File name:

GOG_Galaxy_Fallout_LondonOriginal.exe

Full analysis: https://app.any.run/tasks/fdc21db4-78ba-4e5a-a80d-e46887a0a88e
Verdict: Malicious activity
Analysis date: July 31, 2024, 12:45:23
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

E06605ADD3F263DB0E581F5984B3528A

SHA1:

B154135A57D27854828AB91EE81E245251FC9B54

SHA256:

B46FED96041395A9946020503C823379F1AD574F5454E7F0F8FB44223CB999E5

SSDEEP:

24576:Lpe0XOFWw70y1dLf2f5hYqnbMIbDnW7LV7YD4ZH6KcoqEDGV8f69:Lpe0XOFWw70y1dLf2f5hYqnbMIbDnW7m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
    • Drops the executable file immediately after the start

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxySetup.exe (PID: 1168)
      • GalaxySetup.exe (PID: 6516)
      • VC_redist.x86.exe (PID: 1048)
      • VC_redist.x86.exe (PID: 3848)
      • GalaxySetup.tmp (PID: 5904)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.tmp (PID: 5248)
      • VC_redist.x86.exe (PID: 3848)
    • Checks Windows Trust Settings

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
    • Reads the date of Windows installation

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.tmp (PID: 5248)
      • VC_redist.x86.exe (PID: 3848)
    • Executable content was dropped or overwritten

      • GalaxySetup.exe (PID: 1168)
      • GalaxySetup.exe (PID: 6516)
      • GalaxySetup.tmp (PID: 5904)
      • VC_redist.x86.exe (PID: 1048)
      • VC_redist.x86.exe (PID: 3848)
    • Reads the Windows owner or organization settings

      • GalaxySetup.tmp (PID: 5904)
    • Process drops legitimate windows executable

      • GalaxySetup.tmp (PID: 5904)
      • VC_redist.x86.exe (PID: 1048)
      • VC_redist.x86.exe (PID: 3848)
    • Process drops python dynamic module

      • GalaxySetup.tmp (PID: 5904)
    • The process drops C-runtime libraries

      • GalaxySetup.tmp (PID: 5904)
    • Starts a Microsoft application from unusual location

      • VC_redist.x86.exe (PID: 1048)
      • VC_redist.x86.exe (PID: 3848)
      • VC_redist.x86.exe (PID: 5292)
    • Searches for installed software

      • VC_redist.x86.exe (PID: 3848)
      • VC_redist.x86.exe (PID: 5292)
      • dllhost.exe (PID: 4604)
    • Starts itself from another location

      • VC_redist.x86.exe (PID: 3848)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1812)
  • INFO

    • Creates files or folders in the user directory

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
    • Reads the computer name

      • GalaxyInstaller.exe (PID: 7048)
      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxySetup.tmp (PID: 5248)
      • GalaxySetup.tmp (PID: 5904)
      • VC_redist.x86.exe (PID: 3848)
      • VC_redist.x86.exe (PID: 5292)
    • Reads the machine GUID from the registry

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
    • Create files in a temporary directory

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxySetup.exe (PID: 1168)
      • GalaxySetup.exe (PID: 6516)
      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.tmp (PID: 5904)
      • VC_redist.x86.exe (PID: 3848)
    • Reads the software policy settings

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
    • Checks proxy server information

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
    • Creates files in the program directory

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.tmp (PID: 5904)
    • Checks supported languages

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.exe (PID: 1168)
      • GalaxySetup.exe (PID: 6516)
      • GalaxySetup.tmp (PID: 5904)
      • VC_redist.x86.exe (PID: 1048)
      • VC_redist.x86.exe (PID: 5292)
      • VC_redist.x86.exe (PID: 3848)
      • GalaxySetup.tmp (PID: 5248)
    • Process checks computer location settings

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.tmp (PID: 5248)
      • VC_redist.x86.exe (PID: 3848)
    • Reads Environment values

      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.tmp (PID: 5904)
    • Disables trace logs

      • GalaxyInstaller.exe (PID: 7048)
    • Reads product name

      • GalaxyInstaller.exe (PID: 7048)
    • UPX packer has been detected

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (39.5)
.exe | UPX compressed Win32 Executable (38.7)
.dll | Win32 Dynamic Link Library (generic) (9.4)
.exe | Win32 Executable (generic) (6.4)
.exe | Generic Win/DOS Executable (2.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:25 08:18:41+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 368640
InitializedDataSize: 114688
UninitializedDataSize: 663552
EntryPoint: 0xfcc80
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.2
ProductVersionNumber: 2.0.0.2
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: GOG Sp. z o.o.
FileDescription: Fallout: London
FileVersion: 2.0.0.2
LegalCopyright: (C) GOG Sp. z o.o. 2020
InternalName: GOG Galaxy - Game Installer.exe
ProductName: Fallout: London
ProductVersion: 2.0.0.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
11
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
start THREAT gog_galaxy_fallout_londonoriginal.exe galaxyinstaller.exe galaxysetup.exe galaxysetup.tmp no specs galaxysetup.exe galaxysetup.tmp vc_redist.x86.exe vc_redist.x86.exe vc_redist.x86.exe no specs SPPSurrogate no specs vssvc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1048"C:\Users\admin\AppData\Local\Temp\is-6CKVA.tmp\VC_redist.x86.exe" /install /quiet /norestartC:\Users\admin\AppData\Local\Temp\is-6CKVA.tmp\VC_redist.x86.exe
GalaxySetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.40.33810
Version:
14.40.33810.0
Modules
Images
c:\users\admin\appdata\local\temp\is-6ckva.tmp\vc_redist.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1168"C:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe" /lang=en_US /webinstaller /product_id=1491728574 /silent /game_name="Fallout: London"C:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe
GalaxyInstaller.exe
User:
admin
Company:
GOG.com
Integrity Level:
MEDIUM
Description:
GOG GALAXY
Version:
2.0.75.142
Modules
Images
c:\users\admin\appdata\local\temp\galaxyinstaller_gfnwc\galaxysetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1812C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3848"C:\WINDOWS\Temp\{223AB7EA-1479-4A90-8367-9FC7D801C385}\.cr\VC_redist.x86.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\is-6CKVA.tmp\VC_redist.x86.exe" -burn.filehandle.attached=564 -burn.filehandle.self=572 /install /quiet /norestartC:\Windows\Temp\{223AB7EA-1479-4A90-8367-9FC7D801C385}\.cr\VC_redist.x86.exe
VC_redist.x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.40.33810
Version:
14.40.33810.0
Modules
Images
c:\windows\temp\{223ab7ea-1479-4a90-8367-9fc7d801c385}\.cr\vc_redist.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4604C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
5248"C:\Users\admin\AppData\Local\Temp\is-EQSI5.tmp\GalaxySetup.tmp" /SL5="$8027E,283484498,1268224,C:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe" /lang=en_US /webinstaller /product_id=1491728574 /silent /game_name="Fallout: London"C:\Users\admin\AppData\Local\Temp\is-EQSI5.tmp\GalaxySetup.tmpGalaxySetup.exe
User:
admin
Company:
GOG.com
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-eqsi5.tmp\galaxysetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
5292"C:\WINDOWS\Temp\{756FAA5D-DE88-4514-9E29-9A66DE819CFE}\.be\VC_redist.x86.exe" -q -burn.elevated BurnPipe.{8E114BA9-E6C4-4BAA-8166-51C1D3A188DC} {B87321CD-1CBD-436F-88F2-980B80F2FFFB} 3848C:\Windows\Temp\{756FAA5D-DE88-4514-9E29-9A66DE819CFE}\.be\VC_redist.x86.exeVC_redist.x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.40.33810
Version:
14.40.33810.0
Modules
Images
c:\windows\temp\{756faa5d-de88-4514-9e29-9a66de819cfe}\.be\vc_redist.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5904"C:\Users\admin\AppData\Local\Temp\is-VMOHI.tmp\GalaxySetup.tmp" /SL5="$502A6,283484498,1268224,C:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe" /SPAWNWND=$701E2 /NOTIFYWND=$8027E /lang=en_US /webinstaller /product_id=1491728574 /silent /game_name="Fallout: London"C:\Users\admin\AppData\Local\Temp\is-VMOHI.tmp\GalaxySetup.tmp
GalaxySetup.exe
User:
admin
Company:
GOG.com
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-vmohi.tmp\galaxysetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
6516"C:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe" /SPAWNWND=$701E2 /NOTIFYWND=$8027E /lang=en_US /webinstaller /product_id=1491728574 /silent /game_name="Fallout: London"C:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe
GalaxySetup.tmp
User:
admin
Company:
GOG.com
Integrity Level:
HIGH
Description:
GOG GALAXY
Version:
2.0.75.142
Modules
Images
c:\users\admin\appdata\local\temp\galaxyinstaller_gfnwc\galaxysetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6980"C:\Users\admin\AppData\Local\Temp\GOG_Galaxy_Fallout_LondonOriginal.exe" C:\Users\admin\AppData\Local\Temp\GOG_Galaxy_Fallout_LondonOriginal.exe
explorer.exe
User:
admin
Company:
GOG Sp. z o.o.
Integrity Level:
MEDIUM
Description:
Fallout: London
Version:
2.0.0.2
Modules
Images
c:\users\admin\appdata\local\temp\gog_galaxy_fallout_londonoriginal.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
15 273
Read events
15 173
Write events
90
Delete events
10

Modification events

(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7048) GalaxyInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7048) GalaxyInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7048) GalaxyInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
336
Suspicious files
131
Text files
1 265
Unknown types
153

Dropped files

PID
Process
Filename
Type
6980GOG_Galaxy_Fallout_LondonOriginal.exeC:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\payload.base64
MD5:
SHA256:
7048GalaxyInstaller.exeC:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe
MD5:
SHA256:
6980GOG_Galaxy_Fallout_LondonOriginal.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419der
MD5:ED5B30E666DB4662C06179A981E556F1
SHA256:F7ADA27C5D21F1B67B1ED48FB2A06F0E46BC17038F40761EE8E8E469BBC54BAE
6980GOG_Galaxy_Fallout_LondonOriginal.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\1491728574[1].jsonbinary
MD5:6203BF56D374F725105921A5F5382E45
SHA256:1966FEDCAF1FB03C9C419912146B7FE6BE39208B44FB5ADA675E8106987FD920
6980GOG_Galaxy_Fallout_LondonOriginal.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:4F1F76DB48EB8B5AA479163A0C6E02EF
SHA256:C0020E11C2F37C0D27D626931A2C8965A5A2989E1889A36FA217061524099A84
6980GOG_Galaxy_Fallout_LondonOriginal.exeC:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\remoteconfig.jsonbinary
MD5:6203BF56D374F725105921A5F5382E45
SHA256:1966FEDCAF1FB03C9C419912146B7FE6BE39208B44FB5ADA675E8106987FD920
5904GalaxySetup.tmpC:\Users\admin\AppData\Local\Temp\is-6CKVA.tmp\_isetup\_isdecmp.dllexecutable
MD5:077CB4461A2767383B317EB0C50F5F13
SHA256:8287D0E287A66EE78537C8D1D98E426562B95C50F569B92CEA9CE36A9FA57E64
7048GalaxyInstaller.exeC:\ProgramData\GOG.com\Galaxy\logs\InstallerWebinstaller.logtext
MD5:DABD66F123BFC82419845728322347E5
SHA256:F54C2627C999605EA6B5EE4306EAF84A58D81B072256E5DE5A0BA160D19C3B70
6980GOG_Galaxy_Fallout_LondonOriginal.exeC:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\icon.icoimage
MD5:F2BEE83D52C9144D254A0BC9186D249E
SHA256:A47297633273FEF58CA84B476C1F88917AF2F03A66178ED262EBDE219B285D26
5904GalaxySetup.tmpC:\Users\admin\AppData\Local\Temp\is-6CKVA.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
42
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6980
GOG_Galaxy_Fallout_LondonOriginal.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
6272
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6304
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1664
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
3208
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4936
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1664
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5336
SearchApp.exe
92.123.104.4:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6248
backgroundTaskHost.exe
92.123.104.4:443
www.bing.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 172.217.18.110
whitelisted
login.live.com
  • 20.190.159.75
  • 40.126.31.67
  • 20.190.159.2
  • 20.190.159.71
  • 40.126.31.73
  • 40.126.31.69
  • 20.190.159.68
  • 20.190.159.64
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.bing.com
  • 92.123.104.4
  • 92.123.104.67
  • 92.123.104.6
  • 92.123.104.64
  • 92.123.104.66
  • 92.123.104.63
  • 92.123.104.5
  • 92.123.104.7
  • 92.123.104.65
whitelisted
client.wns.windows.com
  • 40.115.3.253
  • 40.113.103.199
whitelisted
remote-config.gog.com
  • 146.75.121.55
whitelisted
content-system.gog.com
  • 146.75.121.55
whitelisted
gog-cdn-fastly.gog.com
  • 146.75.121.55
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info