File name:

GOG_Galaxy_Fallout_LondonOriginal.exe

Full analysis: https://app.any.run/tasks/fdc21db4-78ba-4e5a-a80d-e46887a0a88e
Verdict: Malicious activity
Analysis date: July 31, 2024, 12:45:23
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

E06605ADD3F263DB0E581F5984B3528A

SHA1:

B154135A57D27854828AB91EE81E245251FC9B54

SHA256:

B46FED96041395A9946020503C823379F1AD574F5454E7F0F8FB44223CB999E5

SSDEEP:

24576:Lpe0XOFWw70y1dLf2f5hYqnbMIbDnW7LV7YD4ZH6KcoqEDGV8f69:Lpe0XOFWw70y1dLf2f5hYqnbMIbDnW7m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxySetup.exe (PID: 6516)
      • GalaxySetup.exe (PID: 1168)
      • VC_redist.x86.exe (PID: 1048)
      • VC_redist.x86.exe (PID: 3848)
      • GalaxySetup.tmp (PID: 5904)
    • Scans artifacts that could help determine the target

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
    • Reads security settings of Internet Explorer

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.tmp (PID: 5248)
      • VC_redist.x86.exe (PID: 3848)
    • Reads the date of Windows installation

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.tmp (PID: 5248)
      • VC_redist.x86.exe (PID: 3848)
    • Executable content was dropped or overwritten

      • GalaxySetup.exe (PID: 1168)
      • GalaxySetup.exe (PID: 6516)
      • GalaxySetup.tmp (PID: 5904)
      • VC_redist.x86.exe (PID: 3848)
      • VC_redist.x86.exe (PID: 1048)
    • Reads the Windows owner or organization settings

      • GalaxySetup.tmp (PID: 5904)
    • Process drops legitimate windows executable

      • GalaxySetup.tmp (PID: 5904)
      • VC_redist.x86.exe (PID: 1048)
      • VC_redist.x86.exe (PID: 3848)
    • Process drops python dynamic module

      • GalaxySetup.tmp (PID: 5904)
    • The process drops C-runtime libraries

      • GalaxySetup.tmp (PID: 5904)
    • Starts a Microsoft application from unusual location

      • VC_redist.x86.exe (PID: 1048)
      • VC_redist.x86.exe (PID: 3848)
      • VC_redist.x86.exe (PID: 5292)
    • Searches for installed software

      • VC_redist.x86.exe (PID: 3848)
      • VC_redist.x86.exe (PID: 5292)
      • dllhost.exe (PID: 4604)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1812)
    • Starts itself from another location

      • VC_redist.x86.exe (PID: 3848)
  • INFO

    • Creates files in the program directory

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.tmp (PID: 5904)
    • Reads the computer name

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.tmp (PID: 5904)
      • GalaxySetup.tmp (PID: 5248)
      • VC_redist.x86.exe (PID: 3848)
      • VC_redist.x86.exe (PID: 5292)
    • Checks proxy server information

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
    • Reads the machine GUID from the registry

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
    • Creates files or folders in the user directory

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
    • Reads the software policy settings

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
    • Checks supported languages

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.exe (PID: 1168)
      • GalaxySetup.tmp (PID: 5904)
      • GalaxySetup.exe (PID: 6516)
      • GalaxySetup.tmp (PID: 5248)
      • VC_redist.x86.exe (PID: 1048)
      • VC_redist.x86.exe (PID: 3848)
      • VC_redist.x86.exe (PID: 5292)
    • Process checks computer location settings

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.tmp (PID: 5248)
      • VC_redist.x86.exe (PID: 3848)
    • Create files in a temporary directory

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.exe (PID: 1168)
      • GalaxySetup.exe (PID: 6516)
      • GalaxySetup.tmp (PID: 5904)
      • VC_redist.x86.exe (PID: 3848)
    • Reads product name

      • GalaxyInstaller.exe (PID: 7048)
    • UPX packer has been detected

      • GOG_Galaxy_Fallout_LondonOriginal.exe (PID: 6980)
    • Disables trace logs

      • GalaxyInstaller.exe (PID: 7048)
    • Reads Environment values

      • GalaxyInstaller.exe (PID: 7048)
      • GalaxySetup.tmp (PID: 5904)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (39.5)
.exe | UPX compressed Win32 Executable (38.7)
.dll | Win32 Dynamic Link Library (generic) (9.4)
.exe | Win32 Executable (generic) (6.4)
.exe | Generic Win/DOS Executable (2.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:25 08:18:41+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 368640
InitializedDataSize: 114688
UninitializedDataSize: 663552
EntryPoint: 0xfcc80
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.2
ProductVersionNumber: 2.0.0.2
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: GOG Sp. z o.o.
FileDescription: Fallout: London
FileVersion: 2.0.0.2
LegalCopyright: (C) GOG Sp. z o.o. 2020
InternalName: GOG Galaxy - Game Installer.exe
ProductName: Fallout: London
ProductVersion: 2.0.0.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
11
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
start THREAT gog_galaxy_fallout_londonoriginal.exe galaxyinstaller.exe galaxysetup.exe galaxysetup.tmp no specs galaxysetup.exe galaxysetup.tmp vc_redist.x86.exe vc_redist.x86.exe vc_redist.x86.exe no specs SPPSurrogate no specs vssvc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1048"C:\Users\admin\AppData\Local\Temp\is-6CKVA.tmp\VC_redist.x86.exe" /install /quiet /norestartC:\Users\admin\AppData\Local\Temp\is-6CKVA.tmp\VC_redist.x86.exe
GalaxySetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.40.33810
Version:
14.40.33810.0
Modules
Images
c:\users\admin\appdata\local\temp\is-6ckva.tmp\vc_redist.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1168"C:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe" /lang=en_US /webinstaller /product_id=1491728574 /silent /game_name="Fallout: London"C:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe
GalaxyInstaller.exe
User:
admin
Company:
GOG.com
Integrity Level:
MEDIUM
Description:
GOG GALAXY
Version:
2.0.75.142
Modules
Images
c:\users\admin\appdata\local\temp\galaxyinstaller_gfnwc\galaxysetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1812C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3848"C:\WINDOWS\Temp\{223AB7EA-1479-4A90-8367-9FC7D801C385}\.cr\VC_redist.x86.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\is-6CKVA.tmp\VC_redist.x86.exe" -burn.filehandle.attached=564 -burn.filehandle.self=572 /install /quiet /norestartC:\Windows\Temp\{223AB7EA-1479-4A90-8367-9FC7D801C385}\.cr\VC_redist.x86.exe
VC_redist.x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.40.33810
Version:
14.40.33810.0
Modules
Images
c:\windows\temp\{223ab7ea-1479-4a90-8367-9fc7d801c385}\.cr\vc_redist.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4604C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
5248"C:\Users\admin\AppData\Local\Temp\is-EQSI5.tmp\GalaxySetup.tmp" /SL5="$8027E,283484498,1268224,C:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe" /lang=en_US /webinstaller /product_id=1491728574 /silent /game_name="Fallout: London"C:\Users\admin\AppData\Local\Temp\is-EQSI5.tmp\GalaxySetup.tmpGalaxySetup.exe
User:
admin
Company:
GOG.com
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-eqsi5.tmp\galaxysetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
5292"C:\WINDOWS\Temp\{756FAA5D-DE88-4514-9E29-9A66DE819CFE}\.be\VC_redist.x86.exe" -q -burn.elevated BurnPipe.{8E114BA9-E6C4-4BAA-8166-51C1D3A188DC} {B87321CD-1CBD-436F-88F2-980B80F2FFFB} 3848C:\Windows\Temp\{756FAA5D-DE88-4514-9E29-9A66DE819CFE}\.be\VC_redist.x86.exeVC_redist.x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.40.33810
Version:
14.40.33810.0
Modules
Images
c:\windows\temp\{756faa5d-de88-4514-9e29-9a66de819cfe}\.be\vc_redist.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5904"C:\Users\admin\AppData\Local\Temp\is-VMOHI.tmp\GalaxySetup.tmp" /SL5="$502A6,283484498,1268224,C:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe" /SPAWNWND=$701E2 /NOTIFYWND=$8027E /lang=en_US /webinstaller /product_id=1491728574 /silent /game_name="Fallout: London"C:\Users\admin\AppData\Local\Temp\is-VMOHI.tmp\GalaxySetup.tmp
GalaxySetup.exe
User:
admin
Company:
GOG.com
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-vmohi.tmp\galaxysetup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
6516"C:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe" /SPAWNWND=$701E2 /NOTIFYWND=$8027E /lang=en_US /webinstaller /product_id=1491728574 /silent /game_name="Fallout: London"C:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe
GalaxySetup.tmp
User:
admin
Company:
GOG.com
Integrity Level:
HIGH
Description:
GOG GALAXY
Version:
2.0.75.142
Modules
Images
c:\users\admin\appdata\local\temp\galaxyinstaller_gfnwc\galaxysetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6980"C:\Users\admin\AppData\Local\Temp\GOG_Galaxy_Fallout_LondonOriginal.exe" C:\Users\admin\AppData\Local\Temp\GOG_Galaxy_Fallout_LondonOriginal.exe
explorer.exe
User:
admin
Company:
GOG Sp. z o.o.
Integrity Level:
MEDIUM
Description:
Fallout: London
Version:
2.0.0.2
Modules
Images
c:\users\admin\appdata\local\temp\gog_galaxy_fallout_londonoriginal.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
15 273
Read events
15 173
Write events
90
Delete events
10

Modification events

(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6980) GOG_Galaxy_Fallout_LondonOriginal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7048) GalaxyInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7048) GalaxyInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7048) GalaxyInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GalaxyInstaller_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
336
Suspicious files
131
Text files
1 265
Unknown types
153

Dropped files

PID
Process
Filename
Type
6980GOG_Galaxy_Fallout_LondonOriginal.exeC:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\payload.base64
MD5:
SHA256:
7048GalaxyInstaller.exeC:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\GalaxySetup.exe
MD5:
SHA256:
6516GalaxySetup.exeC:\Users\admin\AppData\Local\Temp\is-VMOHI.tmp\GalaxySetup.tmpexecutable
MD5:5446A1A5B11D6047D5BF8EBB10B2CB4B
SHA256:F726348D025308BD3C9BDC27113AD4268469C95E5939FE099D8A629D263F9B43
7048GalaxyInstaller.exeC:\ProgramData\GOG.com\Galaxy\logs\InstallerWebinstaller.logtext
MD5:DABD66F123BFC82419845728322347E5
SHA256:F54C2627C999605EA6B5EE4306EAF84A58D81B072256E5DE5A0BA160D19C3B70
5904GalaxySetup.tmpC:\Users\admin\AppData\Local\Temp\is-6CKVA.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6980GOG_Galaxy_Fallout_LondonOriginal.exeC:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\remoteconfig.jsonbinary
MD5:6203BF56D374F725105921A5F5382E45
SHA256:1966FEDCAF1FB03C9C419912146B7FE6BE39208B44FB5ADA675E8106987FD920
1168GalaxySetup.exeC:\Users\admin\AppData\Local\Temp\is-EQSI5.tmp\GalaxySetup.tmpexecutable
MD5:5446A1A5B11D6047D5BF8EBB10B2CB4B
SHA256:F726348D025308BD3C9BDC27113AD4268469C95E5939FE099D8A629D263F9B43
5904GalaxySetup.tmpC:\Program Files (x86)\GOG Galaxy\is-2V8R0.tmpexecutable
MD5:5446A1A5B11D6047D5BF8EBB10B2CB4B
SHA256:F726348D025308BD3C9BDC27113AD4268469C95E5939FE099D8A629D263F9B43
6980GOG_Galaxy_Fallout_LondonOriginal.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419der
MD5:ED5B30E666DB4662C06179A981E556F1
SHA256:F7ADA27C5D21F1B67B1ED48FB2A06F0E46BC17038F40761EE8E8E469BBC54BAE
6980GOG_Galaxy_Fallout_LondonOriginal.exeC:\Users\admin\AppData\Local\Temp\GalaxyInstaller_GfnwC\icon.icoimage
MD5:F2BEE83D52C9144D254A0BC9186D249E
SHA256:A47297633273FEF58CA84B476C1F88917AF2F03A66178ED262EBDE219B285D26
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
42
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6980
GOG_Galaxy_Fallout_LondonOriginal.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
6272
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1664
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6304
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
3208
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4936
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1664
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5336
SearchApp.exe
92.123.104.4:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6248
backgroundTaskHost.exe
92.123.104.4:443
www.bing.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 172.217.18.110
whitelisted
login.live.com
  • 20.190.159.75
  • 40.126.31.67
  • 20.190.159.2
  • 20.190.159.71
  • 40.126.31.73
  • 40.126.31.69
  • 20.190.159.68
  • 20.190.159.64
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.bing.com
  • 92.123.104.4
  • 92.123.104.67
  • 92.123.104.6
  • 92.123.104.64
  • 92.123.104.66
  • 92.123.104.63
  • 92.123.104.5
  • 92.123.104.7
  • 92.123.104.65
whitelisted
client.wns.windows.com
  • 40.115.3.253
  • 40.113.103.199
whitelisted
remote-config.gog.com
  • 146.75.121.55
whitelisted
content-system.gog.com
  • 146.75.121.55
whitelisted
gog-cdn-fastly.gog.com
  • 146.75.121.55
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info