| File name: | goldbet-poker.exe |
| Full analysis: | https://app.any.run/tasks/32c07f9b-6789-476f-b8fe-8407df85cfa9 |
| Verdict: | Malicious activity |
| Analysis date: | May 27, 2025, 10:18:38 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections |
| MD5: | 204128B789C33FFA063E8F1F0F378680 |
| SHA1: | B25DFF8D3031C5AA2E9281E03289B9B2CCB24725 |
| SHA256: | C873CCAA7639178426193E0BB3204EF4CAE0F873ABCCB743F2AFB594619F4FE4 |
| SSDEEP: | 24576:b2CKr82oMbYa4U3Qz+Ys24jHRo9REodEo:b2CKr82oMbYZU3Qz+Y14jHRo9REodEo |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:03:08 14:03:54+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 566784 |
| InitializedDataSize: | 253440 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x5ea95 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.1 |
| ProductVersionNumber: | 1.0.0.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Poker Goldbet.it |
| FileDescription: | Poker Goldbet.it |
| FileVersion: | 1.1.2.5 |
| InternalName: | Installer |
| LegalCopyright: | Copyright 2022 |
| OriginalFileName: | installer.exe |
| ProductName: | Poker Goldbet.it |
| ProductVersion: | 1.1.2.5 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1128 | C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\26500.bat" "C:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\"" | C:\Windows\SysWOW64\cmd.exe | — | goldbet-poker.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1452 | C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\6334.bat" "C:\Users\admin\AppData\Local\Temp\goldbet-poker.exe"" | C:\Windows\SysWOW64\cmd.exe | — | goldbet-poker.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2516 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5132 | "C:\Users\admin\AppData\Local\Poker Goldbet.it\data\QtWebEngineProcess.exe" --type=renderer --no-sandbox --disable-speech-api --enable-threaded-compositing --enable-features=AllowContentInitiatedDataUrlNavigations,NetworkServiceInProcess,TracingServiceInProcess --disable-features=BackgroundFetch,ConsolidatedMovementXY,DnsOverHttpsUpgrade,InstalledApp,MojoVideoCapture,PictureInPicture,SmsReceiver,UseSkiaRenderer,WebPayments,WebUSB --lang=en --webengine-schemes=qrc:sLV --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=3 --mojo-platform-channel-handle=4256 /prefetch:1 | C:\Users\admin\AppData\Local\Poker Goldbet.it\data\QtWebEngineProcess.exe | — | PokerClient.exe | |||||||||||
User: admin Company: The Qt Company Ltd. Integrity Level: MEDIUM Description: C++ Application Development Framework Version: 5.15.17.0 Modules
| |||||||||||||||
| 5384 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5392 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5528 | "C:\Users\admin\AppData\Local\Poker Goldbet.it\data\PokerClient.exe" | C:\Users\admin\AppData\Local\Poker Goldbet.it\data\PokerClient.exe | CrashReporter.exe | ||||||||||||
User: admin Company: Goldbet.it Integrity Level: MEDIUM Description: Goldbet.it Version: 14.6.0.1 Modules
| |||||||||||||||
| 6184 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | SppExtComObj.Exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6252 | "C:/Users/admin/AppData/Local/Poker Goldbet.it/data/CrashReporter.exe" | C:\Users\admin\AppData\Local\Poker Goldbet.it\data\CrashReporter.exe | casino.exe | ||||||||||||
User: admin Company: Goldbet.it Integrity Level: MEDIUM Description: Goldbet.it Version: 17.11.0.1 Modules
| |||||||||||||||
| 6572 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (7012) goldbet-poker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7012) goldbet-poker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7012) goldbet-poker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7012) goldbet-poker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch |
| Operation: | write | Name: | Version |
Value: WS not running | |||
| (PID) Process: | (7012) goldbet-poker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | DisableFirstRunCustomize |
Value: 1 | |||
| (PID) Process: | (7012) goldbet-poker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\PTECH\346 |
| Operation: | write | Name: | userid |
Value: ED0AC33836B8482A8EEC5DFC0688BA3DUI | |||
| (PID) Process: | (7012) goldbet-poker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\PTECH\346 |
| Operation: | write | Name: | skinid |
Value: new | |||
| (PID) Process: | (7012) goldbet-poker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Poker Goldbet.it |
| Operation: | write | Name: | DisplayName |
Value: Poker Goldbet.it | |||
| (PID) Process: | (7012) goldbet-poker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Poker Goldbet.it |
| Operation: | write | Name: | UninstallString |
Value: "C:\Users\admin\AppData\Local\Poker Goldbet.it\goldbet-pokerUninstall1748341220918_na_it.exe" /executeuninstall /trafficsource='na' /profile='na' /userid='ED0AC33836B8482A8EEC5DFC0688BA3DUI' /skinid='new' /fallbackfolder='' | |||
| (PID) Process: | (7012) goldbet-poker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Poker Goldbet.it |
| Operation: | write | Name: | Publisher |
Value: Poker Goldbet.it | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7012 | goldbet-poker.exe | C:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\WebInstaller_7012.log | text | |
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA | SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5 | |||
| 7012 | goldbet-poker.exe | C:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\new\images\fl_it.png | image | |
MD5:2E437B408A6B4158415217F057EB06E2 | SHA256:2F5AC8AC6064CFF3FCDF489E993290A110B60D0FBCE92F5E419E982F0ED0CDF5 | |||
| 7012 | goldbet-poker.exe | C:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\index.7z | compressed | |
MD5:569A28B9EBF6C11A4E52315982BD9AF7 | SHA256:64C2BC0474DC298519CD15312270091A41C7E688D759AC3500F03E4E5B43ED81 | |||
| 7012 | goldbet-poker.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8 | der | |
MD5:EE989C92C1E29AB601C18DFA5FB94406 | SHA256:F3D48BC9A2AFB57D3AD321B6A3140B95D604DB68E00DF14970D3DD82B0CED834 | |||
| 7012 | goldbet-poker.exe | C:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\new\css\template.css | text | |
MD5:22594A7FE9A50B3278E54C0C5D13FF2A | SHA256:42D56DD2A1421E67E9B5C8CA0023860C78CBCEEC957960C5E8F2BBE1BC8C1BF5 | |||
| 7012 | goldbet-poker.exe | C:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\new\images\countless_cash_games_icon.png | image | |
MD5:056B40C9662EFC4D59ED464F841F0973 | SHA256:775635B0CC04E3B1C18006438C92C6FCD01D142A31A234EF8B499ADE73D57A9C | |||
| 7012 | goldbet-poker.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\index[1].7z | compressed | |
MD5:569A28B9EBF6C11A4E52315982BD9AF7 | SHA256:64C2BC0474DC298519CD15312270091A41C7E688D759AC3500F03E4E5B43ED81 | |||
| 7012 | goldbet-poker.exe | C:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\new\images\cta-button_over.png | image | |
MD5:9B1431C5A763AAA55831B3095659B05C | SHA256:2DAF47E3A0CE2418A39BCFE3C66E26496CCBB05966939B24B705DB6F1B8BD820 | |||
| 7012 | goldbet-poker.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\casino[en][1].cab | — | |
MD5:— | SHA256:— | |||
| 7012 | goldbet-poker.exe | C:\Users\admin\AppData\Local\Temp\WebInstaller_ED0AC33836B8482A8EEC5DFC0688BA3D\pack.cab | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7012 | goldbet-poker.exe | GET | 200 | 52.213.137.28:80 | http://stats.ptinstaller.com/stats.gif?v=2&data=ZXZlbnQ9MTAwJnRyYWNraW5nX2lkPW5hJmJyYW5kPVBva2VyIEdvbGRiZXQuaXQmb3M9KDkyMDApXzY0Yml0Jm9zX2xhbmc9ZW4maWVfdmVyPTExLjM2MzYuMTkwNDEuMCZwcm9jZXNzX2lkPUVEMEFDMzM4MzZCODQ4MkE4RUVDNURGQzA2ODhCQTNEJnVzZXJfaWQ9RUQwQUMzMzgzNkI4NDgyQThFRUM1REZDMDY4OEJBM0RVSSZza2luPW5ldyZpbnN0YWxsZXJfdmVyPTEuMS4xLjM2Jmluc3RhbGxlcl9wYXJhbT11bmRlZmluZWQmdmVyaWZpZXI9NzNjZmMxMWM1ODU4ZGJiYTQ4ZThjNjQ0YjVkY2ExZDAmaXNfYWR2X2V4ZT1mYWxzZSZmaWxlX2xhbmd1YWdlPW5hJmZpbGVfbmFtZT1nb2xkYmV0LXBva2VyLmV4ZSZpbnN0YWxsZXJfbGFuZz1uYSZ0aW1lc3RhbXA9MTc0ODM0MTEzMTU3NiZzZWNvbmRzX3J1bm5pbmc9MCZldmVudF90eXBlPWluc3RhbGxlcl9zdGFydGVkJmlzX2Zyb21fc2hvcnRjdXQ9ZmFsc2U%3D | unknown | — | — | unknown |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7012 | goldbet-poker.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | unknown | — | — | whitelisted |
7012 | goldbet-poker.exe | GET | 200 | 18.66.145.213:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D | unknown | — | — | whitelisted |
7012 | goldbet-poker.exe | GET | 200 | 52.213.137.28:80 | http://stats.ptinstaller.com/stats.gif?v=2&data=ZXZlbnQ9MTAwJnRyYWNraW5nX2lkPW5hJmJyYW5kPVBva2VyIEdvbGRiZXQuaXQmb3M9KDkyMDApXzY0Yml0Jm9zX2xhbmc9ZW4maWVfdmVyPTExLjM2MzYuMTkwNDEuMCZwcm9jZXNzX2lkPUVEMEFDMzM4MzZCODQ4MkE4RUVDNURGQzA2ODhCQTNEJnVzZXJfaWQ9RUQwQUMzMzgzNkI4NDgyQThFRUM1REZDMDY4OEJBM0RVSSZza2luPW5ldyZpbnN0YWxsZXJfdmVyPTEuMS4xLjM2Jmluc3RhbGxlcl9wYXJhbT11bmRlZmluZWQmdmVyaWZpZXI9NzNjZmMxMWM1ODU4ZGJiYTQ4ZThjNjQ0YjVkY2ExZDAmaXNfYWR2X2V4ZT1mYWxzZSZmaWxlX2xhbmd1YWdlPW5hJmZpbGVfbmFtZT1nb2xkYmV0LXBva2VyLmV4ZSZpbnN0YWxsZXJfbGFuZz1pdCZ0aW1lc3RhbXA9MTc0ODM0MTE3NTEyNyZzZWNvbmRzX3J1bm5pbmc9NDMmZXZlbnRfdHlwZT1pbnN0YWxsYXRpb25faW5fcHJvZ3Jlc3MmdXNlcl90aW1lPTQy | unknown | — | — | unknown |
7012 | goldbet-poker.exe | GET | 200 | 52.213.137.28:80 | http://stats.ptinstaller.com/stats.gif?v=2&data=ZXZlbnQ9MTAwJmJyYW5kPVBva2VyIEdvbGRiZXQuaXQmZXZlbnRfdHlwZT1pbnN0YWxsZXJfaW5pdCZvcz0oOTIwMClfNjRiaXQmb3NfbGFuZz0xMDMzJmllX3Zlcj0xMS4zNjM2LjE5MDQxLjAmcHJvY2Vzc19pZD1FRDBBQzMzODM2Qjg0ODJBOEVFQzVERkMwNjg4QkEzRCZ2ZXJpZmllcj03M2NmYzExYzU4NThkYmJhNDhlOGM2NDRiNWRjYTFkMCZ1c2VyX2lkPUVEMEFDMzM4MzZCODQ4MkE4RUVDNURGQzA2ODhCQTNEJmluc3RhbGxlcl92ZXI9MS4xLjEuMzYmdGltZXN0YW1wPTE3NDgzNDExMjU1MjMmYWRtaW51c2VyPTAmc3RhcnR0aW1lPTE3NDgzNDExMjUmbGlmZXRpbWU9MA%3D%3D | unknown | — | — | unknown |
7012 | goldbet-poker.exe | GET | 200 | 18.244.20.52:80 | http://d3a6p9a3vksur7.cloudfront.net/compressed_assets/poker_goldbet_it_prod_new/index.7z | unknown | — | — | whitelisted |
7012 | goldbet-poker.exe | GET | 200 | 52.213.137.28:80 | http://stats.ptinstaller.com/stats.gif?v=2&data=ZXZlbnQ9MTAwJnRyYWNraW5nX2lkPW5hJmJyYW5kPVBva2VyIEdvbGRiZXQuaXQmb3M9KDkyMDApXzY0Yml0Jm9zX2xhbmc9ZW4maWVfdmVyPTExLjM2MzYuMTkwNDEuMCZwcm9jZXNzX2lkPUVEMEFDMzM4MzZCODQ4MkE4RUVDNURGQzA2ODhCQTNEJnVzZXJfaWQ9RUQwQUMzMzgzNkI4NDgyQThFRUM1REZDMDY4OEJBM0RVSSZza2luPW5ldyZpbnN0YWxsZXJfdmVyPTEuMS4xLjM2Jmluc3RhbGxlcl9wYXJhbT11bmRlZmluZWQmdmVyaWZpZXI9NzNjZmMxMWM1ODU4ZGJiYTQ4ZThjNjQ0YjVkY2ExZDAmaXNfYWR2X2V4ZT1mYWxzZSZmaWxlX2xhbmd1YWdlPW5hJmZpbGVfbmFtZT1nb2xkYmV0LXBva2VyLmV4ZSZpbnN0YWxsZXJfbGFuZz1pdCZ0aW1lc3RhbXA9MTc0ODM0MTEzMjM3OCZzZWNvbmRzX3J1bm5pbmc9MSZldmVudF90eXBlPXN0YXJ0X2Rvd25sb2FkX2NhYg%3D%3D | unknown | — | — | unknown |
7012 | goldbet-poker.exe | GET | 200 | 52.213.137.28:80 | http://stats.ptinstaller.com/stats.gif?v=2&data=ZXZlbnQ9MTAwJnRyYWNraW5nX2lkPW5hJmJyYW5kPVBva2VyIEdvbGRiZXQuaXQmb3M9KDkyMDApXzY0Yml0Jm9zX2xhbmc9ZW4maWVfdmVyPTExLjM2MzYuMTkwNDEuMCZwcm9jZXNzX2lkPUVEMEFDMzM4MzZCODQ4MkE4RUVDNURGQzA2ODhCQTNEJnVzZXJfaWQ9RUQwQUMzMzgzNkI4NDgyQThFRUM1REZDMDY4OEJBM0RVSSZza2luPW5ldyZpbnN0YWxsZXJfdmVyPTEuMS4xLjM2Jmluc3RhbGxlcl9wYXJhbT11bmRlZmluZWQmdmVyaWZpZXI9NzNjZmMxMWM1ODU4ZGJiYTQ4ZThjNjQ0YjVkY2ExZDAmaXNfYWR2X2V4ZT1mYWxzZSZmaWxlX2xhbmd1YWdlPW5hJmZpbGVfbmFtZT1nb2xkYmV0LXBva2VyLmV4ZSZpbnN0YWxsZXJfbGFuZz1pdCZ0aW1lc3RhbXA9MTc0ODM0MTEzMjM4NyZzZWNvbmRzX3J1bm5pbmc9MSZldmVudF90eXBlPWluc3RhbGxlcl9zaG93ZWQmbG9hZGluZ190aW1lPTE%3D | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2104 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
7012 | goldbet-poker.exe | 52.213.137.28:80 | stats.ptinstaller.com | AMAZON-02 | IE | unknown |
7012 | goldbet-poker.exe | 18.244.20.52:80 | d3a6p9a3vksur7.cloudfront.net | — | US | whitelisted |
3216 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
7012 | goldbet-poker.exe | 18.244.20.52:443 | d3a6p9a3vksur7.cloudfront.net | — | US | whitelisted |
7012 | goldbet-poker.exe | 18.66.145.213:80 | ocsp.rootca1.amazontrust.com | AMAZON-02 | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
stats.ptinstaller.com |
| unknown |
d3a6p9a3vksur7.cloudfront.net |
| whitelisted |
client.wns.windows.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| whitelisted |
cachedownload-poker.goldbet.it |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |