URL:

https://lol.secure.dyn.riotcdn.net:443/channels/public/x/installer/current/live.na.exe

Full analysis: https://app.any.run/tasks/0f06fc4e-6d04-48ee-86ab-2f98e2c907ae
Verdict: Malicious activity
Analysis date: February 12, 2020, 08:20:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

19E7CF8E90BA0ADB0BCFE8AC10A37855

SHA1:

D3CD09194314BBD4D096336A0D9DBC5BEE10AE66

SHA256:

A58FD81D60812417F07BC09AF570FCB2488F0046B38805062C16AA03FFF17CF9

SSDEEP:

3:N8KFmQXuq/XMKM/0uaOSJuygOXKGZ9QEkA:2KFmQeq/XMKMsY6iOXdZvJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Install League of Legends na.exe (PID: 3604)
      • Install League of Legends na.exe (PID: 3188)
      • RiotClientUx.exe (PID: 3204)
      • RiotClientCrashHandler.exe (PID: 3780)
      • RiotClientCrashHandler.exe (PID: 872)
      • RiotClientUxRender.exe (PID: 620)
      • RiotClientCrashHandler.exe (PID: 1136)
    • Loads dropped or rewritten executable

      • RiotClientServices.exe (PID: 332)
      • RiotClientCrashHandler.exe (PID: 3780)
      • RiotClientUx.exe (PID: 3204)
      • RiotClientCrashHandler.exe (PID: 872)
      • RiotClientUxRender.exe (PID: 620)
      • RiotClientCrashHandler.exe (PID: 1136)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 1740)
      • RiotClientServices.exe (PID: 332)
      • Install League of Legends na.exe (PID: 3604)
    • Application launched itself

      • Install League of Legends na.exe (PID: 3604)
      • RiotClientServices.exe (PID: 332)
    • Creates files in the program directory

      • Install League of Legends na.exe (PID: 3604)
      • RiotClientServices.exe (PID: 332)
      • RiotClientServices.exe (PID: 3864)
    • Creates a software uninstall entry

      • RiotClientServices.exe (PID: 332)
    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 1740)
  • INFO

    • Reads the hosts file

      • chrome.exe (PID: 1740)
      • chrome.exe (PID: 3516)
      • RiotClientUx.exe (PID: 3204)
    • Application launched itself

      • chrome.exe (PID: 1740)
    • Reads Internet Cache Settings

      • chrome.exe (PID: 1740)
    • Reads settings of System Certificates

      • chrome.exe (PID: 3516)
      • RiotClientUx.exe (PID: 3204)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
80
Monitored processes
35
Malicious processes
8
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs install league of legends na.exe install league of legends na.exe riotclientservices.exe riotclientcrashhandler.exe no specs riotclientux.exe riotclientcrashhandler.exe no specs riotclientuxrender.exe riotclientservices.exe riotclientcrashhandler.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
332"C:/Riot Games/Riot Client/RiotClientServices.exe" "--launch-product=league_of_legends" "--launch-patchline=live" "--force-auto-patch" "--region=NA" "--locale=en_US" "--session-id=37e2b29c-7907-7d41-beb3-ac6e97a47c07" "--install-flow"C:\Riot Games\Riot Client\RiotClientServices.exe
Install League of Legends na.exe
User:
admin
Company:
Riot Games, Inc.
Integrity Level:
MEDIUM
Description:
RiotClientServices
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\riot games\riot client\riotclientservices.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
620"C:\Riot Games\Riot Client\UX\RiotClientUxRender.exe" --type=renderer --no-sandbox --disable-databases --lang=en-US --lang=en-US --log-file="C:/Users/admin/AppData/Local/Riot Games/Riot Client/Logs/Riot Client UX Logs/debug.log" --disable-spell-checking --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3204.0.172774840\31900752" /prefetch:1 --app-name=RiotClient --ux-name=RiotClientUx --ux-helper-name=RiotClientUxHelper --log-dir="C:/Users/admin/AppData/Local/Riot Games/Riot Client/Logs/Riot Client UX Logs/" --app-port=51820 --crashpad-environment=KeystoneFoundationLiveWin --user-data-root="C:/Users/admin/AppData/Local/Riot Games/Riot Client" --app-root="C:/Riot Games/Riot Client"C:\Riot Games\Riot Client\UX\RiotClientUxRender.exe
RiotClientUx.exe
User:
admin
Company:
Riot Games, Inc.
Integrity Level:
MEDIUM
Description:
RiotClientUx
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\riot games\riot client\ux\riotclientuxrender.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\riot games\riot client\ux\libcef.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
628"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1004,2426818773986262437,14229918162722323741,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=13429758961625745872 --mojo-platform-channel-handle=1024 --ignored=" --type=renderer " /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
816"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,2426818773986262437,14229918162722323741,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=2737759966599557766 --mojo-platform-channel-handle=2416 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
872"C:/Riot Games/Riot Client/RiotClientCrashHandler.exe" "--database=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Crashes/RiotClientUx" "--metrics-dir=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Crashes/RiotClientUx" --url=https://sentry.io/api/1339107/minidump/?sentry_key=dc54709324504ab18ddf517a83f99e1a "--annotation=2020-02-12T08-23-17_3204_RiotClientUx.0.log=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Logs/Riot Client UX Logs/2020-02-12T08-23-17_3204_RiotClientUx.0.log" "--annotation=2020-02-12T08-23-17_3204_RiotClientUx.log=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Logs/Riot Client UX Logs/2020-02-12T08-23-17_3204_RiotClientUx.log" --initial-client-data=0xfc,0x100,0x104,0xf8,0x108,0x5a1c751c,0x5a1c752c,0x5a1c753cC:\Riot Games\Riot Client\RiotClientCrashHandler.exeRiotClientUx.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\riot games\riot client\riotclientcrashhandler.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1136"C:/Riot Games/Riot Client/RiotClientCrashHandler.exe" "--database=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Crashes/RiotClientUxHelper" "--metrics-dir=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Crashes/RiotClientUxHelper" --url=https://sentry.io/api/1339107/minidump/?sentry_key=dc54709324504ab18ddf517a83f99e1a "--annotation=2020-02-12T08-23-18_620_RiotClientUxHelper-renderer.0.log=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Logs/Riot Client UX Logs/RiotClient UX Renderer Logs/2020-02-12T08-23-18_620_RiotClientUxHelper-renderer.0.log" "--annotation=2020-02-12T08-23-18_620_RiotClientUxHelper-renderer.log=C:/Users/admin/AppData/Local/Riot Games/Riot Client/Logs/Riot Client UX Logs/RiotClient UX Renderer Logs/2020-02-12T08-23-18_620_RiotClientUxHelper-renderer.log" --initial-client-data=0xf8,0xfc,0x100,0xf0,0x104,0x5a1c751c,0x5a1c752c,0x5a1c753cC:\Riot Games\Riot Client\RiotClientCrashHandler.exeRiotClientUxRender.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\riot games\riot client\riotclientcrashhandler.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1348"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1004,2426818773986262437,14229918162722323741,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5125553192546263396 --renderer-client-id=15 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3724 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1504"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,2426818773986262437,14229918162722323741,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=9412913822033247024 --mojo-platform-channel-handle=4044 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1684"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1004,2426818773986262437,14229918162722323741,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=218294213723246263 --mojo-platform-channel-handle=3668 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1692"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2564 --on-initialized-event-handle=324 --parent-handle=328 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\gdi32.dll
Total events
1 649
Read events
1 533
Write events
111
Delete events
5

Modification events

(PID) Process:(1740) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(1740) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(1740) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(1740) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(1692) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:1740-13225969227121500
Value:
259
(PID) Process:(1740) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(1740) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(1740) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(1740) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3120-13213713943555664
Value:
0
(PID) Process:(1740) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
Executable files
132
Suspicious files
52
Text files
287
Unknown types
7

Dropped files

PID
Process
Filename
Type
1740chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5E43B54B-6CC.pma
MD5:
SHA256:
1740chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\2c09c5ba-5341-43d6-abf8-b27afa2a8426.tmp
MD5:
SHA256:
1740chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000028.dbtmp
MD5:
SHA256:
1740chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.oldtext
MD5:
SHA256:
1740chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old
MD5:
SHA256:
1740chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RFa66c2f.TMPtext
MD5:
SHA256:
1740chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RFa66c20.TMPtext
MD5:
SHA256:
1740chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.oldtext
MD5:
SHA256:
1740chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
MD5:
SHA256:
1740chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RFa66e33.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
80
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3516
chrome.exe
GET
302
172.217.16.206:80
http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOTRmQUFXVHlhaGJaUTdMLWtCSkNJUl9ZQQ/1.0.0.5_nmmhkkegccagdldgiimedpiccmgmieda.crx
US
html
510 b
whitelisted
332
RiotClientServices.exe
GET
200
2.16.186.59:80
http://riot-client.dyn.riotcdn.net/channels/public/x/status/keystonefoundationlive.json
unknown
text
1.36 Kb
whitelisted
3516
chrome.exe
GET
302
172.217.16.206:80
http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx
US
html
515 b
whitelisted
3516
chrome.exe
GET
200
173.194.138.202:80
http://r5---sn-aigzrn7d.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOTRmQUFXVHlhaGJaUTdMLWtCSkNJUl9ZQQ/1.0.0.5_nmmhkkegccagdldgiimedpiccmgmieda.crx?cms_redirect=yes&mip=185.43.110.249&mm=28&mn=sn-aigzrn7d&ms=nvh&mt=1581495742&mv=m&mvi=4&pl=23&shardbypass=yes
US
crx
293 Kb
whitelisted
3516
chrome.exe
GET
200
173.194.138.200:80
http://r3---sn-aigzrn7d.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOWVmQUFXS041NV9ZVXlJVWwxbGc5TUM4dw/7519.422.0.3_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx?cms_redirect=yes&mip=185.43.110.249&mm=28&mn=sn-aigzrn7d&ms=nvh&mt=1581495742&mv=m&mvi=2&pl=23&shardbypass=yes
US
crx
862 Kb
whitelisted
3204
RiotClientUx.exe
GET
200
205.185.216.42:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.4 Kb
whitelisted
3204
RiotClientUx.exe
GET
200
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.4 Kb
whitelisted
3204
RiotClientUx.exe
GET
200
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.4 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3516
chrome.exe
172.217.22.99:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
3516
chrome.exe
2.16.186.59:443
lol.secure.dyn.riotcdn.net
Akamai International B.V.
whitelisted
3516
chrome.exe
172.217.23.164:443
www.google.com
Google Inc.
US
whitelisted
3516
chrome.exe
172.217.23.99:443
ssl.gstatic.com
Google Inc.
US
whitelisted
3516
chrome.exe
172.217.22.14:443
sb-ssl.google.com
Google Inc.
US
whitelisted
3516
chrome.exe
172.217.16.163:443
www.gstatic.com
Google Inc.
US
whitelisted
3604
Install League of Legends na.exe
10.92.69.160:443
collector-aws-or.rdatasrv.net
unknown
3604
Install League of Legends na.exe
104.16.37.99:443
data.riotgames.com
Cloudflare Inc
US
shared
10.92.69.160:443
collector-aws-or.rdatasrv.net
unknown
3604
Install League of Legends na.exe
104.18.157.37:443
clientconfig.rpg.riotgames.com
Cloudflare Inc
US
unknown

DNS requests

Domain
IP
Reputation
clientservices.googleapis.com
  • 172.217.22.99
whitelisted
lol.secure.dyn.riotcdn.net
  • 2.16.186.59
  • 2.16.186.64
  • 104.17.173.5
  • 104.17.174.5
whitelisted
accounts.google.com
  • 172.217.18.13
shared
www.google.com
  • 172.217.23.164
malicious
ssl.gstatic.com
  • 172.217.23.99
whitelisted
sb-ssl.google.com
  • 172.217.22.14
whitelisted
www.gstatic.com
  • 172.217.16.163
whitelisted
data.riotgames.com
  • 104.16.37.99
  • 104.16.36.99
  • 104.16.34.99
  • 104.16.33.99
  • 104.16.35.99
unknown
collector-aws-or.rdatasrv.net
  • 10.92.69.160
  • 10.92.70.15
unknown
clientconfig.rpg.riotgames.com
  • 104.18.157.37
  • 104.18.156.37
unknown

Threats

No threats detected
Process
Message
Install League of Legends na.exe
Install League of Legends na.exe(00000C44): ALWAYS| Generating new machine id
Install League of Legends na.exe
Install League of Legends na.exe(00000C44): ALWAYS| App Root: C:/Users/admin/Downloads
Install League of Legends na.exe
Install League of Legends na.exe(00000C44): WARN| No version found in system.yaml, computing it. Patch version may be inaccurate
Install League of Legends na.exe
Install League of Legends na.exe(00000C44): ALWAYS| Locking mutex file C:/Users/admin/AppData/Local/Riot Games/Install League of Legends na/Config/lockfile_
Install League of Legends na.exe
Install League of Legends na.exe(00000C44): ALWAYS| Launcher Build CL:3008359 - Build Date:Dec 09 2019 - Build Time:12:42:21
Install League of Legends na.exe
Install League of Legends na.exe(00000C44): ALWAYS| Lock file was not detected at C:/Users/admin/AppData/Local/Riot Games/Install League of Legends na/Config/lockfile
Install League of Legends na.exe
Install League of Legends na.exe(00000C44): ALWAYS| Creating config directory C:/Users/admin/AppData/Local/Riot Games/Install League of Legends na/Config
Install League of Legends na.exe
Install League of Legends na.exe(00000C44): ALWAYS| Keeping window hidden.
Install League of Legends na.exe
Install League of Legends na.exe(00000C44): ALWAYS| Centering screen on monitor.
Install League of Legends na.exe
Install League of Legends na.exe(00000C44): ALWAYS| Successfully transitioned to new screen (not draggable).