File name:

Reborn.exe

Full analysis: https://app.any.run/tasks/02657fd3-8610-4f8e-ac79-a9374682e84a
Verdict: Malicious activity
Analysis date: April 29, 2024, 21:01:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

03CDD33C3892DE6B3A88FE5DEFE7C6A9

SHA1:

66BEE183E8EC70DDBA2E4EE020F2B9EFE42BE433

SHA256:

779EC6A7CF333E79A7FF70C506FB6FE435A26F682933404BAEA1EB56A86AFB9F

SSDEEP:

12288:zlkrPrxk/CptqLxaqAIEAkSe9coTSZ83m4s7wVYnACjZ3WhL1zsaOiiHs5a1dcj1:z+rPrbVnxSZ83rYjZ3WhJzsnm6Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Reborn.exe (PID: 4080)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • Reborn.exe (PID: 4080)
    • Reads the Internet Settings

      • Reborn.exe (PID: 4080)
    • Checks Windows Trust Settings

      • Reborn.exe (PID: 4080)
    • Adds/modifies Windows certificates

      • Reborn.exe (PID: 4080)
    • Reads security settings of Internet Explorer

      • Reborn.exe (PID: 4080)
    • Executable content was dropped or overwritten

      • Reborn.exe (PID: 4080)
    • Potential Corporate Privacy Violation

      • Reborn.exe (PID: 4080)
    • Process requests binary or script from the Internet

      • Reborn.exe (PID: 4080)
  • INFO

    • Checks proxy server information

      • Reborn.exe (PID: 4080)
    • Reads the machine GUID from the registry

      • Reborn.exe (PID: 4080)
    • Creates files or folders in the user directory

      • Reborn.exe (PID: 4080)
    • Reads the computer name

      • wmpnscfg.exe (PID: 1628)
      • Reborn.exe (PID: 4080)
    • Checks supported languages

      • wmpnscfg.exe (PID: 1628)
      • Reborn.exe (PID: 4080)
    • Reads the software policy settings

      • Reborn.exe (PID: 4080)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1628)
      • msedge.exe (PID: 2588)
    • Create files in a temporary directory

      • Reborn.exe (PID: 4080)
    • Application launched itself

      • msedge.exe (PID: 2092)
      • msedge.exe (PID: 2260)
      • msedge.exe (PID: 2588)
    • Drops the executable file immediately after the start

      • msedge.exe (PID: 2588)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 2588)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:08:06 07:25:55+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 240128
InitializedDataSize: 322048
UninitializedDataSize: -
EntryPoint: 0xeafb
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.1012.0
ProductVersionNumber: 1.0.1012.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Russian
CharacterSet: Unicode
CompanyName: Global Gamers Solutions Ltd. (c)
FileDescription: Reborn game installer
FileVersion: 1,0,1012,dc6ff9ab77ea66f0b2877baa66b00c9066705f5d
InternalName: Reborn
LegalCopyright: Copyright(c) 2010 - 2015
OriginalFileName: RebornInstaller.exe
ProductName: Reborn game installer
ProductVersion: 1,0,1012,dc6ff9ab77ea66f0b2877baa66b00c9066705f5d
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
32
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start reborn.exe wmpnscfg.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs reborn.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
312"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4360 --field-trial-handle=1212,i,18349816514438601609,10551275117182292353,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
368"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_collections.mojom.CollectionsDataManager --lang=en-US --service-sandbox-type=collections --mojo-platform-channel-handle=3784 --field-trial-handle=1212,i,18349816514438601609,10551275117182292353,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
552"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4256 --field-trial-handle=1212,i,18349816514438601609,10551275117182292353,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
676"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1404 --field-trial-handle=1376,i,13071672530644222416,15608145435674238381,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
988"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=23 --mojo-platform-channel-handle=4056 --field-trial-handle=1212,i,18349816514438601609,10551275117182292353,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1028"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=872 --field-trial-handle=1212,i,18349816514438601609,10551275117182292353,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1408"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1388 --field-trial-handle=1312,i,2924338121268729754,12082553591212106064,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1412"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3376 --field-trial-handle=1212,i,18349816514438601609,10551275117182292353,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1628"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1868"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1260 --field-trial-handle=1312,i,2924338121268729754,12082553591212106064,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
16 299
Read events
16 180
Write events
100
Delete events
19

Modification events

(PID) Process:(4080) Reborn.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\GGS\QGNA
Operation:writeName:InstKey
Value:
2753
(PID) Process:(4080) Reborn.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\GGS\QGNA
Operation:writeName:MID
Value:
149797806
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4080) Reborn.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
2
Suspicious files
55
Text files
30
Unknown types
20

Dropped files

PID
Process
Filename
Type
4080Reborn.exeC:\Users\admin\AppData\Local\Temp\ggs541D.exe
MD5:
SHA256:
2252msedge.exe
MD5:
SHA256:
4080Reborn.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:BC4E33EEBFBCB33AEFECD2436868C464
SHA256:7C3D713E217038D3B01B538B5ADD13C356AF46EE081A1BA97B560EB6C8302A34
4080Reborn.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:DCB5B68B79CEE698416F45295F4E0BE6
SHA256:6933B81E8D8DC3C19AAC91444E986AD269BC0EC028DC252857AC0416BCA0D9A7
2092msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\34a43e8d-0075-4a96-b814-42aef4c4993b.tmp
MD5:
SHA256:
2092msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RF137e3c.TMP
MD5:
SHA256:
4080Reborn.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4705DB930D032C3386A867A140EC3CE4_4DBD93DBC151E9B3007B54E528670011der
MD5:5ED3EFA9EBBD547A759391370AAF867B
SHA256:ABD8FCD64D4E4B974C3ABF493DAA90BCE2E5A1976A964C3947649C1A9FADF980
4080Reborn.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4705DB930D032C3386A867A140EC3CE4_4DBD93DBC151E9B3007B54E528670011binary
MD5:E86B2BC4A23FC9AF841B9774AA60993E
SHA256:E914BC889D7DE80DA6DA48B474BC143AD3E0512C3FD00AE67C1BF8CAE25B2B17
2092msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RF137e5b.TMP
MD5:
SHA256:
2092msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Last Versiontext
MD5:61FE7896F9494DCDF53480A325F4FB85
SHA256:ACFD3CD36E0DFCF1DCB67C7F31F2A5B9BA0815528A0C604D4330DFAA9E683E51
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
28
DNS requests
27
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4080
Reborn.exe
GET
31.25.231.10:80
http://fs0.gamenet.ru/installers/qgna/reborn/live/reborn_inner.exe
unknown
unknown
2644
msedge.exe
GET
301
31.25.227.141:80
http://go.gamenet.ru/a/19/213/inst
unknown
unknown
2644
msedge.exe
GET
302
31.25.227.141:80
http://go.gamenet.ru/file?id=21&mid=185388917&k=EYkCkbx5bOK0xss1ude1duJH3PNTCIhkrYRW2soSFUkKsQoV4qcaBRiiAUIYvgrRIwg2qC3FO5YAjgLAVeoypxEn1J3ZxvkIMrVbwjzU8aGpKDKQ2emzMw0HL3tQcWg0x0KNdcdUEDyjkKepWemcJTxtxCaFhT4Iv%2BIV%2FC2UtQiVg
unknown
unknown
4080
Reborn.exe
GET
31.25.231.10:80
http://fs0.gamenet.ru/installers/qgna/reborn/live/reborn_inner.exe
unknown
unknown
2644
msedge.exe
GET
302
31.25.227.141:80
http://go.gamenet.ru/file?id=21&mid=185388917&
unknown
unknown
4080
Reborn.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e1b0942b2bf0cfd6
unknown
unknown
4080
Reborn.exe
GET
200
184.24.206.119:80
http://x1.c.lencr.org/
unknown
unknown
4080
Reborn.exe
GET
200
192.124.249.41:80
http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D
unknown
unknown
4080
Reborn.exe
GET
200
192.124.249.41:80
http://ocsp.godaddy.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBTkIInKBAzXkF0Qh0pel3lfHJ9GPAQU0sSw0pHUTBFxs2HLPaH%2B3ahq1OMCAxvnFQ%3D%3D
unknown
unknown
4080
Reborn.exe
GET
200
184.25.51.82:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgOMd2BRN6m5IicTZVqWnEdgYQ%3D%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
4080
Reborn.exe
31.25.227.143:443
gnlogin.ru
Big Mmo Game Network Limited
RU
unknown
4080
Reborn.exe
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
4080
Reborn.exe
184.24.206.119:80
x1.c.lencr.org
Akamai International B.V.
US
unknown
4080
Reborn.exe
184.25.51.82:80
r3.o.lencr.org
Akamai International B.V.
DE
unknown
4080
Reborn.exe
31.25.227.152:443
gnapi.com
Big Mmo Game Network Limited
RU
unknown
4080
Reborn.exe
192.124.249.41:80
ocsp.godaddy.com
SUCURI-SEC
US
unknown
4080
Reborn.exe
31.25.231.10:80
fs0.gamenet.ru
Big Mmo Game Network Limited
RU
unknown

DNS requests

Domain
IP
Reputation
gnlogin.ru
  • 31.25.227.143
unknown
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
x1.c.lencr.org
  • 184.24.206.119
whitelisted
r3.o.lencr.org
  • 184.25.51.82
  • 184.25.51.75
shared
gnapi.com
  • 31.25.227.152
  • 31.25.227.151
unknown
ocsp.godaddy.com
  • 192.124.249.41
  • 192.124.249.36
  • 192.124.249.24
  • 192.124.249.23
  • 192.124.249.22
whitelisted
fs0.gamenet.ru
  • 31.25.231.10
  • 31.25.231.14
  • 31.25.231.3
unknown
config.edge.skype.com
  • 13.107.42.16
whitelisted
go.gamenet.ru
  • 31.25.227.141
  • 31.25.227.142
unknown
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted

Threats

PID
Process
Class
Message
4080
Reborn.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
4080
Reborn.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info