| File name: | Battle.net-Setup.exe |
| Full analysis: | https://app.any.run/tasks/ee31a6e6-ebc8-45b0-acac-fcb30b62a3c4 |
| Verdict: | Malicious activity |
| Analysis date: | November 28, 2023, 21:57:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 1221EFFECC8DC5EC7098004DDE8CAB52 |
| SHA1: | 1AE4E45D136682A4164942D98C11D7C3C9457218 |
| SHA256: | A25D73264E9055AC61151FF134F7400EB38A43FCE67A972BDC45A7C65B3933E1 |
| SSDEEP: | 98304:rqtoSwEJkHYi7hEZ/PybjViwntc9CHFw4LxdAgNPEwzlQMMJfhqB6HA0GmXBT9Wk:5qm |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:06:03 20:10:01+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.15 |
| CodeSize: | 2947584 |
| InitializedDataSize: | 1878016 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13e9f6 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.18.5.3106 |
| ProductVersionNumber: | 1.18.5.3106 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| LegalCopyright: | © 2005-2022 Blizzard Entertainment Inc. |
| InternalName: | Battle.net Setup |
| FileVersion: | 1.18.5.3106 |
| CompanyName: | Blizzard Entertainment |
| ProductName: | Battle.net Setup |
| ProductVersion: | 1.18.5.3106 |
| FileDescription: | Battle.net Setup |
| OriginalFileName: | Battle.net-Setup.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2692 | "C:\Users\admin\AppData\Local\Temp\Battle.net-Setup.exe" | C:\Users\admin\AppData\Local\Temp\Battle.net-Setup.exe | explorer.exe | ||||||||||||
User: admin Company: Blizzard Entertainment Integrity Level: MEDIUM Description: Battle.net Setup Exit code: 0 Version: 1.18.5.3106 Modules
| |||||||||||||||
| 2840 | "C:\Users\admin\AppData\Local\Temp\Battle.net-Setup.exe" --cmdver=2 --elevated --locale=enUS --mode=setup --session=507940333681721471 | C:\Users\admin\AppData\Local\Temp\Battle.net-Setup.exe | Battle.net-Setup.exe | ||||||||||||
User: admin Company: Blizzard Entertainment Integrity Level: HIGH Description: Battle.net Setup Exit code: 0 Version: 1.18.5.3106 Modules
| |||||||||||||||
| 2852 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2988 | "C:\ProgramData\Battle.net\Agent\Agent.exe" --locale=enUS --session=507940333681721471 | C:\ProgramData\Battle.net\Agent\Agent.exe | — | Battle.net-Setup.exe | |||||||||||
User: admin Company: Blizzard Entertainment Integrity Level: HIGH Description: Battle.net File Switcher Exit code: 0 Version: 2.31.3.8445 Modules
| |||||||||||||||
| 3108 | "C:\ProgramData\Battle.net\Agent\Agent.8445\Agent.exe" --locale=enUS --session=507940333681721471 | C:\ProgramData\Battle.net\Agent\Agent.8445\Agent.exe | Agent.exe | ||||||||||||
User: admin Company: Blizzard Entertainment Integrity Level: HIGH Description: Battle.net Update Agent Exit code: 0 Version: 2.31.3.8445 Modules
| |||||||||||||||
| 3832 | "C:\ProgramData\Battle.net\Setup\bna_2\Battle.net-Setup.exe" --cmdver=2 --elevated --locale=enUS --mode=setup --processpath=C:\Users\admin\AppData\Local\Temp\Battle.net-Setup.exe --session=507940333681721471 | C:\ProgramData\Battle.net\Setup\bna_2\Battle.net-Setup.exe | Battle.net-Setup.exe | ||||||||||||
User: admin Company: Blizzard Entertainment Integrity Level: HIGH Description: Battle.net Setup Exit code: 0 Version: 1.18.10.3141 Modules
| |||||||||||||||
| (PID) Process: | (2852) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{4D670498-76A4-4E76-A544-C8C7FEE98338}\{522C9944-C955-40E1-9CD2-D2EB6F9AC3EF} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (2852) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{4D670498-76A4-4E76-A544-C8C7FEE98338} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (2852) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{ED378C2A-8991-4247-AE28-3966296ECE00} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (2692) Battle.net-Setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2692) Battle.net-Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2692) Battle.net-Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2692) Battle.net-Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2692) Battle.net-Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2840) Battle.net-Setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2840) Battle.net-Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2840 | Battle.net-Setup.exe | C:\ProgramData\Battle.net\Setup\bna_2\Logs\battle.net-setup-20231128T215800.log | text | |
MD5:B12CCA8F3CE518646C514D713639C0BE | SHA256:AC337286CA789B698B3A0725CB636A3402148F0BA8E2C95D8307D144E0BD66F4 | |||
| 2840 | Battle.net-Setup.exe | C:\ProgramData\Battle.net\Setup\bna_2\..Battle.net-Setup.exe.7.2840.temp.8.2840.temp.temp | executable | |
MD5:F7FE24CEBBC4B0332C77BCE563E11B1D | SHA256:002F33FEE7B8A159058368B7E93E492931C4CA72E90660BDB2691BCD62FEDD3C | |||
| 2840 | Battle.net-Setup.exe | C:\ProgramData\Battle.net\Setup\bna_2\cleanup.marker | text | |
MD5:8C6384DDA98D8864D00E29DC96179970 | SHA256:9F1B237B5DC314EDB0DAFBA43265A24F2EB3FB998A011B4B605F38EC20A7CEAD | |||
| 2840 | Battle.net-Setup.exe | C:\ProgramData\Battle.net\Setup\bna_2\.Battle.net-Setup.exe.7.2840.temp | binary | |
MD5:03249B905D882FDDEC18602ACF1DAA07 | SHA256:8D256A2DDC1F59956F64638446A00BA91685E6B0458D3DF2D48FCD3677C563B1 | |||
| 2840 | Battle.net-Setup.exe | C:\ProgramData\Battle.net\Setup\bna_2\Battle.net-Setup.exe | executable | |
MD5:F7FE24CEBBC4B0332C77BCE563E11B1D | SHA256:002F33FEE7B8A159058368B7E93E492931C4CA72E90660BDB2691BCD62FEDD3C | |||
| 2692 | Battle.net-Setup.exe | C:\ProgramData\Battle.net\Setup\bna_2\Logs\battle.net-setup-20231128T215755.log | text | |
MD5:43C5E20890E06D8FAC885A2A2158AC72 | SHA256:CB0012A9F2F9D50128F9A9325D75566DF682A742085ABE7F7456D04EB8A230D4 | |||
| 2840 | Battle.net-Setup.exe | C:\ProgramData\Battle.net\Setup\bna_2\.Battle.net-Setup.exe.9.2840.temp | executable | |
MD5:F7FE24CEBBC4B0332C77BCE563E11B1D | SHA256:002F33FEE7B8A159058368B7E93E492931C4CA72E90660BDB2691BCD62FEDD3C | |||
| 2840 | Battle.net-Setup.exe | C:\ProgramData\Battle.net\Setup\bna_2\..Battle.net-Setup.exe.7.2840.temp.8.2840.temp | executable | |
MD5:F7FE24CEBBC4B0332C77BCE563E11B1D | SHA256:002F33FEE7B8A159058368B7E93E492931C4CA72E90660BDB2691BCD62FEDD3C | |||
| 3832 | Battle.net-Setup.exe | C:\ProgramData\Battle.net\Agent\.Blizzard Uninstaller.exe.12.3832.temp | executable | |
MD5:B8BB284B7CD26643DF6876D665FBDE02 | SHA256:117420F75D1D5DB1B3908E0728F748198D37894AF980F7614226480C7DD7BAEB | |||
| 3832 | Battle.net-Setup.exe | C:\ProgramData\Battle.net\Agent\..LICENSES.13.3832.temp.14.3832.temp | text | |
MD5:E60C0CC3B71BAECC5F08C6158A711C79 | SHA256:4FA74FBB073874153BB338746857BF75ED7BE0B436BDEDE1D8625EED2E6C0F3E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2692 | Battle.net-Setup.exe | GET | 204 | 37.244.28.104:80 | http://nydus.battle.net/geoip | unknown | — | — | unknown |
2692 | Battle.net-Setup.exe | POST | — | 24.105.29.24:3724 | http://iir.blizzard.com:3724/submit/BNET_APP | unknown | — | — | unknown |
2840 | Battle.net-Setup.exe | GET | 204 | 37.244.28.104:80 | http://nydus.battle.net/geoip | unknown | — | — | unknown |
2840 | Battle.net-Setup.exe | POST | 200 | 142.250.184.238:80 | http://www.google-analytics.com/collect | unknown | image | 35 b | unknown |
2840 | Battle.net-Setup.exe | GET | 200 | 137.221.64.1:80 | http://eu.cdn.blizzard.com/tpr/bnt004/config/41/01/4101231186fed9e578d03cdbb7d658ec | unknown | text | 548 b | unknown |
2840 | Battle.net-Setup.exe | GET | 200 | 37.244.28.22:1119 | http://eu.patch.battle.net:1119/bts/versions | unknown | text | 3.43 Kb | unknown |
2840 | Battle.net-Setup.exe | GET | 200 | 137.221.64.7:80 | http://eu.cdn.blizzard.com/tpr/bnt004/config/41/01/4101231186fed9e578d03cdbb7d658ec | unknown | text | 548 b | unknown |
2840 | Battle.net-Setup.exe | GET | 200 | 37.244.28.22:1119 | http://eu.patch.battle.net:1119/bts/cdns | unknown | text | 659 b | unknown |
2840 | Battle.net-Setup.exe | GET | 200 | 137.221.64.2:80 | http://eu.cdn.blizzard.com/tpr/bnt004/config/41/01/4101231186fed9e578d03cdbb7d658ec | unknown | text | 548 b | unknown |
2692 | Battle.net-Setup.exe | POST | 200 | 142.250.184.238:80 | http://www.google-analytics.com/collect | unknown | image | 35 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2692 | Battle.net-Setup.exe | 37.244.28.104:80 | nydus.battle.net | Blizzard Entertainment, Inc | US | unknown |
2692 | Battle.net-Setup.exe | 24.105.29.24:3724 | iir.blizzard.com | Blizzard Entertainment, Inc | US | unknown |
2692 | Battle.net-Setup.exe | 142.250.184.238:80 | www.google-analytics.com | GOOGLE | US | whitelisted |
2840 | Battle.net-Setup.exe | 37.244.28.104:80 | nydus.battle.net | Blizzard Entertainment, Inc | US | unknown |
2840 | Battle.net-Setup.exe | 142.250.184.238:80 | www.google-analytics.com | GOOGLE | US | whitelisted |
2840 | Battle.net-Setup.exe | 37.244.28.22:1119 | eu.patch.battle.net | Blizzard Entertainment, Inc | US | unknown |
Domain | IP | Reputation |
|---|---|---|
nydus.battle.net |
| unknown |
iir.blizzard.com |
| unknown |
www.google-analytics.com |
| whitelisted |
eu.patch.battle.net |
| whitelisted |
eu.cdn.blizzard.com |
| whitelisted |
level3.blizzard.com |
| unknown |
blzddist1-a.akamaihd.net |
| whitelisted |
level3.ssl.blizzard.com |
| unknown |
us.patch.battle.net |
| unknown |
us.cdn.blizzard.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2692 | Battle.net-Setup.exe | Potential Corporate Privacy Violation | ET POLICY GeoIP Lookup (nydus.battle.net) |
2840 | Battle.net-Setup.exe | Potential Corporate Privacy Violation | ET POLICY GeoIP Lookup (nydus.battle.net) |
3832 | Battle.net-Setup.exe | Potential Corporate Privacy Violation | ET POLICY GeoIP Lookup (nydus.battle.net) |