File name:

goldbet-poker.exe

Full analysis: https://app.any.run/tasks/32c07f9b-6789-476f-b8fe-8407df85cfa9
Verdict: Malicious activity
Analysis date: May 27, 2025, 10:18:38
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

204128B789C33FFA063E8F1F0F378680

SHA1:

B25DFF8D3031C5AA2E9281E03289B9B2CCB24725

SHA256:

C873CCAA7639178426193E0BB3204EF4CAE0F873ABCCB743F2AFB594619F4FE4

SSDEEP:

24576:b2CKr82oMbYa4U3Qz+Ys24jHRo9REodEo:b2CKr82oMbYZU3Qz+Y14jHRo9REodEo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • goldbet-poker.exe (PID: 7012)
    • Reads Microsoft Outlook installation path

      • goldbet-poker.exe (PID: 7012)
    • Reads security settings of Internet Explorer

      • goldbet-poker.exe (PID: 7012)
      • casino.exe (PID: 7148)
    • Creates a software uninstall entry

      • goldbet-poker.exe (PID: 7012)
    • Drops 7-zip archiver for unpacking

      • goldbet-poker.exe (PID: 7012)
    • Executable content was dropped or overwritten

      • goldbet-poker.exe (PID: 7012)
    • Reads Internet Explorer settings

      • goldbet-poker.exe (PID: 7012)
    • The process drops C-runtime libraries

      • goldbet-poker.exe (PID: 7012)
    • Process drops legitimate windows executable

      • goldbet-poker.exe (PID: 7012)
    • Starts CMD.EXE for commands execution

      • goldbet-poker.exe (PID: 7012)
    • Executing commands from a ".bat" file

      • goldbet-poker.exe (PID: 7012)
  • INFO

    • Checks supported languages

      • goldbet-poker.exe (PID: 7012)
      • casino.exe (PID: 7148)
      • CrashReporter.exe (PID: 6252)
      • PokerClient.exe (PID: 5528)
      • QtWebEngineProcess.exe (PID: 5132)
    • The sample compiled with english language support

      • goldbet-poker.exe (PID: 7012)
    • Create files in a temporary directory

      • goldbet-poker.exe (PID: 7012)
    • Creates files or folders in the user directory

      • goldbet-poker.exe (PID: 7012)
      • CrashReporter.exe (PID: 6252)
      • casino.exe (PID: 7148)
      • PokerClient.exe (PID: 5528)
    • Reads the computer name

      • goldbet-poker.exe (PID: 7012)
      • casino.exe (PID: 7148)
      • PokerClient.exe (PID: 5528)
      • CrashReporter.exe (PID: 6252)
    • Checks proxy server information

      • goldbet-poker.exe (PID: 7012)
      • casino.exe (PID: 7148)
      • CrashReporter.exe (PID: 6252)
      • PokerClient.exe (PID: 5528)
    • Reads the software policy settings

      • slui.exe (PID: 6184)
      • goldbet-poker.exe (PID: 7012)
      • CrashReporter.exe (PID: 6252)
      • casino.exe (PID: 7148)
      • PokerClient.exe (PID: 5528)
    • Reads the machine GUID from the registry

      • goldbet-poker.exe (PID: 7012)
      • casino.exe (PID: 7148)
      • PokerClient.exe (PID: 5528)
    • Process checks computer location settings

      • goldbet-poker.exe (PID: 7012)
      • QtWebEngineProcess.exe (PID: 5132)
      • PokerClient.exe (PID: 5528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:03:08 14:03:54+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 566784
InitializedDataSize: 253440
UninitializedDataSize: -
EntryPoint: 0x5ea95
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Poker Goldbet.it
FileDescription: Poker Goldbet.it
FileVersion: 1.1.2.5
InternalName: Installer
LegalCopyright: Copyright 2022
OriginalFileName: installer.exe
ProductName: Poker Goldbet.it
ProductVersion: 1.1.2.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
12
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start goldbet-poker.exe sppextcomobj.exe no specs slui.exe slui.exe no specs casino.exe cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs crashreporter.exe pokerclient.exe qtwebengineprocess.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1128C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\26500.bat" "C:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\""C:\Windows\SysWOW64\cmd.exegoldbet-poker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1452C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\6334.bat" "C:\Users\admin\AppData\Local\Temp\goldbet-poker.exe""C:\Windows\SysWOW64\cmd.exegoldbet-poker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2516C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5132"C:\Users\admin\AppData\Local\Poker Goldbet.it\data\QtWebEngineProcess.exe" --type=renderer --no-sandbox --disable-speech-api --enable-threaded-compositing --enable-features=AllowContentInitiatedDataUrlNavigations,NetworkServiceInProcess,TracingServiceInProcess --disable-features=BackgroundFetch,ConsolidatedMovementXY,DnsOverHttpsUpgrade,InstalledApp,MojoVideoCapture,PictureInPicture,SmsReceiver,UseSkiaRenderer,WebPayments,WebUSB --lang=en --webengine-schemes=qrc:sLV --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=3 --mojo-platform-channel-handle=4256 /prefetch:1C:\Users\admin\AppData\Local\Poker Goldbet.it\data\QtWebEngineProcess.exePokerClient.exe
User:
admin
Company:
The Qt Company Ltd.
Integrity Level:
MEDIUM
Description:
C++ Application Development Framework
Version:
5.15.17.0
Modules
Images
c:\users\admin\appdata\local\poker goldbet.it\data\qtwebengineprocess.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5384\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5392C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5528"C:\Users\admin\AppData\Local\Poker Goldbet.it\data\PokerClient.exe"C:\Users\admin\AppData\Local\Poker Goldbet.it\data\PokerClient.exe
CrashReporter.exe
User:
admin
Company:
Goldbet.it
Integrity Level:
MEDIUM
Description:
Goldbet.it
Version:
14.6.0.1
Modules
Images
c:\users\admin\appdata\local\poker goldbet.it\data\pokerclient.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6184"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6252"C:/Users/admin/AppData/Local/Poker Goldbet.it/data/CrashReporter.exe"C:\Users\admin\AppData\Local\Poker Goldbet.it\data\CrashReporter.exe
casino.exe
User:
admin
Company:
Goldbet.it
Integrity Level:
MEDIUM
Description:
Goldbet.it
Version:
17.11.0.1
Modules
Images
c:\users\admin\appdata\local\poker goldbet.it\data\crashreporter.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6572\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
9 171
Read events
9 154
Write events
17
Delete events
0

Modification events

(PID) Process:(7012) goldbet-poker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7012) goldbet-poker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7012) goldbet-poker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7012) goldbet-poker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch
Operation:writeName:Version
Value:
WS not running
(PID) Process:(7012) goldbet-poker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:DisableFirstRunCustomize
Value:
1
(PID) Process:(7012) goldbet-poker.exeKey:HKEY_CURRENT_USER\SOFTWARE\PTECH\346
Operation:writeName:userid
Value:
ED0AC33836B8482A8EEC5DFC0688BA3DUI
(PID) Process:(7012) goldbet-poker.exeKey:HKEY_CURRENT_USER\SOFTWARE\PTECH\346
Operation:writeName:skinid
Value:
new
(PID) Process:(7012) goldbet-poker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Poker Goldbet.it
Operation:writeName:DisplayName
Value:
Poker Goldbet.it
(PID) Process:(7012) goldbet-poker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Poker Goldbet.it
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\Poker Goldbet.it\goldbet-pokerUninstall1748341220918_na_it.exe" /executeuninstall /trafficsource='na' /profile='na' /userid='ED0AC33836B8482A8EEC5DFC0688BA3DUI' /skinid='new' /fallbackfolder=''
(PID) Process:(7012) goldbet-poker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Poker Goldbet.it
Operation:writeName:Publisher
Value:
Poker Goldbet.it
Executable files
191
Suspicious files
50
Text files
350
Unknown types
10

Dropped files

PID
Process
Filename
Type
7012goldbet-poker.exeC:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\WebInstaller_7012.logtext
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
7012goldbet-poker.exeC:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\new\images\fl_it.pngimage
MD5:2E437B408A6B4158415217F057EB06E2
SHA256:2F5AC8AC6064CFF3FCDF489E993290A110B60D0FBCE92F5E419E982F0ED0CDF5
7012goldbet-poker.exeC:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\index.7zcompressed
MD5:569A28B9EBF6C11A4E52315982BD9AF7
SHA256:64C2BC0474DC298519CD15312270091A41C7E688D759AC3500F03E4E5B43ED81
7012goldbet-poker.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8der
MD5:EE989C92C1E29AB601C18DFA5FB94406
SHA256:F3D48BC9A2AFB57D3AD321B6A3140B95D604DB68E00DF14970D3DD82B0CED834
7012goldbet-poker.exeC:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\new\css\template.csstext
MD5:22594A7FE9A50B3278E54C0C5D13FF2A
SHA256:42D56DD2A1421E67E9B5C8CA0023860C78CBCEEC957960C5E8F2BBE1BC8C1BF5
7012goldbet-poker.exeC:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\new\images\countless_cash_games_icon.pngimage
MD5:056B40C9662EFC4D59ED464F841F0973
SHA256:775635B0CC04E3B1C18006438C92C6FCD01D142A31A234EF8B499ADE73D57A9C
7012goldbet-poker.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\index[1].7zcompressed
MD5:569A28B9EBF6C11A4E52315982BD9AF7
SHA256:64C2BC0474DC298519CD15312270091A41C7E688D759AC3500F03E4E5B43ED81
7012goldbet-poker.exeC:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\new\images\cta-button_over.pngimage
MD5:9B1431C5A763AAA55831B3095659B05C
SHA256:2DAF47E3A0CE2418A39BCFE3C66E26496CCBB05966939B24B705DB6F1B8BD820
7012goldbet-poker.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\casino[en][1].cab
MD5:
SHA256:
7012goldbet-poker.exeC:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\pack.cab
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
69
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7012
goldbet-poker.exe
GET
200
52.213.137.28:80
http://stats.ptinstaller.com/stats.gif?v=2&data=ZXZlbnQ9MTAwJnRyYWNraW5nX2lkPW5hJmJyYW5kPVBva2VyIEdvbGRiZXQuaXQmb3M9KDkyMDApXzY0Yml0Jm9zX2xhbmc9ZW4maWVfdmVyPTExLjM2MzYuMTkwNDEuMCZwcm9jZXNzX2lkPUVEMEFDMzM4MzZCODQ4MkE4RUVDNURGQzA2ODhCQTNEJnVzZXJfaWQ9RUQwQUMzMzgzNkI4NDgyQThFRUM1REZDMDY4OEJBM0RVSSZza2luPW5ldyZpbnN0YWxsZXJfdmVyPTEuMS4xLjM2Jmluc3RhbGxlcl9wYXJhbT11bmRlZmluZWQmdmVyaWZpZXI9NzNjZmMxMWM1ODU4ZGJiYTQ4ZThjNjQ0YjVkY2ExZDAmaXNfYWR2X2V4ZT1mYWxzZSZmaWxlX2xhbmd1YWdlPW5hJmZpbGVfbmFtZT1nb2xkYmV0LXBva2VyLmV4ZSZpbnN0YWxsZXJfbGFuZz1uYSZ0aW1lc3RhbXA9MTc0ODM0MTEzMTU3NiZzZWNvbmRzX3J1bm5pbmc9MCZldmVudF90eXBlPWluc3RhbGxlcl9zdGFydGVkJmlzX2Zyb21fc2hvcnRjdXQ9ZmFsc2U%3D
unknown
unknown
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7012
goldbet-poker.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
7012
goldbet-poker.exe
GET
200
18.66.145.213:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
unknown
whitelisted
7012
goldbet-poker.exe
GET
200
52.213.137.28:80
http://stats.ptinstaller.com/stats.gif?v=2&data=ZXZlbnQ9MTAwJnRyYWNraW5nX2lkPW5hJmJyYW5kPVBva2VyIEdvbGRiZXQuaXQmb3M9KDkyMDApXzY0Yml0Jm9zX2xhbmc9ZW4maWVfdmVyPTExLjM2MzYuMTkwNDEuMCZwcm9jZXNzX2lkPUVEMEFDMzM4MzZCODQ4MkE4RUVDNURGQzA2ODhCQTNEJnVzZXJfaWQ9RUQwQUMzMzgzNkI4NDgyQThFRUM1REZDMDY4OEJBM0RVSSZza2luPW5ldyZpbnN0YWxsZXJfdmVyPTEuMS4xLjM2Jmluc3RhbGxlcl9wYXJhbT11bmRlZmluZWQmdmVyaWZpZXI9NzNjZmMxMWM1ODU4ZGJiYTQ4ZThjNjQ0YjVkY2ExZDAmaXNfYWR2X2V4ZT1mYWxzZSZmaWxlX2xhbmd1YWdlPW5hJmZpbGVfbmFtZT1nb2xkYmV0LXBva2VyLmV4ZSZpbnN0YWxsZXJfbGFuZz1pdCZ0aW1lc3RhbXA9MTc0ODM0MTE3NTEyNyZzZWNvbmRzX3J1bm5pbmc9NDMmZXZlbnRfdHlwZT1pbnN0YWxsYXRpb25faW5fcHJvZ3Jlc3MmdXNlcl90aW1lPTQy
unknown
unknown
7012
goldbet-poker.exe
GET
200
52.213.137.28:80
http://stats.ptinstaller.com/stats.gif?v=2&data=ZXZlbnQ9MTAwJmJyYW5kPVBva2VyIEdvbGRiZXQuaXQmZXZlbnRfdHlwZT1pbnN0YWxsZXJfaW5pdCZvcz0oOTIwMClfNjRiaXQmb3NfbGFuZz0xMDMzJmllX3Zlcj0xMS4zNjM2LjE5MDQxLjAmcHJvY2Vzc19pZD1FRDBBQzMzODM2Qjg0ODJBOEVFQzVERkMwNjg4QkEzRCZ2ZXJpZmllcj03M2NmYzExYzU4NThkYmJhNDhlOGM2NDRiNWRjYTFkMCZ1c2VyX2lkPUVEMEFDMzM4MzZCODQ4MkE4RUVDNURGQzA2ODhCQTNEJmluc3RhbGxlcl92ZXI9MS4xLjEuMzYmdGltZXN0YW1wPTE3NDgzNDExMjU1MjMmYWRtaW51c2VyPTAmc3RhcnR0aW1lPTE3NDgzNDExMjUmbGlmZXRpbWU9MA%3D%3D
unknown
unknown
7012
goldbet-poker.exe
GET
200
18.244.20.52:80
http://d3a6p9a3vksur7.cloudfront.net/compressed_assets/poker_goldbet_it_prod_new/index.7z
unknown
whitelisted
7012
goldbet-poker.exe
GET
200
52.213.137.28:80
http://stats.ptinstaller.com/stats.gif?v=2&data=ZXZlbnQ9MTAwJnRyYWNraW5nX2lkPW5hJmJyYW5kPVBva2VyIEdvbGRiZXQuaXQmb3M9KDkyMDApXzY0Yml0Jm9zX2xhbmc9ZW4maWVfdmVyPTExLjM2MzYuMTkwNDEuMCZwcm9jZXNzX2lkPUVEMEFDMzM4MzZCODQ4MkE4RUVDNURGQzA2ODhCQTNEJnVzZXJfaWQ9RUQwQUMzMzgzNkI4NDgyQThFRUM1REZDMDY4OEJBM0RVSSZza2luPW5ldyZpbnN0YWxsZXJfdmVyPTEuMS4xLjM2Jmluc3RhbGxlcl9wYXJhbT11bmRlZmluZWQmdmVyaWZpZXI9NzNjZmMxMWM1ODU4ZGJiYTQ4ZThjNjQ0YjVkY2ExZDAmaXNfYWR2X2V4ZT1mYWxzZSZmaWxlX2xhbmd1YWdlPW5hJmZpbGVfbmFtZT1nb2xkYmV0LXBva2VyLmV4ZSZpbnN0YWxsZXJfbGFuZz1pdCZ0aW1lc3RhbXA9MTc0ODM0MTEzMjM3OCZzZWNvbmRzX3J1bm5pbmc9MSZldmVudF90eXBlPXN0YXJ0X2Rvd25sb2FkX2NhYg%3D%3D
unknown
unknown
7012
goldbet-poker.exe
GET
200
52.213.137.28:80
http://stats.ptinstaller.com/stats.gif?v=2&data=ZXZlbnQ9MTAwJnRyYWNraW5nX2lkPW5hJmJyYW5kPVBva2VyIEdvbGRiZXQuaXQmb3M9KDkyMDApXzY0Yml0Jm9zX2xhbmc9ZW4maWVfdmVyPTExLjM2MzYuMTkwNDEuMCZwcm9jZXNzX2lkPUVEMEFDMzM4MzZCODQ4MkE4RUVDNURGQzA2ODhCQTNEJnVzZXJfaWQ9RUQwQUMzMzgzNkI4NDgyQThFRUM1REZDMDY4OEJBM0RVSSZza2luPW5ldyZpbnN0YWxsZXJfdmVyPTEuMS4xLjM2Jmluc3RhbGxlcl9wYXJhbT11bmRlZmluZWQmdmVyaWZpZXI9NzNjZmMxMWM1ODU4ZGJiYTQ4ZThjNjQ0YjVkY2ExZDAmaXNfYWR2X2V4ZT1mYWxzZSZmaWxlX2xhbmd1YWdlPW5hJmZpbGVfbmFtZT1nb2xkYmV0LXBva2VyLmV4ZSZpbnN0YWxsZXJfbGFuZz1pdCZ0aW1lc3RhbXA9MTc0ODM0MTEzMjM4NyZzZWNvbmRzX3J1bm5pbmc9MSZldmVudF90eXBlPWluc3RhbGxlcl9zaG93ZWQmbG9hZGluZ190aW1lPTE%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
7012
goldbet-poker.exe
52.213.137.28:80
stats.ptinstaller.com
AMAZON-02
IE
unknown
7012
goldbet-poker.exe
18.244.20.52:80
d3a6p9a3vksur7.cloudfront.net
US
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7012
goldbet-poker.exe
18.244.20.52:443
d3a6p9a3vksur7.cloudfront.net
US
whitelisted
7012
goldbet-poker.exe
18.66.145.213:80
ocsp.rootca1.amazontrust.com
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.174
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
stats.ptinstaller.com
  • 52.213.137.28
unknown
d3a6p9a3vksur7.cloudfront.net
  • 18.244.20.52
  • 18.244.20.71
  • 18.244.20.38
  • 18.244.20.86
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.66.145.213
whitelisted
cachedownload-poker.goldbet.it
  • 23.207.210.130
  • 23.207.210.149
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.159.73
  • 20.190.159.2
  • 20.190.159.75
  • 40.126.31.130
  • 40.126.31.128
  • 20.190.159.0
  • 20.190.159.23
  • 40.126.31.67
whitelisted

Threats

No threats detected
No debug info