File name:

itch-setup.exe

Full analysis: https://app.any.run/tasks/ebbf5530-b7c9-49a4-92e9-1f3c8bf4d934
Verdict: Malicious activity
Analysis date: January 11, 2025, 04:36:20
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
golang
arch-exec
nodejs
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows, 10 sections
MD5:

574B3D68C7EE68B3AC1BA0B556C3A3AF

SHA1:

B1E421F479FDD55A87AABB3E73CCA72C574306A0

SHA256:

AD9780336BF0E54F8AECE6435F70993EC8C4AC34A3637642C0B542F171A00865

SSDEEP:

98304:kjMBFgStgyD8er+rq1IaOhJVewjhwjlWossyCMrZT1lYzN89xN+hKtbDv/uDZeIw:ZYff

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • butler.exe (PID: 3820)
      • butler.exe (PID: 6624)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • itch-setup.exe (PID: 6476)
    • Executable content was dropped or overwritten

      • itch-setup.exe (PID: 6476)
      • itch.exe (PID: 7096)
    • Creates a software uninstall entry

      • itch-setup.exe (PID: 6476)
    • Application launched itself

      • itch.exe (PID: 7096)
    • Starts CMD.EXE for commands execution

      • itch.exe (PID: 5652)
    • Starts application with an unusual extension

      • cmd.exe (PID: 3060)
    • Drops 7-zip archiver for unpacking

      • itch.exe (PID: 7096)
    • Searches for installed software

      • itch-setup.exe (PID: 6808)
  • INFO

    • Create files in a temporary directory

      • itch-setup.exe (PID: 6476)
      • itch.exe (PID: 7096)
      • itch-setup.exe (PID: 6592)
    • The sample compiled with english language support

      • itch-setup.exe (PID: 6476)
      • itch.exe (PID: 7096)
    • Reads the machine GUID from the registry

      • itch-setup.exe (PID: 6476)
      • itch.exe (PID: 7096)
      • butler.exe (PID: 6624)
      • itch-setup.exe (PID: 6808)
      • itch.exe (PID: 5980)
    • Reads the software policy settings

      • itch-setup.exe (PID: 6476)
      • itch.exe (PID: 7096)
      • itch-setup.exe (PID: 6808)
      • butler.exe (PID: 6624)
    • Application based on Golang

      • itch-setup.exe (PID: 6476)
    • Reads the computer name

      • itch-setup.exe (PID: 6476)
      • itch.exe (PID: 7096)
      • itch.exe (PID: 6336)
      • itch.exe (PID: 3836)
      • butler.exe (PID: 3820)
      • butler.exe (PID: 6624)
      • itch-setup.exe (PID: 6808)
      • itch.exe (PID: 5980)
    • Creates files or folders in the user directory

      • itch-setup.exe (PID: 6476)
      • itch.exe (PID: 7096)
      • butler.exe (PID: 6624)
      • itch.exe (PID: 3836)
      • butler.exe (PID: 3820)
      • itch.exe (PID: 5980)
    • Checks supported languages

      • itch-setup.exe (PID: 6476)
      • itch.exe (PID: 7096)
      • itch.exe (PID: 6336)
      • itch.exe (PID: 3836)
      • itch.exe (PID: 5652)
      • chcp.com (PID: 5252)
      • butler.exe (PID: 3820)
      • butler.exe (PID: 6624)
      • itch-setup.exe (PID: 6592)
      • itch-setup.exe (PID: 6808)
      • itch.exe (PID: 6952)
      • itch.exe (PID: 3032)
      • itch.exe (PID: 5980)
      • itch.exe (PID: 1512)
    • Process checks computer location settings

      • itch.exe (PID: 7096)
      • itch.exe (PID: 5652)
      • itch.exe (PID: 1512)
      • itch.exe (PID: 6952)
      • itch.exe (PID: 3032)
    • Reads product name

      • itch.exe (PID: 7096)
      • itch.exe (PID: 5652)
    • Reads Environment values

      • itch.exe (PID: 7096)
      • itch.exe (PID: 5652)
    • Checks proxy server information

      • itch.exe (PID: 7096)
    • Changes the display of characters in the console

      • cmd.exe (PID: 3060)
    • Node.js compiler has been detected

      • itch.exe (PID: 7096)
      • itch.exe (PID: 6336)
      • itch.exe (PID: 3836)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:12:03 20:42:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, No debug
PEType: PE32+
LinkerVersion: 2.34
CodeSize: 7040512
InitializedDataSize: 16218624
UninitializedDataSize: 242176
EntryPoint: 0x14c0
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (British)
CharacterSet: Windows, Latin1
CompanyName: itch corp.
FileDescription: Installer and self-update helper for the itch app
FileVersion: 1
InternalName: itch-setup
LegalCopyright: itch corp.
OriginalFileName: itch-setup.exe
ProductName: itch-setup
ProductVersion: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
19
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start itch-setup.exe itch.exe itch.exe no specs itch.exe itch.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs butler.exe no specs conhost.exe no specs butler.exe conhost.exe no specs itch-setup.exe no specs itch-setup.exe itch.exe no specs itch.exe no specs itch.exe no specs itch.exe no specs itch.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1512"C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\itch" --standard-schemes=itch-cave,itch --secure-schemes=itch-cave,itch --bypasscsp-schemes=itch-cave,itch --cors-schemes=itch-cave,itch --fetch-schemes=itch-cave,itch --service-worker-schemes --streaming-schemes --app-user-model-id=com.squirrel.itch.itch --app-path="C:\Users\admin\AppData\Local\itch\app-26.1.9\resources\app" --enable-sandbox --enable-blink-features --disable-blink-features --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3584 --field-trial-handle=1816,i,7034999335433858628,7305760760850125347,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exeitch.exe
User:
admin
Company:
itch corp.
Integrity Level:
LOW
Description:
the itch.io desktop app
Exit code:
0
Version:
26.1.9
Modules
Images
c:\users\admin\appdata\local\itch\app-26.1.9\itch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3032"C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\itch" --standard-schemes=itch-cave,itch --secure-schemes=itch-cave,itch --bypasscsp-schemes=itch-cave,itch --cors-schemes=itch-cave,itch --fetch-schemes=itch-cave,itch --service-worker-schemes --streaming-schemes --app-user-model-id=com.squirrel.itch.itch --app-path="C:\Users\admin\AppData\Local\itch\app-26.1.9\resources\app" --enable-sandbox --enable-blink-features --disable-blink-features --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=3924 --field-trial-handle=1816,i,7034999335433858628,7305760760850125347,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exeitch.exe
User:
admin
Company:
itch corp.
Integrity Level:
LOW
Description:
the itch.io desktop app
Version:
26.1.9
Modules
Images
c:\users\admin\appdata\local\itch\app-26.1.9\itch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3060C:\WINDOWS\system32\cmd.exe /d /s /c "chcp"C:\Windows\System32\cmd.exeitch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
3420\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3820C:\Users\admin\AppData\Roaming\itch\broth\butler\versions\15.24.0\butler --json daemon --transport tcp --keep-alive --dbpath C:\Users\admin\AppData\Roaming\itch\db\butler.db --address https://itch.io/ --user-agent "itch/26.1.9 (win32)" --destiny-pid 7096C:\Users\admin\AppData\Roaming\itch\broth\butler\versions\15.24.0\butler.exeitch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
Helper program for the itch app
Exit code:
1
Version:
1.0
Modules
Images
c:\users\admin\appdata\roaming\itch\broth\butler\versions\15.24.0\butler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
3832\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exebutler.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3836"C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\itch" --standard-schemes=itch-cave,itch --secure-schemes=itch-cave,itch --bypasscsp-schemes=itch-cave,itch --cors-schemes=itch-cave,itch --fetch-schemes=itch-cave,itch --service-worker-schemes --streaming-schemes --mojo-platform-channel-handle=2028 --field-trial-handle=1816,i,7034999335433858628,7305760760850125347,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe
itch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
the itch.io desktop app
Version:
26.1.9
Modules
Images
c:\users\admin\appdata\local\itch\app-26.1.9\itch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5252chcpC:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
5652"C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\itch" --standard-schemes=itch-cave,itch --secure-schemes=itch-cave,itch --bypasscsp-schemes=itch-cave,itch --cors-schemes=itch-cave,itch --fetch-schemes=itch-cave,itch --service-worker-schemes --streaming-schemes --app-user-model-id=com.squirrel.itch.itch --app-path="C:\Users\admin\AppData\Local\itch\app-26.1.9\resources\app" --no-sandbox --no-zygote --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --mojo-platform-channel-handle=2572 --field-trial-handle=1816,i,7034999335433858628,7305760760850125347,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exeitch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
the itch.io desktop app
Version:
26.1.9
Modules
Images
c:\users\admin\appdata\local\itch\app-26.1.9\itch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5980"C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --user-data-dir="C:\Users\admin\AppData\Roaming\itch" --gpu-preferences=UAAAAAAAAADoAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAACQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=2116 --field-trial-handle=1816,i,7034999335433858628,7305760760850125347,131072 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2C:\Users\admin\AppData\Local\itch\app-26.1.9\itch.exeitch.exe
User:
admin
Company:
itch corp.
Integrity Level:
MEDIUM
Description:
the itch.io desktop app
Exit code:
0
Version:
26.1.9
Modules
Images
c:\users\admin\appdata\local\itch\app-26.1.9\itch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
23 432
Read events
23 397
Write events
15
Delete events
20

Modification events

(PID) Process:(6476) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:DisplayName
Value:
itch
(PID) Process:(6476) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:DisplayVersion
Value:
26.1.9
(PID) Process:(6476) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:InstallDate
Value:
20250111
(PID) Process:(6476) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\itch
(PID) Process:(6476) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:Publisher
Value:
itch corp.
(PID) Process:(6476) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Local\itch\itch-setup.exe" --appname itch --uninstall
(PID) Process:(6476) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\itch\itch-setup.exe" --appname itch --uninstall
(PID) Process:(6476) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:URLUpdateInfo
Value:
https://itch.io/app
(PID) Process:(6476) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\itch\app.ico
(PID) Process:(6476) itch-setup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itch
Operation:writeName:EstimatedSize
Value:
258411
Executable files
11
Suspicious files
1 923
Text files
55
Unknown types
19

Dropped files

PID
Process
Filename
Type
6476itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\LICENSES.chromium.html
MD5:
SHA256:
6476itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\icudtl.dat
MD5:
SHA256:
6476itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\itch.exe
MD5:
SHA256:
6476itch-setup.exeC:\Users\admin\AppData\Local\itch\.write-testtext
MD5:4782368B344E1DB633B24349E27FEF83
SHA256:2C669F3D437E9D6C2B1A193FD0DAD2B9133DE79D323BE5593944B9EEA37D0A51
6476itch-setup.exeC:\Users\admin\AppData\Local\Temp\img559135867image
MD5:EF26C3A82280D3266280C9455F1A9DC3
SHA256:D3863478D66DB0CF5B68442B092DE15158D562EF970F9B59F841161E965FE34B
6476itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\locales\da.pakbinary
MD5:FECABF71853BAB84EACDD95699C49F69
SHA256:1B0793B1CBEB6A56FF1E64523C37BA753457320AA29F9718022CAA07B4981D8F
6476itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\ffmpeg.dllexecutable
MD5:00FFABBB9438A0DA15A021451A9C2D0D
SHA256:AAD7E7AC9D74AC18892801950C9728E9C4EACD3B676CBB5D6F63382DA2CE0559
6476itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\libEGL.dllexecutable
MD5:EF4291ACE01485EE773183EE3C1ED5C4
SHA256:85F238FB7ACE3CBDF7C29C72B01307C440F13491B07A509CBC5B9F257A637164
6476itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\chrome_100_percent.pakbinary
MD5:D31F3439E2A3F7BEE4DDD26F46A2B83F
SHA256:9F79F46CA911543EAD096A5EE28A34BF1FBE56EC9BA956032A6A2892B254857E
6476itch-setup.exeC:\Users\admin\AppData\Local\itch\staging\app-26.1.9\locales\ar.pakbinary
MD5:98F8A48892B41E64BEF135B86F3D4A6C
SHA256:E34D5CABAED4634C672591074057C12947BC9E728004228A9E75F87829F4A48A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
90
DNS requests
42
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3700
svchost.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
3700
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6200
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6904
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6904
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
4
System
192.168.100.255:137
unknown
4712
MoUsoCoreWorker.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
unknown
3700
svchost.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
unknown
4712
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
3700
svchost.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5064
SearchApp.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
unknown
4
System
192.168.100.255:138
unknown
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1176
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
unknown
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.72
unknown
www.microsoft.com
  • 2.23.246.101
unknown
google.com
  • 142.250.186.142
unknown
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown
login.live.com
  • 40.126.31.67
  • 20.190.159.71
  • 20.190.159.4
  • 40.126.31.71
  • 20.190.159.75
  • 40.126.31.69
  • 20.190.159.23
  • 40.126.31.73
unknown
go.microsoft.com
  • 2.23.242.9
unknown
broth.itch.zone
  • 104.21.12.135
  • 172.67.132.40
unknown
itchio-mirror.cb031a832f44726753d6267436f3b414.r2.cloudflarestorage.com
  • 162.159.141.50
  • 172.66.1.46
unknown

Threats

PID
Process
Class
Message
6476
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare R2 Storage (r2 .cloudflarestorage .com)
6476
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
6476
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
6476
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
2192
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare R2 Storage (r2 .cloudflarestorage .com)
6808
itch-setup.exe
Potentially Bad Traffic
ET JA3 Hash - Possible Rclone Client Response (Mega Storage)
No debug info