File name:

itch-setup.exe

Full analysis: https://app.any.run/tasks/9b3ec0f3-330f-4097-86d9-7af9d37237f6
Verdict: Malicious activity
Analysis date: January 11, 2025, 04:08:03
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows, 10 sections
MD5:

574B3D68C7EE68B3AC1BA0B556C3A3AF

SHA1:

B1E421F479FDD55A87AABB3E73CCA72C574306A0

SHA256:

AD9780336BF0E54F8AECE6435F70993EC8C4AC34A3637642C0B542F171A00865

SSDEEP:

98304:kjMBFgStgyD8er+rq1IaOhJVewjhwjlWossyCMrZT1lYzN89xN+hKtbDv/uDZeIw:ZYff

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • butler.exe (PID: 7072)
      • butler.exe (PID: 5604)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
    • Process drops legitimate windows executable

      • itch-setup.exe (PID: 4952)
    • Creates a software uninstall entry

      • itch-setup.exe (PID: 4952)
    • Application launched itself

      • itch.exe (PID: 6404)
    • Starts application with an unusual extension

      • cmd.exe (PID: 6948)
    • Starts CMD.EXE for commands execution

      • itch.exe (PID: 6752)
    • Drops 7-zip archiver for unpacking

      • itch.exe (PID: 6404)
    • Searches for installed software

      • itch-setup.exe (PID: 2012)
  • INFO

    • The sample compiled with english language support

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
    • Create files in a temporary directory

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
      • itch-setup.exe (PID: 6168)
    • Reads the computer name

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
      • itch.exe (PID: 6672)
      • butler.exe (PID: 7072)
      • itch.exe (PID: 6632)
      • itch-setup.exe (PID: 2012)
      • butler.exe (PID: 5604)
    • Checks supported languages

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
      • itch.exe (PID: 6632)
      • itch.exe (PID: 6672)
      • itch.exe (PID: 6752)
      • chcp.com (PID: 7004)
      • butler.exe (PID: 7072)
      • itch-setup.exe (PID: 6168)
      • butler.exe (PID: 5604)
      • itch-setup.exe (PID: 2012)
    • Reads the software policy settings

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
      • itch-setup.exe (PID: 2012)
    • Reads the machine GUID from the registry

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
      • itch-setup.exe (PID: 2012)
    • Creates files or folders in the user directory

      • itch-setup.exe (PID: 4952)
      • itch.exe (PID: 6404)
      • butler.exe (PID: 7072)
      • butler.exe (PID: 5604)
      • itch.exe (PID: 6672)
    • Application based on Golang

      • itch-setup.exe (PID: 4952)
    • Process checks computer location settings

      • itch.exe (PID: 6404)
      • itch.exe (PID: 6752)
    • Reads Environment values

      • itch.exe (PID: 6404)
      • itch.exe (PID: 6752)
    • Reads product name

      • itch.exe (PID: 6404)
      • itch.exe (PID: 6752)
    • Checks proxy server information

      • itch.exe (PID: 6404)
    • Changes the display of characters in the console

      • cmd.exe (PID: 6948)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:12:03 20:42:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, No debug
PEType: PE32+
LinkerVersion: 2.34
CodeSize: 7040512
InitializedDataSize: 16218624
UninitializedDataSize: 242176
EntryPoint: 0x14c0
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (British)
CharacterSet: Windows, Latin1
CompanyName: itch corp.
FileDescription: Installer and self-update helper for the itch app
FileVersion: 1
InternalName: itch-setup
LegalCopyright: itch corp.
OriginalFileName: itch-setup.exe
ProductName: itch-setup
ProductVersion: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
14
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start itch-setup.exe itch.exe itch.exe no specs itch.exe itch.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs butler.exe no specs conhost.exe no specs butler.exe no specs conhost.exe no specs itch-setup.exe no specs itch-setup.exe

Process information

PID
CMD
Path
Indicators
Parent process
2012C:\Users\admin\AppData\Roaming\itch\broth\itch-setup\versions\1.27.0\itch-setup --appname itch --upgradeC:\Users\admin\AppData\Roaming\itch\broth\itch-setup\versions\1.27.0\itch-setup.exe
itch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
Installer and self-update helper for the itch app
Exit code:
0
Version:
1.0
Modules
Images
c:\users\admin\appdata\roaming\itch\broth\itch-setup\versions\1.27.0\itch-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4128\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exebutler.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4952"C:\Users\admin\AppData\Local\Temp\itch-setup.exe" C:\Users\admin\AppData\Local\Temp\itch-setup.exe
explorer.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
Installer and self-update helper for the itch app
Exit code:
0
Version:
1.0
Modules
Images
c:\users\admin\appdata\local\temp\itch-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5604C:\Users\admin\AppData\Roaming\itch\broth\butler\versions\15.24.0\butler --json daemon --transport tcp --keep-alive --dbpath C:\Users\admin\AppData\Roaming\itch\db\butler.db --address https://itch.io/ --user-agent "itch/26.1.9 (win32)" --destiny-pid 6404C:\Users\admin\AppData\Roaming\itch\broth\butler\versions\15.24.0\butler.exeitch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
Helper program for the itch app
Version:
1.0
Modules
Images
c:\users\admin\appdata\roaming\itch\broth\butler\versions\15.24.0\butler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
6168C:\Users\admin\AppData\Roaming\itch\broth\itch-setup\versions\1.27.0\itch-setup --versionC:\Users\admin\AppData\Roaming\itch\broth\itch-setup\versions\1.27.0\itch-setup.exeitch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
Installer and self-update helper for the itch app
Exit code:
0
Version:
1.0
Modules
Images
c:\users\admin\appdata\roaming\itch\broth\itch-setup\versions\1.27.0\itch-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6404C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exeC:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe
itch-setup.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
the itch.io desktop app
Version:
26.1.9
Modules
Images
c:\users\admin\appdata\local\itch\app-26.1.9\itch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6632"C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe" --type=gpu-process --user-data-dir="C:\Users\admin\AppData\Roaming\itch" --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1664 --field-trial-handle=1808,i,6340397221311150823,1546541364587728282,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exeitch.exe
User:
admin
Company:
itch corp.
Integrity Level:
LOW
Description:
the itch.io desktop app
Version:
26.1.9
Modules
Images
c:\users\admin\appdata\local\itch\app-26.1.9\itch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6672"C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\itch" --standard-schemes=itch-cave,itch --secure-schemes=itch-cave,itch --bypasscsp-schemes=itch-cave,itch --cors-schemes=itch-cave,itch --fetch-schemes=itch-cave,itch --service-worker-schemes --streaming-schemes --mojo-platform-channel-handle=1768 --field-trial-handle=1808,i,6340397221311150823,1546541364587728282,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe
itch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
the itch.io desktop app
Version:
26.1.9
Modules
Images
c:\users\admin\appdata\local\itch\app-26.1.9\itch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6752"C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\itch" --standard-schemes=itch-cave,itch --secure-schemes=itch-cave,itch --bypasscsp-schemes=itch-cave,itch --cors-schemes=itch-cave,itch --fetch-schemes=itch-cave,itch --service-worker-schemes --streaming-schemes --app-user-model-id=com.squirrel.itch.itch --app-path="C:\Users\admin\AppData\Local\itch\app-26.1.9\resources\app" --no-sandbox --no-zygote --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2504 --field-trial-handle=1808,i,6340397221311150823,1546541364587728282,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exeitch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
the itch.io desktop app
Version:
26.1.9
Modules
Images
c:\users\admin\appdata\local\itch\app-26.1.9\itch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6948C:\WINDOWS\system32\cmd.exe /d /s /c "chcp"C:\Windows\System32\cmd.exeitch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
Total events
16 831
Read events
16 796
Write events
15
Delete events
20

Modification events

(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:DisplayName
Value:
itch
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:DisplayVersion
Value:
26.1.9
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:InstallDate
Value:
20250111
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\itch
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:Publisher
Value:
itch corp.
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Local\itch\itch-setup.exe" --appname itch --uninstall
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\itch\itch-setup.exe" --appname itch --uninstall
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:URLUpdateInfo
Value:
https://itch.io/app
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\itch\app.ico
(PID) Process:(4952) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:EstimatedSize
Value:
258411
Executable files
11
Suspicious files
333
Text files
45
Unknown types
0

Dropped files

PID
Process
Filename
Type
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\LICENSES.chromium.html
MD5:
SHA256:
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\icudtl.dat
MD5:
SHA256:
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\itch.exe
MD5:
SHA256:
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\LICENSEtext
MD5:4D42118D35941E0F664DDDBD83F633C5
SHA256:5154E165BD6C2CC0CFBCD8916498C7ABAB0497923BAFCD5CB07673FE8480087D
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\.write-testtext
MD5:4782368B344E1DB633B24349E27FEF83
SHA256:2C669F3D437E9D6C2B1A193FD0DAD2B9133DE79D323BE5593944B9EEA37D0A51
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\chrome_100_percent.pakbinary
MD5:D31F3439E2A3F7BEE4DDD26F46A2B83F
SHA256:9F79F46CA911543EAD096A5EE28A34BF1FBE56EC9BA956032A6A2892B254857E
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\ffmpeg.dllexecutable
MD5:00FFABBB9438A0DA15A021451A9C2D0D
SHA256:AAD7E7AC9D74AC18892801950C9728E9C4EACD3B676CBB5D6F63382DA2CE0559
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\locales\ca.pakbinary
MD5:2F8D050C228583559CDA181291B76E5A
SHA256:E1D6B5FD0BC411F2895EAAA1409916F5FFE39A5C6BD1BAFE8AF7CE33DA5BE17D
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\locales\ar.pakbinary
MD5:98F8A48892B41E64BEF135B86F3D4A6C
SHA256:E34D5CABAED4634C672591074057C12947BC9E728004228A9E75F87829F4A48A
4952itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\libGLESv2.dllexecutable
MD5:60E42E83B260582FC96AAF43293D99E1
SHA256:25D49934FC220B169CADEB21FC99DC2A8FB1DD5A4F244265799392F0F5F2F8F8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
40
DNS requests
20
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4328
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4328
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6116
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4328
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4328
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
104.126.37.145:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4952
itch-setup.exe
104.21.12.135:443
broth.itch.zone
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 216.58.206.46
whitelisted
www.bing.com
  • 104.126.37.145
  • 104.126.37.163
  • 104.126.37.130
  • 104.126.37.178
  • 104.126.37.131
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
broth.itch.zone
  • 104.21.12.135
  • 172.67.132.40
unknown
login.live.com
  • 40.126.32.72
  • 20.190.160.20
  • 40.126.32.134
  • 40.126.32.136
  • 20.190.160.14
  • 40.126.32.74
  • 20.190.160.22
  • 20.190.160.17
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
itchio-mirror.cb031a832f44726753d6267436f3b414.r2.cloudflarestorage.com
  • 172.66.1.46
  • 162.159.141.50
unknown

Threats

PID
Process
Class
Message
4952
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
4952
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare R2 Storage (r2 .cloudflarestorage .com)
4952
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
4952
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare R2 Storage (r2 .cloudflarestorage .com)
2012
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
No debug info