File name:

Desktop.zip

Full analysis: https://app.any.run/tasks/9fb37b70-97b2-4a9c-8a42-9083469117bb
Verdict: Malicious activity
Analysis date: January 18, 2020, 17:25:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

CDDA6F563F8B5CB8ED9DBAD3FCB52508

SHA1:

CF1A2E4DAFD431B1291EF841AC038544072D9281

SHA256:

D73D07D888B7FC08AF4E235D27854B0514B28E40EF52026E21A7C3D21030F22F

SSDEEP:

49152:5KZnmOTsOP8vSbC3Uiraiki1LRTK0UqtyUkodoXfQS1M:5imhOP8vSbwbrJnNRTYqtrdePQ4M

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Agent.exe (PID: 2424)
      • Agent.exe (PID: 792)
      • Battle.net.exe (PID: 1800)
      • Battle.net.exe (PID: 532)
      • Battle.net.exe (PID: 1724)
      • Battle.net.exe (PID: 1552)
      • SystemSurvey.exe (PID: 616)
      • Agent.exe (PID: 3900)
      • Agent.exe (PID: 2864)
      • Battle.net.exe (PID: 2836)
      • Battle.net.exe (PID: 2556)
      • Battle.net.exe (PID: 856)
      • Battle.net.exe (PID: 2308)
      • Battle.net.exe (PID: 1428)
      • Battle.net Launcher.exe (PID: 3236)
      • Battle.net.exe (PID: 3432)
      • SystemSurvey.exe (PID: 2108)
      • Agent.exe (PID: 2512)
      • Battle.net.exe (PID: 1104)
      • Battle.net.exe (PID: 2472)
      • Agent.exe (PID: 2284)
      • Battle.net.exe (PID: 3896)
      • Battle.net.exe (PID: 3512)
      • VSPTUMJIU.exe (PID: 2516)
      • Battle.net.exe (PID: 3116)
      • SystemSurvey.exe (PID: 2860)
      • Battle.net.exe (PID: 408)
      • Battle.net-Setup.exe (PID: 912)
      • Battle.net-Setup.exe (PID: 4088)
      • Agent.exe (PID: 3260)
      • Agent.exe (PID: 3436)
      • Battle.net.exe (PID: 2428)
    • Changes settings of System certificates

      • Agent.exe (PID: 2424)
    • Loads dropped or rewritten executable

      • Battle.net.exe (PID: 532)
      • SystemSurvey.exe (PID: 616)
      • Battle.net.exe (PID: 1552)
      • Battle.net.exe (PID: 1724)
      • Battle.net.exe (PID: 1800)
      • Battle.net.exe (PID: 2836)
      • Battle.net.exe (PID: 1428)
      • Battle.net.exe (PID: 856)
      • Battle.net.exe (PID: 2308)
      • Battle.net.exe (PID: 2556)
      • Battle.net.exe (PID: 3432)
      • SystemSurvey.exe (PID: 2108)
      • Battle.net.exe (PID: 1104)
      • Battle.net.exe (PID: 3896)
      • Battle.net.exe (PID: 3512)
      • Battle.net.exe (PID: 2472)
      • Battle.net.exe (PID: 3116)
      • SystemSurvey.exe (PID: 2860)
      • Battle.net.exe (PID: 2428)
      • Battle.net.exe (PID: 408)
  • SUSPICIOUS

    • Connects to unusual port

      • Battle.net-Setup.exe (PID: 912)
      • Agent.exe (PID: 2424)
      • Battle.net.exe (PID: 1800)
      • SystemSurvey.exe (PID: 616)
      • Battle.net.exe (PID: 1428)
      • Battle.net-Setup.exe (PID: 4088)
      • Battle.net.exe (PID: 3512)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1016)
      • Battle.net-Setup.exe (PID: 4088)
      • Battle.net.exe (PID: 1800)
      • Agent.exe (PID: 2424)
    • Creates files in the program directory

      • Agent.exe (PID: 792)
      • Battle.net-Setup.exe (PID: 912)
      • Agent.exe (PID: 2424)
      • Agent.exe (PID: 2864)
      • Battle.net.exe (PID: 1800)
      • Battle.net.exe (PID: 1428)
      • Agent.exe (PID: 2512)
      • Battle.net-Setup.exe (PID: 4088)
      • Agent.exe (PID: 3436)
    • Modifies the open verb of a shell class

      • Agent.exe (PID: 2424)
    • Creates a software uninstall entry

      • Agent.exe (PID: 2424)
    • Application launched itself

      • Battle.net.exe (PID: 1800)
      • Battle.net.exe (PID: 1428)
      • Battle.net.exe (PID: 3512)
      • Battle.net-Setup.exe (PID: 912)
    • Creates files in the user directory

      • Battle.net.exe (PID: 1800)
      • Battle.net.exe (PID: 1428)
      • VSPTUMJIU.exe (PID: 2516)
      • Battle.net.exe (PID: 3512)
    • Loads DLL from Mozilla Firefox

      • VSPTUMJIU.exe (PID: 2516)
    • Reads the cookies of Google Chrome

      • VSPTUMJIU.exe (PID: 2516)
    • Reads the cookies of Mozilla Firefox

      • VSPTUMJIU.exe (PID: 2516)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • Agent.exe (PID: 2424)
    • Reads the hosts file

      • Battle.net.exe (PID: 1800)
      • Battle.net.exe (PID: 1724)
      • Battle.net.exe (PID: 2308)
      • Battle.net.exe (PID: 1428)
      • Battle.net.exe (PID: 2472)
      • Battle.net.exe (PID: 3512)
      • Battle.net.exe (PID: 408)
    • Manual execution by user

      • taskmgr.exe (PID: 2820)
      • Battle.net Launcher.exe (PID: 3236)
      • VSPTUMJIU.exe (PID: 2516)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2020:01:18 04:26:21
ZipCRC: 0x95e1a651
ZipCompressedSize: 2358707
ZipUncompressedSize: 4902896
ZipFileName: Battle.net-Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
81
Monitored processes
34
Malicious processes
25
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start start drop and start winrar.exe battle.net-setup.exe battle.net-setup.exe agent.exe no specs agent.exe battle.net.exe battle.net.exe no specs systemsurvey.exe battle.net.exe battle.net.exe no specs agent.exe no specs agent.exe battle.net.exe no specs taskmgr.exe no specs battle.net.exe no specs battle.net.exe no specs battle.net.exe no specs battle.net launcher.exe no specs battle.net.exe battle.net.exe no specs systemsurvey.exe agent.exe no specs agent.exe battle.net.exe no specs battle.net.exe battle.net.exe no specs battle.net.exe vsptumjiu.exe no specs battle.net.exe no specs systemsurvey.exe battle.net.exe battle.net.exe no specs agent.exe no specs agent.exe

Process information

PID
CMD
Path
Indicators
Parent process
408"C:\Program Files\Battle.net\Battle.net.exe" --type=utility --field-trial-handle=1960,13603235831490049813,18206977999646087000,131072 --disable-features=HardwareMediaKeyHandling --lang=ru --service-sandbox-type=network --no-sandbox --log-file="C:\Users\admin\AppData\Local\Battle.net\Logs\libcef-20200118T173050.367140.log" --log-severity=error --product-version="Battle.net/1.18.1.11740 (retail) Chrome/75.0.3770.100" --lang=ru --watch-browser-pid=3512 --log-file="C:\Users\admin\AppData\Local\Battle.net\Logs\libcef-20200118T173050.367140.log" --service-request-channel-token=6551478573578191480 --mojo-platform-channel-handle=2648 /prefetch:8 --battle-net-helper=Battle.net.11740C:\Program Files\Battle.net\Battle.net.exe
Battle.net.exe
User:
admin
Company:
Blizzard Entertainment
Integrity Level:
MEDIUM
Description:
Blizzard Battle.net App
Exit code:
0
Version:
1.18.1.11740
Modules
Images
c:\program files\battle.net\battle.net.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
532"C:\Program Files\Battle.net\Battle.net.exe" --type=gpu-process --field-trial-handle=2040,3157551406477383205,15153978150086914107,131072 --disable-features=HardwareMediaKeyHandling --no-sandbox --log-file="C:\Users\admin\AppData\Local\Battle.net\Logs\libcef-20200118T172854.857375.log" --log-severity=error --product-version="Battle.net/1.18.1.11740 (retail) Chrome/75.0.3770.100" --lang=ru --watch-browser-pid=1800 --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Users\admin\AppData\Local\Battle.net\Logs\libcef-20200118T172854.857375.log" --service-request-channel-token=2238848406441893599 --mojo-platform-channel-handle=2076 /prefetch:2 --battle-net-helper=Battle.net.11740C:\Program Files\Battle.net\Battle.net.exeBattle.net.exe
User:
admin
Company:
Blizzard Entertainment
Integrity Level:
MEDIUM
Description:
Blizzard Battle.net App
Exit code:
1
Version:
1.18.1.11740
Modules
Images
c:\program files\battle.net\battle.net.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
616"C:\Program Files\Battle.net\Battle.net.11740\SystemSurvey.exe" C:\Program Files\Battle.net\Battle.net.11740\SystemSurvey.exe
Battle.net.exe
User:
admin
Company:
Blizzard Entertainment, Inc.
Integrity Level:
MEDIUM
Description:
SystemSurvey
Exit code:
0
Version:
2.4.1.48
Modules
Images
c:\program files\battle.net\battle.net.11740\systemsurvey.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
792"C:\ProgramData\Battle.net\Agent\Agent.exe" --locale=ruRU --session=397729918451533261C:\ProgramData\Battle.net\Agent\Agent.exeBattle.net-Setup.exe
User:
admin
Company:
Blizzard Entertainment
Integrity Level:
HIGH
Description:
Blizzard File Switcher
Exit code:
0
Version:
2.19.3.6926
Modules
Images
c:\programdata\battle.net\agent\agent.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
856"C:\Program Files\Battle.net\Battle.net.exe" --type=gpu-process --field-trial-handle=2040,3157551406477383205,15153978150086914107,131072 --disable-features=HardwareMediaKeyHandling --no-sandbox --log-file="C:\Users\admin\AppData\Local\Battle.net\Logs\libcef-20200118T172854.857375.log" --log-severity=error --product-version="Battle.net/1.18.1.11740 (retail) Chrome/75.0.3770.100" --lang=ru --watch-browser-pid=1800 --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Users\admin\AppData\Local\Battle.net\Logs\libcef-20200118T172854.857375.log" --service-request-channel-token=2763832312509965833 --mojo-platform-channel-handle=2488 /prefetch:2 --battle-net-helper=Battle.net.11740C:\Program Files\Battle.net\Battle.net.exeBattle.net.exe
User:
admin
Company:
Blizzard Entertainment
Integrity Level:
MEDIUM
Description:
Blizzard Battle.net App
Exit code:
0
Version:
1.18.1.11740
Modules
Images
c:\program files\battle.net\battle.net.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
912"C:\Users\admin\AppData\Local\Temp\Rar$EXa1016.36715\Battle.net-Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1016.36715\Battle.net-Setup.exe
WinRAR.exe
User:
admin
Company:
Blizzard Entertainment
Integrity Level:
MEDIUM
Description:
Battle.net Setup
Exit code:
0
Version:
1.16.3.2988
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1016.36715\battle.net-setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1016"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Desktop.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1104"C:\Program Files\Battle.net\Battle.net.exe" --type=gpu-process --field-trial-handle=1972,10279035196449079955,9091582330138558403,131072 --disable-features=HardwareMediaKeyHandling --disable-gpu-sandbox --use-gl=disabled --no-sandbox --log-file="C:\Users\admin\AppData\Local\Battle.net\Logs\libcef-20200118T172948.242140.log" --log-severity=error --product-version="Battle.net/1.18.1.11740 (retail) Chrome/75.0.3770.100" --lang=ru --watch-browser-pid=1428 --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Users\admin\AppData\Local\Battle.net\Logs\libcef-20200118T172948.242140.log" --service-request-channel-token=3218503507155099860 --mojo-platform-channel-handle=2692 /prefetch:2 --battle-net-helper=Battle.net.11740C:\Program Files\Battle.net\Battle.net.exeBattle.net.exe
User:
admin
Company:
Blizzard Entertainment
Integrity Level:
MEDIUM
Description:
Blizzard Battle.net App
Exit code:
0
Version:
1.18.1.11740
Modules
Images
c:\program files\battle.net\battle.net.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1428"C:\Program Files\Battle.net\Battle.net.exe" --from-launcherC:\Program Files\Battle.net\Battle.net.exe
Battle.net Launcher.exe
User:
admin
Company:
Blizzard Entertainment
Integrity Level:
MEDIUM
Description:
Blizzard Battle.net App
Exit code:
3221225547
Version:
1.18.1.11740
Modules
Images
c:\program files\battle.net\battle.net.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1552"C:\Program Files\Battle.net\Battle.net.exe" --type=renderer --no-sandbox --log-file="C:\Users\admin\AppData\Local\Battle.net\Logs\libcef-20200118T172854.857375.log" --field-trial-handle=2040,3157551406477383205,15153978150086914107,131072 --disable-features=HardwareMediaKeyHandling --lang=ru --log-file="C:\Users\admin\AppData\Local\Battle.net\Logs\libcef-20200118T172854.857375.log" --log-severity=error --product-version="Battle.net/1.18.1.11740 (retail) Chrome/75.0.3770.100" --disable-spell-checking --uncaught-exception-stack-size=10 --watch-browser-pid=1800 --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4480388518282856647 --renderer-client-id=4 --mojo-platform-channel-handle=2796 /prefetch:1 --battle-net-helper=Battle.net.11740C:\Program Files\Battle.net\Battle.net.exeBattle.net.exe
User:
admin
Company:
Blizzard Entertainment
Integrity Level:
MEDIUM
Description:
Blizzard Battle.net App
Exit code:
1
Version:
1.18.1.11740
Modules
Images
c:\program files\battle.net\battle.net.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
2 876
Read events
2 192
Write events
683
Delete events
1

Modification events

(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1016) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Desktop.zip
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
196
Suspicious files
117
Text files
892
Unknown types
74

Dropped files

PID
Process
Filename
Type
4088Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\.Blizzard Uninstaller.exe.92.4088.temp
MD5:
SHA256:
4088Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\..Blizzard Uninstaller.exe.92.4088.temp.93.4088.temp
MD5:
SHA256:
4088Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\..Blizzard Uninstaller.exe.92.4088.temp.93.4088.temp.temp
MD5:
SHA256:
4088Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\.LICENSES.95.4088.temp
MD5:
SHA256:
4088Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\..LICENSES.95.4088.temp.96.4088.temp
MD5:
SHA256:
4088Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\..LICENSES.95.4088.temp.96.4088.temp.temp
MD5:
SHA256:
4088Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\.BlizzardError.exe.98.4088.temp
MD5:
SHA256:
4088Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\..BlizzardError.exe.98.4088.temp.99.4088.temp
MD5:
SHA256:
4088Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\..BlizzardError.exe.98.4088.temp.99.4088.temp.temp
MD5:
SHA256:
4088Battle.net-Setup.exeC:\ProgramData\Battle.net\Agent\Agent.6926\.Agent.exe.101.4088.temp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2 588
TCP/UDP connections
2 262
DNS requests
64
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
912
Battle.net-Setup.exe
GET
204
37.244.28.104:80
http://nydus.battle.net/geoip
FR
suspicious
4088
Battle.net-Setup.exe
GET
204
37.244.28.104:80
http://nydus.battle.net/geoip
FR
suspicious
4088
Battle.net-Setup.exe
GET
37.244.28.30:1119
http://eu.patch.battle.net:1119/bts/versions
FR
suspicious
4088
Battle.net-Setup.exe
GET
37.244.28.30:1119
http://eu.patch.battle.net:1119/agent/versions
FR
suspicious
4088
Battle.net-Setup.exe
GET
37.244.28.30:1119
http://eu.patch.battle.net:1119/agent/cdns
FR
suspicious
4088
Battle.net-Setup.exe
GET
8.241.123.126:80
http://level3.blizzard.com/tpr/bnt001/config/5e/bd/5ebdfdfccc5d0fbc80954ab0d226f986
US
suspicious
4088
Battle.net-Setup.exe
GET
8.253.207.109:80
http://level3.blizzard.com/tpr/bnt001/config/33/75/3375c022404dc3dc60916105aa74de14
US
suspicious
4088
Battle.net-Setup.exe
GET
200
137.221.64.4:80
http://eu.cdn.blizzard.com/tpr/configs/data/0a/a7/0aa753b748ca92b11a090d6d125ce81f
FR
text
2.17 Kb
whitelisted
4088
Battle.net-Setup.exe
GET
200
137.221.64.6:80
http://eu.cdn.blizzard.com/tpr/configs/data/0a/a7/0aa753b748ca92b11a090d6d125ce81f
FR
text
2.17 Kb
whitelisted
4088
Battle.net-Setup.exe
GET
200
137.221.64.5:80
http://eu.cdn.blizzard.com/tpr/configs/data/0a/a7/0aa753b748ca92b11a090d6d125ce81f
FR
text
2.17 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
912
Battle.net-Setup.exe
37.244.28.104:80
nydus.battle.net
Blizzard Entertainment, Inc
FR
suspicious
912
Battle.net-Setup.exe
24.105.29.24:3724
iir.blizzard.com
Blizzard Entertainment, Inc
US
suspicious
912
Battle.net-Setup.exe
172.217.18.174:80
www.google-analytics.com
Google Inc.
US
whitelisted
4088
Battle.net-Setup.exe
37.244.28.104:80
nydus.battle.net
Blizzard Entertainment, Inc
FR
suspicious
4088
Battle.net-Setup.exe
172.217.18.174:80
www.google-analytics.com
Google Inc.
US
whitelisted
4088
Battle.net-Setup.exe
24.105.29.24:3724
iir.blizzard.com
Blizzard Entertainment, Inc
US
suspicious
4088
Battle.net-Setup.exe
37.244.28.30:1119
eu.patch.battle.net
Blizzard Entertainment, Inc
FR
suspicious
4088
Battle.net-Setup.exe
137.221.64.6:80
eu.cdn.blizzard.com
FR
suspicious
4088
Battle.net-Setup.exe
137.221.64.4:80
eu.cdn.blizzard.com
FR
unknown
4088
Battle.net-Setup.exe
137.221.64.5:80
eu.cdn.blizzard.com
FR
suspicious

DNS requests

Domain
IP
Reputation
nydus.battle.net
  • 37.244.28.104
suspicious
iir.blizzard.com
  • 24.105.29.24
suspicious
www.google-analytics.com
  • 172.217.18.174
whitelisted
eu.patch.battle.net
  • 37.244.28.30
whitelisted
eu.cdn.blizzard.com
  • 137.221.64.8
  • 137.221.64.1
  • 137.221.64.3
  • 137.221.64.7
  • 137.221.64.4
  • 137.221.64.6
  • 137.221.64.5
  • 137.221.64.2
whitelisted
level3.ssl.blizzard.com
  • 8.241.9.1
  • 8.248.126.20
  • 8.241.81.169
  • 8.241.122.1
  • 8.248.128.20
  • 67.27.157.129
unknown
level3.blizzard.com
  • 8.253.207.110
  • 8.253.207.121
  • 8.253.207.109
  • 8.241.123.254
  • 8.241.123.126
suspicious
blzddist1-a.akamaihd.net
  • 2.16.186.48
  • 2.16.186.120
whitelisted
telemetry-in.battle.net
  • 24.105.29.76
unknown
ocsp.digicert.com
  • 93.184.220.29
whitelisted

Threats

No threats detected
Process
Message
Agent.exe
DEBUG (TELE): [2136]: Chosen raw Locale: English_United States.1252
Agent.exe
DEBUG (TELE): [2136]: Chosen cooked Locale: English_United States
Agent.exe
DEBUG (TELE): [2136]: Current Locale: C
Battle.net.exe
[0118/173035.937:ERROR:ssl_client_socket_impl.cc(947)] handshake failed; returned -1, SSL error code 1, net_error -101
Battle.net.exe
[0118/173036.101:ERROR:ssl_client_socket_impl.cc(947)] handshake failed; returned -1, SSL error code 1, net_error -101