File name:

Reborn.exe

Full analysis: https://app.any.run/tasks/02657fd3-8610-4f8e-ac79-a9374682e84a
Verdict: Malicious activity
Analysis date: April 29, 2024, 21:01:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

03CDD33C3892DE6B3A88FE5DEFE7C6A9

SHA1:

66BEE183E8EC70DDBA2E4EE020F2B9EFE42BE433

SHA256:

779EC6A7CF333E79A7FF70C506FB6FE435A26F682933404BAEA1EB56A86AFB9F

SSDEEP:

12288:zlkrPrxk/CptqLxaqAIEAkSe9coTSZ83m4s7wVYnACjZ3WhL1zsaOiiHs5a1dcj1:z+rPrbVnxSZ83rYjZ3WhJzsnm6Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Reborn.exe (PID: 4080)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Reborn.exe (PID: 4080)
    • Checks Windows Trust Settings

      • Reborn.exe (PID: 4080)
    • Reads security settings of Internet Explorer

      • Reborn.exe (PID: 4080)
    • Adds/modifies Windows certificates

      • Reborn.exe (PID: 4080)
    • Reads settings of System Certificates

      • Reborn.exe (PID: 4080)
    • Process requests binary or script from the Internet

      • Reborn.exe (PID: 4080)
    • Potential Corporate Privacy Violation

      • Reborn.exe (PID: 4080)
    • Executable content was dropped or overwritten

      • Reborn.exe (PID: 4080)
  • INFO

    • Checks supported languages

      • Reborn.exe (PID: 4080)
      • wmpnscfg.exe (PID: 1628)
    • Checks proxy server information

      • Reborn.exe (PID: 4080)
    • Reads the computer name

      • Reborn.exe (PID: 4080)
      • wmpnscfg.exe (PID: 1628)
    • Reads the software policy settings

      • Reborn.exe (PID: 4080)
    • Creates files or folders in the user directory

      • Reborn.exe (PID: 4080)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1628)
      • msedge.exe (PID: 2588)
    • Reads the machine GUID from the registry

      • Reborn.exe (PID: 4080)
    • Application launched itself

      • msedge.exe (PID: 2092)
      • msedge.exe (PID: 2260)
      • msedge.exe (PID: 2588)
    • Create files in a temporary directory

      • Reborn.exe (PID: 4080)
    • Drops the executable file immediately after the start

      • msedge.exe (PID: 2588)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 2588)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:08:06 07:25:55+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 240128
InitializedDataSize: 322048
UninitializedDataSize: -
EntryPoint: 0xeafb
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.1012.0
ProductVersionNumber: 1.0.1012.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Russian
CharacterSet: Unicode
CompanyName: Global Gamers Solutions Ltd. (c)
FileDescription: Reborn game installer
FileVersion: 1,0,1012,dc6ff9ab77ea66f0b2877baa66b00c9066705f5d
InternalName: Reborn
LegalCopyright: Copyright(c) 2010 - 2015
OriginalFileName: RebornInstaller.exe
ProductName: Reborn game installer
ProductVersion: 1,0,1012,dc6ff9ab77ea66f0b2877baa66b00c9066705f5d
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
32
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start reborn.exe wmpnscfg.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs reborn.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
312"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4360 --field-trial-handle=1212,i,18349816514438601609,10551275117182292353,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
368"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_collections.mojom.CollectionsDataManager --lang=en-US --service-sandbox-type=collections --mojo-platform-channel-handle=3784 --field-trial-handle=1212,i,18349816514438601609,10551275117182292353,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
552"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4256 --field-trial-handle=1212,i,18349816514438601609,10551275117182292353,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
676"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1404 --field-trial-handle=1376,i,13071672530644222416,15608145435674238381,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
988"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=23 --mojo-platform-channel-handle=4056 --field-trial-handle=1212,i,18349816514438601609,10551275117182292353,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1028"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=872 --field-trial-handle=1212,i,18349816514438601609,10551275117182292353,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1408"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1388 --field-trial-handle=1312,i,2924338121268729754,12082553591212106064,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1412"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3376 --field-trial-handle=1212,i,18349816514438601609,10551275117182292353,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1628"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1868"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1260 --field-trial-handle=1312,i,2924338121268729754,12082553591212106064,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
16 299
Read events
16 180
Write events
100
Delete events
19

Modification events

(PID) Process:(4080) Reborn.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\GGS\QGNA
Operation:writeName:InstKey
Value:
2753
(PID) Process:(4080) Reborn.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\GGS\QGNA
Operation:writeName:MID
Value:
149797806
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
2
Suspicious files
55
Text files
30
Unknown types
20

Dropped files

PID
Process
Filename
Type
4080Reborn.exeC:\Users\admin\AppData\Local\Temp\ggs541D.exe
MD5:
SHA256:
2252msedge.exe
MD5:
SHA256:
4080Reborn.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\16AAAA27B835E6A92EA76A67101BC2F1binary
MD5:618D65A4BD5EF5E1D1C771EBBCCE96C2
SHA256:04BBA08F477619F5041672CD371AF9F435C3EB6F7E72140B9F9F62DA7BF4EF20
4080Reborn.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EB2C4AB8B68FFA4B7733A9139239A396_D76DB901EE986B889F30D8CC06229E2Dbinary
MD5:121398305703909718FA417B116ACFAB
SHA256:0F6F9D7EC8C467CFA9C3041D8F10446C9D857712A40FA6137F8D2DBD888DD8FC
2092msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\34a43e8d-0075-4a96-b814-42aef4c4993b.tmp
MD5:
SHA256:
2092msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RF137e3c.TMP
MD5:
SHA256:
4080Reborn.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771binary
MD5:73F926A60B902DB70DCE4B7C174F8460
SHA256:67D9D660FB39BD2E51168135E409E4FFA058EB21BFE1A795DD924B2D8079EE38
4080Reborn.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EB2C4AB8B68FFA4B7733A9139239A396_D76DB901EE986B889F30D8CC06229E2Dbinary
MD5:7165F8201BD09ED502D58B173E14121F
SHA256:6A14907A2D2B75A57B7E09417B68F3DFBB047408F1BAEA1A2B2620FBF176BACE
2092msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RF137e5b.TMP
MD5:
SHA256:
4080Reborn.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4705DB930D032C3386A867A140EC3CE4_4DBD93DBC151E9B3007B54E528670011der
MD5:5ED3EFA9EBBD547A759391370AAF867B
SHA256:ABD8FCD64D4E4B974C3ABF493DAA90BCE2E5A1976A964C3947649C1A9FADF980
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
28
DNS requests
27
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4080
Reborn.exe
GET
200
184.24.206.119:80
http://x1.c.lencr.org/
unknown
unknown
4080
Reborn.exe
GET
200
192.124.249.41:80
http://ocsp.godaddy.com//MEowSDBGMEQwQjAJBgUrDgMCGgUABBS2CA1fbGt26xPkOKX4ZguoUjM0TgQUQMK9J47MNIMwojPX%2B2yz8LQsgM4CCQCJS5RMZDQjhw%3D%3D
unknown
unknown
4080
Reborn.exe
GET
31.25.231.10:80
http://fs0.gamenet.ru/installers/qgna/reborn/live/reborn_inner.exe
unknown
unknown
4080
Reborn.exe
GET
31.25.231.10:80
http://fs0.gamenet.ru/installers/qgna/reborn/live/reborn_inner.exe
unknown
unknown
4080
Reborn.exe
GET
31.25.231.10:80
http://fs0.gamenet.ru/installers/qgna/reborn/live/reborn_inner.exe
unknown
unknown
2644
msedge.exe
GET
302
31.25.227.141:80
http://go.gamenet.ru/file?id=21&mid=185388917&
unknown
unknown
2644
msedge.exe
GET
302
31.25.227.141:80
http://go.gamenet.ru/file?id=21&mid=185388917&k=EYkCkbx5bOK0xss1ude1duJH3PNTCIhkrYRW2soSFUkKsQoV4qcaBRiiAUIYvgrRIwg2qC3FO5YAjgLAVeoypxEn1J3ZxvkIMrVbwjzU8aGpKDKQ2emzMw0HL3tQcWg0x0KNdcdUEDyjkKepWemcJTxtxCaFhT4Iv%2BIV%2FC2UtQiVg
unknown
unknown
2644
msedge.exe
GET
301
31.25.227.141:80
http://go.gamenet.ru/a/19/213/inst
unknown
unknown
4080
Reborn.exe
GET
200
184.25.51.82:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgOMd2BRN6m5IicTZVqWnEdgYQ%3D%3D
unknown
unknown
4080
Reborn.exe
GET
200
192.124.249.41:80
http://ocsp.godaddy.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBTkIInKBAzXkF0Qh0pel3lfHJ9GPAQU0sSw0pHUTBFxs2HLPaH%2B3ahq1OMCAxvnFQ%3D%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
4080
Reborn.exe
31.25.227.143:443
gnlogin.ru
Big Mmo Game Network Limited
RU
unknown
4080
Reborn.exe
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
4080
Reborn.exe
184.24.206.119:80
x1.c.lencr.org
Akamai International B.V.
US
unknown
4080
Reborn.exe
184.25.51.82:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
4080
Reborn.exe
31.25.227.152:443
gnapi.com
Big Mmo Game Network Limited
RU
unknown
4080
Reborn.exe
192.124.249.41:80
ocsp.godaddy.com
SUCURI-SEC
US
unknown
4080
Reborn.exe
31.25.231.10:80
fs0.gamenet.ru
Big Mmo Game Network Limited
RU
unknown

DNS requests

Domain
IP
Reputation
gnlogin.ru
  • 31.25.227.143
unknown
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
x1.c.lencr.org
  • 184.24.206.119
whitelisted
r3.o.lencr.org
  • 184.25.51.82
  • 184.25.51.75
shared
gnapi.com
  • 31.25.227.152
  • 31.25.227.151
unknown
ocsp.godaddy.com
  • 192.124.249.41
  • 192.124.249.36
  • 192.124.249.24
  • 192.124.249.23
  • 192.124.249.22
whitelisted
fs0.gamenet.ru
  • 31.25.231.10
  • 31.25.231.14
  • 31.25.231.3
unknown
config.edge.skype.com
  • 13.107.42.16
whitelisted
go.gamenet.ru
  • 31.25.227.141
  • 31.25.227.142
unknown
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted

Threats

PID
Process
Class
Message
4080
Reborn.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
4080
Reborn.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info