| URL: | https://lol.secure.dyn.riotcdn.net:443/channels/public/x/installer/current/live.na.exe |
| Full analysis: | https://app.any.run/tasks/0f06fc4e-6d04-48ee-86ab-2f98e2c907ae |
| Verdict: | Malicious activity |
| Analysis date: | February 12, 2020, 08:20:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 19E7CF8E90BA0ADB0BCFE8AC10A37855 |
| SHA1: | D3CD09194314BBD4D096336A0D9DBC5BEE10AE66 |
| SHA256: | A58FD81D60812417F07BC09AF570FCB2488F0046B38805062C16AA03FFF17CF9 |
| SSDEEP: | 3:N8KFmQXuq/XMKM/0uaOSJuygOXKGZ9QEkA:2KFmQeq/XMKMsY6iOXdZvJ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 332 | "C:/Riot Games/Riot Client/RiotClientServices.exe" "--launch-product=league_of_legends" "--launch-patchline=live" "--force-auto-patch" "--region=NA" "--locale=en_US" "--session-id=37e2b29c-7907-7d41-beb3-ac6e97a47c07" "--install-flow" | C:\Riot Games\Riot Client\RiotClientServices.exe | Install League of Legends na.exe | ||||||||||||
User: admin Company: Riot Games, Inc. Integrity Level: MEDIUM Description: RiotClientServices Exit code: 0 Version: 2.0.0.0 Modules
| |||||||||||||||
| 620 | "C:\Riot Games\Riot Client\UX\RiotClientUxRender.exe" --type=renderer --no-sandbox --disable-databases --lang=en-US --lang=en-US --log-file="C:/Users/admin/AppData/Local/Riot Games/Riot Client/Logs/Riot Client UX Logs/debug.log" --disable-spell-checking --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3204.0.172774840\31900752" /prefetch:1 --app-name=RiotClient --ux-name=RiotClientUx --ux-helper-name=RiotClientUxHelper --log-dir="C:/Users/admin/AppData/Local/Riot Games/Riot Client/Logs/Riot Client UX Logs/" --app-port=51820 --crashpad-environment=KeystoneFoundationLiveWin --user-data-root="C:/Users/admin/AppData/Local/Riot Games/Riot Client" --app-root="C:/Riot Games/Riot Client" | C:\Riot Games\Riot Client\UX\RiotClientUxRender.exe | RiotClientUx.exe | ||||||||||||
User: admin Company: Riot Games, Inc. Integrity Level: MEDIUM Description: RiotClientUx Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 628 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1004,2426818773986262437,14229918162722323741,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=13429758961625745872 --mojo-platform-channel-handle=1024 --ignored=" --type=renderer " /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 816 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,2426818773986262437,14229918162722323741,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=2737759966599557766 --mojo-platform-channel-handle=2416 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 872 | "C:/Riot Games/Riot Client/RiotClientCrashHandler.exe" "--database=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Crashes/RiotClientUx" "--metrics-dir=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Crashes/RiotClientUx" --url=https://sentry.io/api/1339107/minidump/?sentry_key=dc54709324504ab18ddf517a83f99e1a "--annotation=2020-02-12T08-23-17_3204_RiotClientUx.0.log=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Logs/Riot Client UX Logs/2020-02-12T08-23-17_3204_RiotClientUx.0.log" "--annotation=2020-02-12T08-23-17_3204_RiotClientUx.log=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Logs/Riot Client UX Logs/2020-02-12T08-23-17_3204_RiotClientUx.log" --initial-client-data=0xfc,0x100,0x104,0xf8,0x108,0x5a1c751c,0x5a1c752c,0x5a1c753c | C:\Riot Games\Riot Client\RiotClientCrashHandler.exe | — | RiotClientUx.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1136 | "C:/Riot Games/Riot Client/RiotClientCrashHandler.exe" "--database=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Crashes/RiotClientUxHelper" "--metrics-dir=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Crashes/RiotClientUxHelper" --url=https://sentry.io/api/1339107/minidump/?sentry_key=dc54709324504ab18ddf517a83f99e1a "--annotation=2020-02-12T08-23-18_620_RiotClientUxHelper-renderer.0.log=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Logs/Riot Client UX Logs/RiotClient UX Renderer Logs/2020-02-12T08-23-18_620_RiotClientUxHelper-renderer.0.log" "--annotation=2020-02-12T08-23-18_620_RiotClientUxHelper-renderer.log=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Logs/Riot Client UX Logs/RiotClient UX Renderer Logs/2020-02-12T08-23-18_620_RiotClientUxHelper-renderer.log" --initial-client-data=0xf8,0xfc,0x100,0xf0,0x104,0x5a1c751c,0x5a1c752c,0x5a1c753c | C:\Riot Games\Riot Client\RiotClientCrashHandler.exe | — | RiotClientUxRender.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1348 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1004,2426818773986262437,14229918162722323741,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5125553192546263396 --renderer-client-id=15 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3724 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1504 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,2426818773986262437,14229918162722323741,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=9412913822033247024 --mojo-platform-channel-handle=4044 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1684 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,2426818773986262437,14229918162722323741,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=218294213723246263 --mojo-platform-channel-handle=3668 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1692 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2564 --on-initialized-event-handle=324 --parent-handle=328 /prefetch:6 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| (PID) Process: | (1740) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (1740) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (1740) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (1740) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (1692) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 1740-13225969227121500 |
Value: 259 | |||
| (PID) Process: | (1740) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1740) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (1740) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (1740) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3120-13213713943555664 |
Value: 0 | |||
| (PID) Process: | (1740) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1740 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5E43B54B-6CC.pma | — | |
MD5:— | SHA256:— | |||
| 1740 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\2c09c5ba-5341-43d6-abf8-b27afa2a8426.tmp | — | |
MD5:— | SHA256:— | |||
| 1740 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000028.dbtmp | — | |
MD5:— | SHA256:— | |||
| 1740 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old | text | |
MD5:— | SHA256:— | |||
| 1740 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1740 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RFa66c2f.TMP | text | |
MD5:— | SHA256:— | |||
| 1740 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RFa66c20.TMP | text | |
MD5:— | SHA256:— | |||
| 1740 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
| 1740 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1740 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RFa66e33.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3516 | chrome.exe | GET | 302 | 172.217.16.206:80 | http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOTRmQUFXVHlhaGJaUTdMLWtCSkNJUl9ZQQ/1.0.0.5_nmmhkkegccagdldgiimedpiccmgmieda.crx | US | html | 510 b | whitelisted |
332 | RiotClientServices.exe | GET | 200 | 2.16.186.59:80 | http://riot-client.dyn.riotcdn.net/channels/public/x/status/keystonefoundationlive.json | unknown | text | 1.36 Kb | whitelisted |
3516 | chrome.exe | GET | 302 | 172.217.16.206:80 | http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx | US | html | 515 b | whitelisted |
3516 | chrome.exe | GET | 200 | 173.194.138.202:80 | http://r5---sn-aigzrn7d.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOTRmQUFXVHlhaGJaUTdMLWtCSkNJUl9ZQQ/1.0.0.5_nmmhkkegccagdldgiimedpiccmgmieda.crx?cms_redirect=yes&mip=185.43.110.249&mm=28&mn=sn-aigzrn7d&ms=nvh&mt=1581495742&mv=m&mvi=4&pl=23&shardbypass=yes | US | crx | 293 Kb | whitelisted |
3516 | chrome.exe | GET | 200 | 173.194.138.200:80 | http://r3---sn-aigzrn7d.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx?cms_redirect=yes&mip=185.43.110.249&mm=28&mn=sn-aigzrn7d&ms=nvh&mt=1581495742&mv=m&mvi=2&pl=23&shardbypass=yes | US | crx | 862 Kb | whitelisted |
3204 | RiotClientUx.exe | GET | 200 | 205.185.216.42:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.4 Kb | whitelisted |
3204 | RiotClientUx.exe | GET | 200 | 93.184.221.240:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.4 Kb | whitelisted |
3204 | RiotClientUx.exe | GET | 200 | 93.184.221.240:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 57.4 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3516 | chrome.exe | 172.217.22.99:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
3516 | chrome.exe | 2.16.186.59:443 | lol.secure.dyn.riotcdn.net | Akamai International B.V. | — | whitelisted |
3516 | chrome.exe | 172.217.23.164:443 | www.google.com | Google Inc. | US | whitelisted |
3516 | chrome.exe | 172.217.23.99:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
3516 | chrome.exe | 172.217.22.14:443 | sb-ssl.google.com | Google Inc. | US | whitelisted |
3516 | chrome.exe | 172.217.16.163:443 | www.gstatic.com | Google Inc. | US | whitelisted |
3604 | Install League of Legends na.exe | 10.92.69.160:443 | collector-aws-or.rdatasrv.net | — | — | unknown |
3604 | Install League of Legends na.exe | 104.16.37.99:443 | data.riotgames.com | Cloudflare Inc | US | shared |
— | — | 10.92.69.160:443 | collector-aws-or.rdatasrv.net | — | — | unknown |
3604 | Install League of Legends na.exe | 104.18.157.37:443 | clientconfig.rpg.riotgames.com | Cloudflare Inc | US | unknown |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
lol.secure.dyn.riotcdn.net |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| malicious |
ssl.gstatic.com |
| whitelisted |
sb-ssl.google.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
data.riotgames.com |
| unknown |
collector-aws-or.rdatasrv.net |
| unknown |
clientconfig.rpg.riotgames.com |
| unknown |
Process | Message |
|---|---|
Install League of Legends na.exe | Install League of Legends na.exe(00000C44): ALWAYS| Generating new machine id
|
Install League of Legends na.exe | Install League of Legends na.exe(00000C44): ALWAYS| App Root: C:/Users/admin/Downloads
|
Install League of Legends na.exe | Install League of Legends na.exe(00000C44): WARN| No version found in system.yaml, computing it. Patch version may be inaccurate
|
Install League of Legends na.exe | Install League of Legends na.exe(00000C44): ALWAYS| Locking mutex file C:/Users/admin/AppData/Local/Riot Games/Install League of Legends na/Config/lockfile_
|
Install League of Legends na.exe | Install League of Legends na.exe(00000C44): ALWAYS| Launcher Build CL:3008359 - Build Date:Dec 09 2019 - Build Time:12:42:21
|
Install League of Legends na.exe | Install League of Legends na.exe(00000C44): ALWAYS| Lock file was not detected at C:/Users/admin/AppData/Local/Riot Games/Install League of Legends na/Config/lockfile
|
Install League of Legends na.exe | Install League of Legends na.exe(00000C44): ALWAYS| Creating config directory C:/Users/admin/AppData/Local/Riot Games/Install League of Legends na/Config
|
Install League of Legends na.exe | Install League of Legends na.exe(00000C44): ALWAYS| Keeping window hidden.
|
Install League of Legends na.exe | Install League of Legends na.exe(00000C44): ALWAYS| Centering screen on monitor.
|
Install League of Legends na.exe | Install League of Legends na.exe(00000C44): ALWAYS| Successfully transitioned to new screen (not draggable).
|