File name:

itch-setup.exe

Full analysis: https://app.any.run/tasks/9b3ec0f3-330f-4097-86d9-7af9d37237f6
Verdict: Malicious activity
Analysis date: January 11, 2025, 04:08:03
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows, 10 sections
MD5:

574B3D68C7EE68B3AC1BA0B556C3A3AF

SHA1:

B1E421F479FDD55A87AABB3E73CCA72C574306A0

SHA256:

AD9780336BF0E54F8AECE6435F70993EC8C4AC34A3637642C0B542F171A00865

SSDEEP:

98304:kjMBFgStgyD8er+rq1IaOhJVewjhwjlWossyCMrZT1lYzN89xN+hKtbDv/uDZeIw:ZYff

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • butler.exe (PID: 7072)
      • butler.exe (PID: 5604)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
    • Process drops legitimate windows executable

      • itch-setup.exe (PID: 4952)
    • Creates a software uninstall entry

      • itch-setup.exe (PID: 4952)
    • Application launched itself

      • itch.exe (PID: 6404)
    • Starts CMD.EXE for commands execution

      • itch.exe (PID: 6752)
    • Starts application with an unusual extension

      • cmd.exe (PID: 6948)
    • Drops 7-zip archiver for unpacking

      • itch.exe (PID: 6404)
    • Searches for installed software

      • itch-setup.exe (PID: 2012)
  • INFO

    • Checks supported languages

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
      • itch.exe (PID: 6632)
      • itch.exe (PID: 6672)
      • itch.exe (PID: 6752)
      • chcp.com (PID: 7004)
      • butler.exe (PID: 7072)
      • butler.exe (PID: 5604)
      • itch-setup.exe (PID: 6168)
      • itch-setup.exe (PID: 2012)
    • Reads the software policy settings

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
      • itch-setup.exe (PID: 2012)
    • Create files in a temporary directory

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
      • itch-setup.exe (PID: 6168)
    • Reads the machine GUID from the registry

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
      • itch-setup.exe (PID: 2012)
    • Reads the computer name

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
      • itch.exe (PID: 6632)
      • itch.exe (PID: 6672)
      • butler.exe (PID: 7072)
      • butler.exe (PID: 5604)
      • itch-setup.exe (PID: 2012)
    • Creates files or folders in the user directory

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
      • butler.exe (PID: 7072)
      • butler.exe (PID: 5604)
      • itch.exe (PID: 6672)
    • Reads product name

      • itch.exe (PID: 6404)
      • itch.exe (PID: 6752)
    • Reads Environment values

      • itch.exe (PID: 6404)
      • itch.exe (PID: 6752)
    • Application based on Golang

      • itch-setup.exe (PID: 4952)
    • Checks proxy server information

      • itch.exe (PID: 6404)
    • The sample compiled with english language support

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
    • Process checks computer location settings

      • itch.exe (PID: 6404)
      • itch.exe (PID: 6752)
    • Changes the display of characters in the console

      • cmd.exe (PID: 6948)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:12:03 20:42:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, No debug
PEType: PE32+
LinkerVersion: 2.34
CodeSize: 7040512
InitializedDataSize: 16218624
UninitializedDataSize: 242176
EntryPoint: 0x14c0
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (British)
CharacterSet: Windows, Latin1
CompanyName: itch corp.
FileDescription: Installer and self-update helper for the itch app
FileVersion: 1
InternalName: itch-setup
LegalCopyright: itch corp.
OriginalFileName: itch-setup.exe
ProductName: itch-setup
ProductVersion: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
14
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start itch-setup.exe itch.exe itch.exe no specs itch.exe itch.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs butler.exe no specs conhost.exe no specs butler.exe no specs conhost.exe no specs itch-setup.exe no specs itch-setup.exe

Process information

PID
CMD
Path
Indicators
Parent process
2012C:\Users\admin\AppData\Roaming\itch\broth\itch-setup\versions\1.27.0\itch-setup --appname itch --upgradeC:\Users\admin\AppData\Roaming\itch\broth\itch-setup\versions\1.27.0\itch-setup.exe
itch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
Installer and self-update helper for the itch app
Exit code:
0
Version:
1.0
Modules
Images
c:\users\admin\appdata\roaming\itch\broth\itch-setup\versions\1.27.0\itch-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4128\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exebutler.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4952"C:\Users\admin\AppData\Local\Temp\itch-setup.exe" C:\Users\admin\AppData\Local\Temp\itch-setup.exe
explorer.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
Installer and self-update helper for the itch app
Exit code:
0
Version:
1.0
Modules
Images
c:\users\admin\appdata\local\temp\itch-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5604C:\Users\admin\AppData\Roaming\itch\broth\butler\versions\15.24.0\butler --json daemon --transport tcp --keep-alive --dbpath C:\Users\admin\AppData\Roaming\itch\db\butler.db --address https://itch.io/ --user-agent "itch/26.1.9 (win32)" --destiny-pid 6404C:\Users\admin\AppData\Roaming\itch\broth\butler\versions\15.24.0\butler.exeitch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
Helper program for the itch app
Version:
1.0
Modules
Images
c:\users\admin\appdata\roaming\itch\broth\butler\versions\15.24.0\butler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
6168C:\Users\admin\AppData\Roaming\itch\broth\itch-setup\versions\1.27.0\itch-setup --versionC:\Users\admin\AppData\Roaming\itch\broth\itch-setup\versions\1.27.0\itch-setup.exeitch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
Installer and self-update helper for the itch app
Exit code:
0
Version:
1.0
Modules
Images
c:\users\admin\appdata\roaming\itch\broth\itch-setup\versions\1.27.0\itch-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6404C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exeC:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe
itch-setup.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
the itch.io desktop app
Version:
26.1.9
Modules
Images
c:\users\admin\appdata\local\itch\app-26.1.9\itch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6632"C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe" --type=gpu-process --user-data-dir="C:\Users\admin\AppData\Roaming\itch" --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1664 --field-trial-handle=1808,i,6340397221311150823,1546541364587728282,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exeitch.exe
User:
admin
Company:
itch corp.
Integrity Level:
LOW
Description:
the itch.io desktop app
Version:
26.1.9
Modules
Images
c:\users\admin\appdata\local\itch\app-26.1.9\itch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6672"C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\itch" --standard-schemes=itch-cave,itch --secure-schemes=itch-cave,itch --bypasscsp-schemes=itch-cave,itch --cors-schemes=itch-cave,itch --fetch-schemes=itch-cave,itch --service-worker-schemes --streaming-schemes --mojo-platform-channel-handle=1768 --field-trial-handle=1808,i,6340397221311150823,1546541364587728282,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe
itch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
the itch.io desktop app
Version:
26.1.9
Modules
Images
c:\users\admin\appdata\local\itch\app-26.1.9\itch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6752"C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\itch" --standard-schemes=itch-cave,itch --secure-schemes=itch-cave,itch --bypasscsp-schemes=itch-cave,itch --cors-schemes=itch-cave,itch --fetch-schemes=itch-cave,itch --service-worker-schemes --streaming-schemes --app-user-model-id=com.squirrel.itch.itch --app-path="C:\Users\admin\AppData\Local\itch\app-26.1.9\resources\app" --no-sandbox --no-zygote --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2504 --field-trial-handle=1808,i,6340397221311150823,1546541364587728282,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exeitch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
the itch.io desktop app
Version:
26.1.9
Modules
Images
c:\users\admin\appdata\local\itch\app-26.1.9\itch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6948C:\WINDOWS\system32\cmd.exe /d /s /c "chcp"C:\Windows\System32\cmd.exeitch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
Total events
16 831
Read events
16 796
Write events
15
Delete events
20

Modification events

(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:DisplayName
Value:
itch
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:DisplayVersion
Value:
26.1.9
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:InstallDate
Value:
20250111
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\itch
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:Publisher
Value:
itch corp.
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Local\itch\itch-setup.exe" --appname itch --uninstall
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\itch\itch-setup.exe" --appname itch --uninstall
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:URLUpdateInfo
Value:
https://itch.io/app
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\itch\app.ico
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:EstimatedSize
Value:
258411
Executable files
11
Suspicious files
333
Text files
45
Unknown types
0

Dropped files

PID
Process
Filename
Type
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\LICENSES.chromium.html
MD5:
SHA256:
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\icudtl.dat
MD5:
SHA256:
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\itch.exe
MD5:
SHA256:
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\chrome_100_percent.pakbinary
MD5:D31F3439E2A3F7BEE4DDD26F46A2B83F
SHA256:9F79F46CA911543EAD096A5EE28A34BF1FBE56EC9BA956032A6A2892B254857E
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\LICENSEtext
MD5:4D42118D35941E0F664DDDBD83F633C5
SHA256:5154E165BD6C2CC0CFBCD8916498C7ABAB0497923BAFCD5CB07673FE8480087D
4952itch-setup.exeC:\Users\admin\AppData\Local\Temp\img126998807image
MD5:EF26C3A82280D3266280C9455F1A9DC3
SHA256:D3863478D66DB0CF5B68442B092DE15158D562EF970F9B59F841161E965FE34B
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\locales\af.pakbinary
MD5:198092A7A82EFCED4D59715BD3E41703
SHA256:D63222C4A20FA9741F5262634CF9751F22FBB4FCD9D3138D7C8D49E0EFB57FBA
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\ffmpeg.dllexecutable
MD5:00FFABBB9438A0DA15A021451A9C2D0D
SHA256:AAD7E7AC9D74AC18892801950C9728E9C4EACD3B676CBB5D6F63382DA2CE0559
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\libEGL.dllexecutable
MD5:EF4291ACE01485EE773183EE3C1ED5C4
SHA256:85F238FB7ACE3CBDF7C29C72B01307C440F13491B07A509CBC5B9F257A637164
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\chrome_200_percent.pakbinary
MD5:5604B67E3F03AB2741F910A250C91137
SHA256:1408387E87CB5308530DEF6CE57BDC4E0ABBBAA9E70F687FD6C3A02A56A0536C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
40
DNS requests
20
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4328
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6116
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4328
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4328
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4328
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
104.126.37.145:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4952
itch-setup.exe
104.21.12.135:443
broth.itch.zone
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 216.58.206.46
whitelisted
www.bing.com
  • 104.126.37.145
  • 104.126.37.163
  • 104.126.37.130
  • 104.126.37.178
  • 104.126.37.131
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
broth.itch.zone
  • 104.21.12.135
  • 172.67.132.40
unknown
login.live.com
  • 40.126.32.72
  • 20.190.160.20
  • 40.126.32.134
  • 40.126.32.136
  • 20.190.160.14
  • 40.126.32.74
  • 20.190.160.22
  • 20.190.160.17
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
itchio-mirror.cb031a832f44726753d6267436f3b414.r2.cloudflarestorage.com
  • 172.66.1.46
  • 162.159.141.50
unknown

Threats

PID
Process
Class
Message
4952
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
4952
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare R2 Storage (r2 .cloudflarestorage .com)
4952
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
4952
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare R2 Storage (r2 .cloudflarestorage .com)
2012
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
No debug info