URL:

https://se7en.ws/gta-v/?lang=en

Full analysis: https://app.any.run/tasks/b171d959-32bc-4683-a526-f55d569caccb
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: May 03, 2021, 20:11:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

4180C3CE907EB143AA34E1CCA6114B55

SHA1:

A2352FD3A304F47B27299A0B7AF7AA343E33496A

SHA256:

5921FB842658835CB6446EA79297F2958FF733BE64ADC0997E41510A44711176

SSDEEP:

3:N8Nm6GaQbun:2gHapn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • 7l_gtav_setup.exe (PID: 2188)
      • 7l_gtav_setup.exe (PID: 4088)
    • Application was dropped or rewritten from another process

      • 7l_gtav_setup.exe (PID: 2188)
      • 7l_gtav_setup.exe (PID: 4088)
      • Run_GTAV.exe (PID: 3620)
      • aria2c.exe (PID: 2308)
    • Adds new firewall rule via NETSH.EXE

      • 7l_gtav_setup.tmp (PID: 4084)
    • Changes settings of System certificates

      • Run_GTAV.exe (PID: 3620)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 3504)
      • 7l_gtav_setup.exe (PID: 2188)
      • 7l_gtav_setup.exe (PID: 4088)
      • 7l_gtav_setup.tmp (PID: 4084)
      • Run_GTAV.exe (PID: 3620)
    • Reads Windows owner or organization settings

      • 7l_gtav_setup.tmp (PID: 4084)
    • Drops a file with too old compile date

      • 7l_gtav_setup.tmp (PID: 4084)
      • Run_GTAV.exe (PID: 3620)
      • aria2c.exe (PID: 2308)
    • Creates a directory in Program Files

      • 7l_gtav_setup.tmp (PID: 4084)
      • Run_GTAV.exe (PID: 3620)
      • aria2c.exe (PID: 2308)
    • Uses TASKKILL.EXE to kill process

      • 7l_gtav_setup.tmp (PID: 4084)
    • Reads internet explorer settings

      • Run_GTAV.exe (PID: 3620)
    • Reads the Windows organization settings

      • 7l_gtav_setup.tmp (PID: 4084)
    • Changes IE settings (feature browser emulation)

      • Run_GTAV.exe (PID: 3620)
    • Creates files in the user directory

      • Run_GTAV.exe (PID: 3620)
    • Drops a file with a compile date too recent

      • 7l_gtav_setup.tmp (PID: 4084)
    • Uses NETSH.EXE for network configuration

      • 7l_gtav_setup.tmp (PID: 4084)
    • Changes default file association

      • Run_GTAV.exe (PID: 3620)
    • Creates files in the program directory

      • Run_GTAV.exe (PID: 3620)
      • aria2c.exe (PID: 2308)
    • Adds / modifies Windows certificates

      • Run_GTAV.exe (PID: 3620)
    • Drops a file that was compiled in debug mode

      • aria2c.exe (PID: 2308)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 3504)
    • Reads the hosts file

      • chrome.exe (PID: 1068)
      • chrome.exe (PID: 3504)
      • aria2c.exe (PID: 2308)
    • Reads settings of System Certificates

      • chrome.exe (PID: 3504)
    • Application was dropped or rewritten from another process

      • 7l_gtav_setup.tmp (PID: 3640)
      • 7l_gtav_setup.tmp (PID: 4084)
    • Loads dropped or rewritten executable

      • 7l_gtav_setup.tmp (PID: 4084)
    • Creates a software uninstall entry

      • 7l_gtav_setup.tmp (PID: 4084)
    • Creates files in the program directory

      • 7l_gtav_setup.tmp (PID: 4084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
68
Monitored processes
22
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs 7l_gtav_setup.exe 7l_gtav_setup.tmp no specs 7l_gtav_setup.exe 7l_gtav_setup.tmp taskkill.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs run_gtav.exe chrome.exe no specs aria2c.exe

Process information

PID
CMD
Path
Indicators
Parent process
1068"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1024,16551027446030760601,7640000898160447532,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=15217687943777795368 --mojo-platform-channel-handle=1448 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1540"C:\Windows\system32\netsh.exe" advfirewall firewall add rule name="P2P Out" program="C:\Program Files\GTA V\7launcher\tools\aria2\aria2c.exe" dir=out action=allow enable=yesC:\Windows\system32\netsh.exe7l_gtav_setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1792"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6df7a9d0,0x6df7a9e0,0x6df7a9ecC:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1968"C:\Windows\system32\netsh.exe" advfirewall firewall add rule name="7Launcher GTA 5 Out" program="C:\Program Files\GTA V\Run_GTAV.exe" dir=out action=allow enable=yesC:\Windows\system32\netsh.exe7l_gtav_setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2180"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1024,16551027446030760601,7640000898160447532,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=5247800651317239093 --mojo-platform-channel-handle=3704 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2188"C:\Users\admin\Downloads\7l_gtav_setup.exe" /SPAWNWND=$20176 /NOTIFYWND=$20160 C:\Users\admin\Downloads\7l_gtav_setup.exe
7l_gtav_setup.tmp
User:
admin
Company:
SE7EN Solutions
Integrity Level:
HIGH
Description:
7Launcher GTA 5 Setup
Exit code:
0
Version:
1.4.3
Modules
Images
c:\users\admin\downloads\7l_gtav_setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2224"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1024,16551027446030760601,7640000898160447532,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=15963441379385866900 --mojo-platform-channel-handle=1044 --ignored=" --type=renderer " /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2308"C:\Program Files\GTA V\7launcher\tools\aria2\aria2c.exe" "https://se7en.ws/torrents/gtav_latest.torrent" --follow-torrent=mem --file-allocation=none --seed-time=0 --bt-enable-lpd=true --summary-interval=0 --truncate-console-readout=false --enable-color=false --human-readable=false --check-integrity=true --bt-max-peers=70 --bt-request-peer-speed-limit=100K --bt-max-open-files=300 --disk-cache=32M --dir="C:\Program Files\GTA V\!Setup"C:\Program Files\GTA V\7launcher\tools\aria2\aria2c.exe
Run_GTAV.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\gta v\7launcher\tools\aria2\aria2c.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
2424"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1024,16551027446030760601,7640000898160447532,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=17222223573597394477 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2168 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2616"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1024,16551027446030760601,7640000898160447532,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=12993072484507745840 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2384 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
1 825
Read events
1 501
Write events
315
Delete events
9

Modification events

(PID) Process:(2976) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:3504-13264546274467500
Value:
259
(PID) Process:(3504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(3504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(3504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(3504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(3504) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3252-13245750958665039
Value:
0
(PID) Process:(3504) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
Executable files
9
Suspicious files
43
Text files
112
Unknown types
17

Dropped files

PID
Process
Filename
Type
3504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-609058E3-DB0.pma
MD5:
SHA256:
3504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\96f30c91-f667-4b9d-8a5f-00340f50d450.tmp
MD5:
SHA256:
3504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp
MD5:
SHA256:
3504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF483b3.TMPtext
MD5:
SHA256:
3504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old
MD5:
SHA256:
3504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.oldtext
MD5:
SHA256:
3504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.oldtext
MD5:
SHA256:
3504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.oldtext
MD5:
SHA256:
3504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
MD5:
SHA256:
3504chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF48597.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
24
TCP/UDP connections
139
DNS requests
33
Threats
27

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2308
aria2c.exe
GET
172.67.173.173:80
http://gtav.se7en.icu/c/GTA%20V%20RePack%20by%20SE7EN/data_up_02.bin
US
suspicious
2308
aria2c.exe
GET
172.67.173.173:80
http://gtav.se7en.icu/c/GTA%20V%20RePack%20by%20SE7EN/data_01.bin
US
suspicious
3620
Run_GTAV.exe
GET
104.21.2.209:80
http://updater.se7enkills.net/images/telega-banner.png
US
whitelisted
2308
aria2c.exe
GET
172.67.173.173:80
http://gtav.se7en.icu/c/GTA%20V%20RePack%20by%20SE7EN/data_up_04.bin
US
suspicious
2308
aria2c.exe
GET
172.67.190.56:80
http://gtav.7n.re/c/GTA%20V%20RePack%20by%20SE7EN/data_02.bin
US
suspicious
2308
aria2c.exe
GET
172.67.173.173:80
http://gtav.se7en.icu/c/GTA%20V%20RePack%20by%20SE7EN/data_02.bin
US
suspicious
2308
aria2c.exe
GET
172.67.190.56:80
http://gtav.7n.re/c/GTA%20V%20RePack%20by%20SE7EN/data_up_02.bin
US
suspicious
2308
aria2c.exe
GET
172.67.190.56:80
http://gtav.7n.re/c/GTA%20V%20RePack%20by%20SE7EN/data_03.bin
US
suspicious
3620
Run_GTAV.exe
GET
200
104.21.2.209:80
http://updater.se7enkills.net/gtav/inf.ini
US
text
2.06 Kb
whitelisted
3620
Run_GTAV.exe
GET
200
104.21.2.209:80
http://updater.se7enkills.net/gtav/en/
US
html
1.48 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1068
chrome.exe
172.67.74.169:443
se7en.ws
US
suspicious
1068
chrome.exe
142.250.186.45:443
accounts.google.com
Google Inc.
US
suspicious
1068
chrome.exe
142.250.184.232:443
www.googletagmanager.com
Google Inc.
US
suspicious
1068
chrome.exe
95.213.129.125:443
cackle.me
OOO Network of data-centers Selectel
RU
unknown
1068
chrome.exe
142.250.74.195:443
fonts.gstatic.com
Google Inc.
US
whitelisted
1068
chrome.exe
94.130.71.126:443
j.cackle.me
Hetzner Online GmbH
DE
unknown
1068
chrome.exe
74.125.71.155:443
stats.g.doubleclick.net
Google Inc.
US
whitelisted
1068
chrome.exe
142.250.185.132:443
www.google.com
Google Inc.
US
whitelisted
1068
chrome.exe
192.0.80.241:443
gravatar.com
Automattic, Inc
US
unknown
1068
chrome.exe
87.250.251.119:443
mc.yandex.ru
YANDEX LLC
RU
whitelisted

DNS requests

Domain
IP
Reputation
se7en.ws
  • 104.26.2.87
  • 104.26.3.87
  • 172.67.74.169
whitelisted
accounts.google.com
  • 142.250.186.45
shared
www.google.com
  • 142.250.185.132
malicious
www.googletagmanager.com
  • 142.250.184.232
whitelisted
fonts.gstatic.com
  • 142.250.74.195
whitelisted
cackle.me
  • 95.213.129.125
unknown
mc.yandex.ru
  • 87.250.251.119
  • 77.88.21.119
  • 87.250.250.119
  • 93.158.134.119
whitelisted
clients1.google.com
  • 216.58.212.174
whitelisted
www.google-analytics.com
  • 142.250.185.110
whitelisted
j.cackle.me
  • 94.130.71.126
unknown

Threats

PID
Process
Class
Message
3620
Run_GTAV.exe
Potential Corporate Privacy Violation
ET POLICY User-Agent (Launcher)
3620
Run_GTAV.exe
Potential Corporate Privacy Violation
AV POLICY User-Agent (Launcher)
3620
Run_GTAV.exe
Potential Corporate Privacy Violation
ET POLICY User-Agent (Launcher)
3620
Run_GTAV.exe
Potential Corporate Privacy Violation
AV POLICY User-Agent (Launcher)
3620
Run_GTAV.exe
Potential Corporate Privacy Violation
ET POLICY User-Agent (Launcher)
3620
Run_GTAV.exe
Potential Corporate Privacy Violation
AV POLICY User-Agent (Launcher)
2308
aria2c.exe
Potentially Bad Traffic
ET INFO DNS Query for Suspicious .icu Domain
2308
aria2c.exe
A Network Trojan was detected
ET USER_AGENTS Aria2 User-Agent
2308
aria2c.exe
A Network Trojan was detected
ET USER_AGENTS Aria2 User-Agent
2308
aria2c.exe
A Network Trojan was detected
ET USER_AGENTS Aria2 User-Agent
No debug info