess.exe (PID: 3412)
      • CefSharp.BrowserSubprocess.exe (PID: 1640)
    • Connects to CnC server

      • launcherUpdate.exe (PID: 2496)
    • Changes the autorun value in the registry

      • AppIDC.exe (PID: 3800)
    • Changes settings of System certificates

      • AppIDC.exe (PID: 3800)
      • IDCUpdater.tmp (PID: 3344)
    • Downloads executable files from the Internet

      • launcherUpdate.exe (PID: 2496)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2400)
      • iexplore.exe (PID: 2872)
      • IDCUpdater.exe (PID: 3020)
      • IDCUpdater.tmp (PID: 3344)
      • IDCUpdater.exe (PID: 3328)
      • launcherUpdate.exe (PID: 2496)
    • Reads Environment values

      • launcherUpdate.exe (PID: 2496)
      • AppIDC.exe (PID: 3800)
    • Modifies the open verb of a shell class

      • AppIDC.exe (PID: 3800)
    • Reads the Windows organization settings

      • IDCUpdater.tmp (PID: 3344)
    • Adds / modifies Windows certificates

      • AppIDC.exe (PID: 3800)
      • IDCUpdater.tmp (PID: 3344)
    • Creates files in the program directory

      • launcherUpdate.exe (PID: 2496)
      • AppIDC.exe (PID: 3800)
    • Reads Windows owner or organization settings

      • IDCUpdater.tmp (PID: 3344)
    • Searches for installed software

      • AppIDC.exe (PID: 3800)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2872)
      • iexplore.exe (PID: 2400)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2872)
    • Changes internet zones settings

      • iexplore.exe (PID: 2872)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2872)
      • IDCUpdater.tmp (PID: 3344)
      • AppIDC.exe (PID: 3800)
    • Creates files in the user directory

      • iexplore.exe (PID: 2872)
    • Creates files in the program directory

      • IDCUpdater.tmp (PID: 3344)
    • Creates a software uninstall entry

      • IDCUpdater.tmp (PID: 3344)
    • Dropped object may contain Bitcoin addresses

      • launcherUpdate.exe (PID: 2496)
    • Application was dropped or rewritten from another process

      • IDCUpdater.tmp (PID: 2628)
      • IDCUpdater.tmp (PID: 3344)
    • Reads the hosts file

      • AppIDC.exe (PID: 3800)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2872)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2872)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
11
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe idcupdater.exe idcupdater.tmp no specs idcupdater.exe idcupdater.tmp launcherupdate.exe appidc.exe cefsharp.browsersubprocess.exe no specs cefsharp.browsersubprocess.exe no specs cefsharp.browsersubprocess.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1640"C:\Program Files\IDCLauncher\CefSharp.BrowserSubprocess.exe" --type=renderer --no-sandbox --log-file="C:\Program Files\IDCLauncher\debug.log" --field-trial-handle=2588,2842114591036617539,2963566700334367219,131072 --disable-gpu-compositing --service-pipe-token=13471856472057684321 --lang=en-US --log-file="C:\Program Files\IDCLauncher\debug.log" --log-severity=disable --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36 idclauncher" --enable-system-flash=1 --cefsharpexitsub --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=13471856472057684321 --renderer-client-id=3 --mojo-platform-channel-handle=3144 /prefetch:1 --host-process-id=3800C:\Program Files\IDCLauncher\CefSharp.BrowserSubprocess.exeAppIDC.exe
User:
admin
Company:
The CefSharp Authors
Integrity Level:
HIGH
Description:
CefSharp.BrowserSubprocess
Exit code:
0
Version:
73.1.130.0
Modules
Images
c:\program files\idclauncher\cefsharp.browsersubprocess.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2400"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2872 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2496"C:\Program Files\IDCLauncher\launcherUpdate.exe"C:\Program Files\IDCLauncher\launcherUpdate.exe
IDCUpdater.tmp
User:
admin
Company:
IDCGames
Integrity Level:
HIGH
Description:
Launcher Updater
Exit code:
0
Version:
1.48.0.0
Modules
Images
c:\program files\idclauncher\launcherupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2556"C:\Program Files\IDCLauncher\CefSharp.BrowserSubprocess.exe" --type=gpu-process --field-trial-handle=2588,2842114591036617539,2963566700334367219,131072 --no-sandbox --log-file="C:\Program Files\IDCLauncher\debug.log" --log-severity=disable --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36 idclauncher" --lang=en-US --cefsharpexitsub --gpu-preferences=KAAAAAAAAACAAwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Program Files\IDCLauncher\debug.log" --service-request-channel-token=157179220301579602 --mojo-platform-channel-handle=2680 /prefetch:2 --host-process-id=3800C:\Program Files\IDCLauncher\CefSharp.BrowserSubprocess.exeAppIDC.exe
User:
admin
Company:
The CefSharp Authors
Integrity Level:
HIGH
Description:
CefSharp.BrowserSubprocess
Exit code:
0
Version:
73.1.130.0
Modules
Images
c:\program files\idclauncher\cefsharp.browsersubprocess.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2628"C:\Users\admin\AppData\Local\Temp\is-H928J.tmp\IDCUpdater.tmp" /SL5="$8020E,1338488,794624,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\IDCUpdater.exe" C:\Users\admin\AppData\Local\Temp\is-H928J.tmp\IDCUpdater.tmpIDCUpdater.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-h928j.tmp\idcupdater.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2872"C:\Program Files\Internet Explorer\iexplore.exe" https://es.idcgames.com:443/launcher/IDCUpdater.exeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3020"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\IDCUpdater.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\IDCUpdater.exe
iexplore.exe
User:
admin
Company:
IDCGames
Integrity Level:
MEDIUM
Description:
IDC Updater Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\idcupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3328"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\IDCUpdater.exe" /SPAWNWND=$C012C /NOTIFYWND=$8020E C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\IDCUpdater.exe
IDCUpdater.tmp
User:
admin
Company:
IDCGames
Integrity Level:
HIGH
Description:
IDC Updater Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\idcupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3344"C:\Users\admin\AppData\Local\Temp\is-P6O4T.tmp\IDCUpdater.tmp" /SL5="$6021A,1338488,794624,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\IDCUpdater.exe" /SPAWNWND=$C012C /NOTIFYWND=$8020E C:\Users\admin\AppData\Local\Temp\is-P6O4T.tmp\IDCUpdater.tmp
IDCUpdater.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-p6o4t.tmp\idcupdater.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3412"C:\Program Files\IDCLauncher\CefSharp.BrowserSubprocess.exe" --type=gpu-process --field-trial-handle=2588,2842114591036617539,2963566700334367219,131072 --disable-gpu-sandbox --use-gl=disabled --no-sandbox --log-file="C:\Program Files\IDCLauncher\debug.log" --log-severity=disable --user-agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36 idclauncher" --lang=en-US --cefsharpexitsub --gpu-preferences=KAAAAAAAAACAAwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Program Files\IDCLauncher\debug.log" --service-request-channel-token=10922603187045586096 --mojo-platform-channel-handle=3836 /prefetch:2 --host-process-id=3800C:\Program Files\IDCLauncher\CefSharp.BrowserSubprocess.exeAppIDC.exe
User:
admin
Company:
The CefSharp Authors
Integrity Level:
HIGH
Description:
CefSharp.BrowserSubprocess
Exit code:
0
Version:
73.1.130.0
Modules
Images
c:\program files\idclauncher\cefsharp.browsersubprocess.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
Total events
7 436
Read events
2 543
Write events
3 699
Delete events
1 194

Modification events

(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
2744272822
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30790118
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
211
Suspicious files
57
Text files
49
Unknown types
93

Dropped files

PID
Process
Filename
Type
2400iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab6181.tmp
MD5:
SHA256:
2400iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar6182.tmp
MD5:
SHA256:
2400iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\IDCUpdater.exe.qcw5v5x.partial
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF5112AD2DF4A31301.TMP
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\IDCUpdater.exe.qcw5v5x.partial:Zone.Identifier
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Local\Temp\Cab4A5A.tmp
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Local\Temp\Tar4A5B.tmp
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\3PLWVN89.txt
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\R04YRGR8.txt
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_D9817BD5013875AD517DA73475345203binary
MD5:F2FA156187BA4DEABABFEE2494DBF7A2
SHA256:1CF95FF7CC62E32AC4EFEA952842ABD1CF10D7346624ECE4D23D8D060D6E020B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
230
TCP/UDP connections
51
DNS requests
25
Threats
41

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2496
launcherUpdate.exe
GET
200
31.24.231.76:80
http://download.idcgames.com/games/idc-games/bW1mZEx4K2dKZGxQUmRGbg==/common/icudtl.dat
GB
binary
9.85 Mb
malicious
2496
launcherUpdate.exe
GET
200
31.24.231.76:80
http://download.idcgames.com/games/idc-games/bW1mZEx4K2dKZGxQUmRGbg==/common/System.Design.dll
GB
executable
2.40 Mb
malicious
2496
launcherUpdate.exe
GET
200
31.24.231.76:80
http://download.idcgames.com/games/idc-games/bW1mZEx4K2dKZGxQUmRGbg==/common/SharpDX.Direct2D1.xml
GB
xml
3.29 Mb
malicious
2496
launcherUpdate.exe
GET
200
31.24.231.76:80
http://download.idcgames.com/games/idc-games/bW1mZEx4K2dKZGxQUmRGbg==/common/SharpDX.MediaFoundation.xml
GB
xml
3.88 Mb
malicious
2496
launcherUpdate.exe
GET
31.24.231.76:80
http://download.idcgames.com/games/idc-games/bW1mZEx4K2dKZGxQUmRGbg==/common/SharpDX.Direct3D9.xml
GB
malicious
2872
iexplore.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/Omniroot2025.crl
US
der
5.13 Kb
whitelisted
2496
launcherUpdate.exe
GET
200
31.24.231.76:80
http://download.idcgames.com/games/idc-games/bW1mZEx4K2dKZGxQUmRGbg==/common/devtools_resources.pak
GB
pgc
5.69 Mb
malicious
2496
launcherUpdate.exe
GET
200
31.24.231.76:80
http://download.idcgames.com/games/global_releases/version/0.json
GB
text
105 Kb
malicious
2872
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
2496
launcherUpdate.exe
GET
31.24.231.76:80
http://download.idcgames.com/games/idc-games/bW1mZEx4K2dKZGxQUmRGbg==/common/System.Reactive.dll
GB
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2400
iexplore.exe
51.91.48.135:443
es.idcgames.com
GB
unknown
2400
iexplore.exe
151.139.128.14:80
ocsp.usertrust.com
Highwinds Network Group, Inc.
US
suspicious
2872
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2872
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2872
iexplore.exe
204.79.197.200:443
ieonline.microsoft.com
Microsoft Corporation
US
whitelisted
3344
IDCUpdater.tmp
51.91.48.135:443
es.idcgames.com
GB
unknown
2496
launcherUpdate.exe
51.91.48.135:443
es.idcgames.com
GB
unknown
2496
launcherUpdate.exe
31.24.231.76:80
download.idcgames.com
UK-2 Limited
GB
malicious
1052
svchost.exe
2.16.186.120:80
crl.microsoft.com
Akamai International B.V.
whitelisted
3800
AppIDC.exe
31.24.231.76:80
download.idcgames.com
UK-2 Limited
GB
malicious

DNS requests

Domain
IP
Reputation
es.idcgames.com
  • 51.91.48.135
unknown
ocsp.usertrust.com
  • 151.139.128.14
whitelisted
ocsp.sectigo.com
  • 216.58.207.36
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
en.idcgames.com
  • 51.91.48.135
unknown
ieonline.microsoft.com
  • 204.79.197.200
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted
download.idcgames.com
  • 31.24.231.76
  • 88.202.231.134
malicious

Threats

PID
Process
Class
Message
2496
launcherUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2496
launcherUpdate.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2496
launcherUpdate.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2496
launcherUpdate.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2496
launcherUpdate.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2496
launcherUpdate.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2496
launcherUpdate.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2496
launcherUpdate.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2496
launcherUpdate.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2496
launcherUpdate.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
5 ETPRO signatures available at the full report
Process
Message
AppIDC.exe
IDC=> IDCHlp_init