File name:

Launcher.exe

Full analysis: https://app.any.run/tasks/ce476a92-9199-4f6d-bec7-d25264962a93
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: December 06, 2019, 06:47:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

101D606E040F3506412987BFB8BC5182

SHA1:

D534C8AA724DFAEEBA7686C7C14FD56A9F50F771

SHA256:

9A7FDB21A212ED6A2D55CBA1B825428CBA6CB5A75FC3BA4C890D6D052F79BFF1

SSDEEP:

12288:Pszo/A/Tj/iwTep8fql4bGRknSNgDsG9iiPwtsmi13TPFaFyiD:Ao/A/3/iwTep8fql4bGRknSNgDsswtsG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Tefor.exe (PID: 3060)
      • Tefor.exe (PID: 3092)
      • Tefor.exe (PID: 2864)
      • Tefor.exe (PID: 3824)
    • Downloads executable files from the Internet

      • Launcher.exe (PID: 1636)
    • Loads dropped or rewritten executable

      • Tefor.exe (PID: 3092)
      • Tefor.exe (PID: 3060)
      • Tefor.exe (PID: 3824)
    • Changes settings of System certificates

      • Tefor.exe (PID: 3092)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Launcher.exe (PID: 1636)
    • Adds / modifies Windows certificates

      • Tefor.exe (PID: 3092)
    • Starts Internet Explorer

      • Tefor.exe (PID: 3824)
    • Reads Environment values

      • Launcher.exe (PID: 1636)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 2540)
    • Application launched itself

      • Tefor.exe (PID: 3092)
    • Starts CMD.EXE for commands execution

      • Launcher.exe (PID: 1636)
    • Creates files in the user directory

      • Tefor.exe (PID: 3092)
  • INFO

    • Creates files in the user directory

      • iexplore.exe (PID: 3432)
    • Changes internet zones settings

      • iexplore.exe (PID: 2956)
    • Reads the hosts file

      • Tefor.exe (PID: 3092)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3432)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:06:14 22:24:42+02:00
PEType: PE32
LinkerVersion: 8
CodeSize: 649728
InitializedDataSize: 36352
UninitializedDataSize: -
EntryPoint: 0xa087e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: Launcher
FileVersion: 1.0.0.0
InternalName: Launcher.exe
LegalCopyright: Copyright © 2019
LegalTrademarks: -
OriginalFileName: Launcher.exe
ProductName: Launcher
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 14-Jun-2019 20:24:42
Comments: -
CompanyName: -
FileDescription: Launcher
FileVersion: 1.0.0.0
InternalName: Launcher.exe
LegalCopyright: Copyright © 2019
LegalTrademarks: -
OriginalFilename: Launcher.exe
ProductName: Launcher
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000080

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 14-Jun-2019 20:24:42
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00002000
0x0009E884
0x0009EA00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.05555
.rsrc
0x000A2000
0x00008B74
0x00008C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.8688
.reloc
0x000AC000
0x0000000C
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
0.0815394

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.43336
3980
UNKNOWN
UNKNOWN
RT_MANIFEST
32512
1.51664
20
UNKNOWN
UNKNOWN
RT_GROUP_ICON

Imports

mscoree.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
10
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start launcher.exe cmd.exe no specs taskkill.exe no specs tefor.exe tefor.exe no specs tefor.exe no specs tefor.exe no specs iexplore.exe iexplore.exe launcher.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1636"C:\Users\admin\AppData\Local\Temp\Launcher.exe" C:\Users\admin\AppData\Local\Temp\Launcher.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
1
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\launcher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2540"C:\Windows\System32\cmd.exe" /C taskkill /f /pid 1636 & chdir "C:\Users\admin\AppData\Local\Temp/Tefor/v.17" & start Tefor.exeC:\Windows\System32\cmd.exeLauncher.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2620taskkill /f /pid 1636 C:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2812"C:\Users\admin\AppData\Local\Temp\Launcher.exe" C:\Users\admin\AppData\Local\Temp\Launcher.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Launcher
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\launcher.exe
c:\systemroot\system32\ntdll.dll
2864"C:\Users\admin\AppData\Local\Temp\Tefor\v.17\Tefor.exe" --type=gpu-process --field-trial-handle=1388,18289470993995234271,2497856185640551065,131072 --disable-features=SpareRendererForSitePerProcess --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=IAAAAAAAAADgAAAgAAAAAAAAYAAAAAAACAAAAAAAAAAoAAAABAAAACAAAAAAAAAAKAAAAAAAAAAwAAAAAAAAADgAAAAAAAAAEAAAAAAAAAAAAAAABQAAABAAAAAAAAAAAAAAAAYAAAAQAAAAAAAAAAEAAAAFAAAAEAAAAAAAAAABAAAABgAAAA== --service-request-channel-token=16505556800654944969 --mojo-platform-channel-handle=2760 /prefetch:2C:\Users\admin\AppData\Local\Temp\Tefor\v.17\Tefor.exeTefor.exe
User:
admin
Company:
Alkad Software
Integrity Level:
HIGH
Description:
Tefor
Exit code:
0
Version:
1.0.12
Modules
Images
c:\users\admin\appdata\local\temp\tefor\v.17\tefor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\tefor\v.17\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2956"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
Tefor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3060"C:\Users\admin\AppData\Local\Temp\Tefor\v.17\Tefor.exe" --type=gpu-process --field-trial-handle=1388,18289470993995234271,2497856185640551065,131072 --disable-features=SpareRendererForSitePerProcess --gpu-preferences=IAAAAAAAAADgAAAgAAAAAAAAYAAAAAAACAAAAAAAAAAoAAAABAAAACAAAAAAAAAAKAAAAAAAAAAwAAAAAAAAADgAAAAAAAAAEAAAAAAAAAAAAAAABQAAABAAAAAAAAAAAAAAAAYAAAAQAAAAAAAAAAEAAAAFAAAAEAAAAAAAAAABAAAABgAAAA== --service-request-channel-token=14725796155200424238 --mojo-platform-channel-handle=1400 --ignored=" --type=renderer " /prefetch:2C:\Users\admin\AppData\Local\Temp\Tefor\v.17\Tefor.exeTefor.exe
User:
admin
Company:
Alkad Software
Integrity Level:
LOW
Description:
Tefor
Exit code:
0
Version:
1.0.12
Modules
Images
c:\users\admin\appdata\local\temp\tefor\v.17\tefor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\tefor\v.17\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3092Tefor.exe C:\Users\admin\AppData\Local\Temp\Tefor\v.17\Tefor.exe
cmd.exe
User:
admin
Company:
Alkad Software
Integrity Level:
HIGH
Description:
Tefor
Exit code:
0
Version:
1.0.12
Modules
Images
c:\users\admin\appdata\local\temp\tefor\v.17\tefor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\tefor\v.17\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3432"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2956 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3824"C:\Users\admin\AppData\Local\Temp\Tefor\v.17\Tefor.exe" --type=renderer --field-trial-handle=1388,18289470993995234271,2497856185640551065,131072 --disable-features=SpareRendererForSitePerProcess --lang=en-US --app-path="C:\Users\admin\AppData\Local\Temp\Tefor\v.17\resources\app.asar" --node-integration --no-sandbox --no-zygote --background-color=#fff --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=11245684553337024647 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1776 /prefetch:1C:\Users\admin\AppData\Local\Temp\Tefor\v.17\Tefor.exeTefor.exe
User:
admin
Company:
Alkad Software
Integrity Level:
HIGH
Description:
Tefor
Exit code:
0
Version:
1.0.12
Modules
Images
c:\users\admin\appdata\local\temp\tefor\v.17\tefor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\tefor\v.17\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
505
Read events
431
Write events
73
Delete events
1

Modification events

(PID) Process:(1636) Launcher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Launcher_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1636) Launcher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Launcher_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1636) Launcher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Launcher_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(1636) Launcher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Launcher_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(1636) Launcher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Launcher_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(1636) Launcher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Launcher_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(1636) Launcher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Launcher_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1636) Launcher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Launcher_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1636) Launcher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Launcher_RASMANCS
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(1636) Launcher.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Launcher_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
4294901760
Executable files
7
Suspicious files
19
Text files
24
Unknown types
61

Dropped files

PID
Process
Filename
Type
1636Launcher.exeC:\Users\admin\AppData\Local\Temp\Tefor\v.update17\locales\am.pakpgc
MD5:5243586AB8BA46819F25BA4D101C37E2
SHA256:4DB1017A857CEE4C332E72A1591ACA5E74A4E37C747BBFB9A9EF0C70C04A5B21
1636Launcher.exeC:\Users\admin\AppData\Local\Temp\Tefor\v.update17\locales\ar.pakpgc
MD5:9304C7491E32AF17FE2DC362FE0BD068
SHA256:F3E1520F2A799B8A2916ED50370A3D7608546504ACBA832528A6589C40BCB96D
1636Launcher.exeC:\Users\admin\AppData\Local\Temp\Tefor\v.update17\locales\bn.pakpgc
MD5:FF3CD4B973750A923D7ABFBBEEEBC8EB
SHA256:19A95C12D011776AD2D128C71018DE6BF4B9AA8346284BEE28D42778E2289E3E
1636Launcher.exeC:\Users\admin\AppData\Local\Temp\Tefor\v.update17\locales\bg.pakpgc
MD5:14D4009F946C4A7B78489B07DF5AA82E
SHA256:E420764AF35AA734C221240061940EAEFA41D397341FEC7DD733A1423D76E272
1636Launcher.exeC:\Users\admin\AppData\Local\Temp\Tefor\v.update17\locales\de.pakpgc
MD5:4883E792E4097F9021806B60959C32AC
SHA256:E4630D8059E25A0119874ECA6A9759915ECE6B241D1F01FDE8F8F686F770BD72
1636Launcher.exeC:\Users\admin\AppData\Local\Temp\Tefor\v.update17\locales\ca.pakpgc
MD5:3102FD61444837AB5893C9EA60643155
SHA256:4E1F3CAED46577032A11834497C38274888A1AECEBFC85A86B534CE3923D0CCC
1636Launcher.exeC:\Users\admin\AppData\Local\Temp\Tefor\v.update17\locales\cs.pakpgc
MD5:695B25666425D89E3A23D21B7514E5AA
SHA256:69FBA694C5CE9D10EC0DDA38EDC2689E0D12B3B73B257B3BA6ED5EC986E9D748
1636Launcher.exeC:\Users\admin\AppData\Local\Temp\Tefor\v.update17\GameWer\Updater.exeexecutable
MD5:3BD084F1877111273FA50A8AE6473E1C
SHA256:D04F78569C2AAB08A5D53D31DB20374059308C22537FC0850487C3E5A0BEDF9C
1636Launcher.exeC:\Users\admin\AppData\Local\Temp\Tefor\v.update17\locales\el.pakpgc
MD5:74676C037CD3655A29926C9A9F488D5D
SHA256:00E6E0C6830DA458A42CC80D7124DB6B3983DEF408E7F13EA9BA126DAA5C4375
1636Launcher.exeC:\Users\admin\AppData\Local\Temp\Tefor\v.update17\locales\en-US.pakpgc
MD5:15E8556F737D17BD4D645513EE190990
SHA256:12E4FD083A49E038578EA2993E6C88239083C8D098231527EEE861299A4E1C99
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
78
TCP/UDP connections
127
DNS requests
9
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1636
Launcher.exe
GET
200
144.76.28.169:80
http://cdn.alkad.org/tefor/Launcher.version.txt?v=12/6/2019%206:47:20%20AM
DE
text
93 b
suspicious
1636
Launcher.exe
GET
200
144.76.28.169:80
http://cdn.alkad.org/tefor/actual/Tefor.version.txt?v=12/6/2019%206:47:20%20AM
DE
text
7.56 Kb
suspicious
1636
Launcher.exe
GET
200
144.76.28.169:80
http://cdn.alkad.org/tefor/actual/locales/ca.pak?v=12/6/2019%206:47:22%20AM
DE
pgc
82.2 Kb
suspicious
1636
Launcher.exe
GET
200
144.76.28.169:80
http://cdn.alkad.org/tefor/actual/locales/am.pak?v=12/6/2019%206:47:21%20AM
DE
pgc
115 Kb
suspicious
1636
Launcher.exe
GET
200
144.76.28.169:80
http://cdn.alkad.org/tefor/actual/GameWer/Updater.exe?v=12/6/2019%206:47:20%20AM
DE
executable
802 Kb
suspicious
1636
Launcher.exe
GET
200
144.76.28.169:80
http://cdn.alkad.org/tefor/actual/locales/bg.pak?v=12/6/2019%206:47:21%20AM
DE
pgc
125 Kb
suspicious
1636
Launcher.exe
GET
200
144.76.28.169:80
http://cdn.alkad.org/tefor/actual/locales/ar.pak?v=12/6/2019%206:47:21%20AM
DE
pgc
116 Kb
suspicious
1636
Launcher.exe
GET
200
144.76.28.169:80
http://cdn.alkad.org/tefor/actual/locales/fil.pak?v=12/6/2019%206:47:23%20AM
DE
mmw
83.2 Kb
suspicious
1636
Launcher.exe
GET
200
144.76.28.169:80
http://cdn.alkad.org/tefor/actual/locales/el.pak?v=12/6/2019%206:47:22%20AM
DE
pgc
140 Kb
suspicious
1636
Launcher.exe
GET
200
144.76.28.169:80
http://cdn.alkad.org/tefor/actual/locales/bn.pak?v=12/6/2019%206:47:21%20AM
DE
pgc
163 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1636
Launcher.exe
144.76.28.169:80
cdn.alkad.org
Hetzner Online GmbH
DE
suspicious
3092
Tefor.exe
104.17.64.4:443
cdnjs.cloudflare.com
Cloudflare Inc
US
unknown
3092
Tefor.exe
172.217.21.238:443
www.google-analytics.com
Google Inc.
US
whitelisted
3092
Tefor.exe
144.76.28.169:80
cdn.alkad.org
Hetzner Online GmbH
DE
suspicious
3092
Tefor.exe
151.101.14.214:443
api.twitch.tv
Fastly
US
suspicious
3092
Tefor.exe
185.97.254.34:28015
ArtPlanet LLC
RU
unknown
3092
Tefor.exe
93.158.134.119:443
mc.yandex.ru
YANDEX LLC
RU
whitelisted
185.97.254.34:2291
ArtPlanet LLC
RU
unknown
185.97.254.34:2231
ArtPlanet LLC
RU
unknown
185.97.254.34:7777
ArtPlanet LLC
RU
unknown

DNS requests

Domain
IP
Reputation
cdn.alkad.org
  • 144.76.28.169
suspicious
cdnjs.cloudflare.com
  • 104.17.64.4
  • 104.17.65.4
whitelisted
mc.yandex.ru
  • 93.158.134.119
  • 77.88.21.119
  • 87.250.250.119
  • 87.250.251.119
whitelisted
www.google-analytics.com
  • 172.217.21.238
whitelisted
api.twitch.tv
  • 151.101.14.214
whitelisted
store.steampowered.com
  • 184.25.158.97
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted

Threats

PID
Process
Class
Message
1636
Launcher.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1636
Launcher.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
1636
Launcher.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1636
Launcher.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
No debug info