File name:

GPT_Chorme_installer.exe

Full analysis: https://app.any.run/tasks/1243145f-81da-4f85-8e56-8888137252d2
Verdict: Malicious activity
Analysis date: January 20, 2025, 14:29:06
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
auto
generic
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

AD90E265345CD45C02B3698D60A53337

SHA1:

B2DC1C2D1E8162DED9D83248F4453D4B0C8B0BE1

SHA256:

04E45B9D973EABE61733CB378B607C7A8EB8890E0F1C588B2DB0AADD1C03F9B5

SSDEEP:

98304:CjC+FubTuta5+ag0hfIJvnEgAZHEt7Rt+/KMagvVQQzhCR2hELS/2u2LwIBQIQ:z

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 7za.exe (PID: 6292)
      • GPT_Chorme_installer.exe (PID: 6324)
    • Application launched itself

      • GPT_Chorme_installer.exe (PID: 5616)
      • GptBrowser.exe (PID: 4624)
      • GptBrowser.exe (PID: 4648)
      • GptBrowser.exe (PID: 1200)
      • GptBrowser.exe (PID: 4020)
      • GptBrowser.exe (PID: 5236)
      • GptBrowser.exe (PID: 5096)
      • GptBrowser.exe (PID: 4024)
    • Reads security settings of Internet Explorer

      • GPT_Chorme_installer.exe (PID: 5616)
      • GPT_Chorme_installer.exe (PID: 6324)
      • GptBrowser.exe (PID: 7284)
      • GptBrowser.exe (PID: 4648)
      • GptBrowser.exe (PID: 7568)
      • GptBrowser.exe (PID: 7648)
      • GptBrowser.exe (PID: 8060)
      • GptBrowser.exe (PID: 4024)
    • Drops 7-zip archiver for unpacking

      • GPT_Chorme_installer.exe (PID: 6324)
    • Process drops legitimate windows executable

      • 7za.exe (PID: 6292)
    • Creates a software uninstall entry

      • GPT_Chorme_installer.exe (PID: 6324)
    • Executes as Windows Service

      • GptChromeService.exe (PID: 3632)
    • There is functionality for taking screenshot (YARA)

      • GPT_Chorme_installer.exe (PID: 6324)
    • Read disk information to detect sandboxing environments

      • GptBrowser.exe (PID: 4648)
    • Searches for installed software

      • GptBrowser.exe (PID: 4648)
    • Connects to unusual port

      • SpUpdate.exe (PID: 6344)
      • SpUpdate.exe (PID: 5764)
  • INFO

    • Checks supported languages

      • GPT_Chorme_installer.exe (PID: 5616)
      • GPT_Chorme_installer.exe (PID: 6324)
      • GptBrowser.exe (PID: 4648)
      • GptBrowser.exe (PID: 5748)
      • GptBrowser.exe (PID: 6520)
      • GptBrowser.exe (PID: 6524)
      • GptChromeService.exe (PID: 3632)
      • 7za.exe (PID: 6292)
      • GptBrowser.exe (PID: 1200)
      • GptBrowser.exe (PID: 8)
      • GptBrowser.exe (PID: 7160)
      • GptBrowser.exe (PID: 4628)
      • GptBrowser.exe (PID: 1668)
      • GptBrowser.exe (PID: 7136)
      • GptBrowser.exe (PID: 3688)
      • GptBrowser.exe (PID: 1472)
      • GptBrowser.exe (PID: 2956)
      • GptBrowser.exe (PID: 556)
      • GptBrowser.exe (PID: 6956)
      • GptBrowser.exe (PID: 1216)
      • GptBrowser.exe (PID: 4528)
      • GptBrowser.exe (PID: 4144)
      • GptBrowser.exe (PID: 1852)
      • GptBrowser.exe (PID: 1476)
      • GptBrowser.exe (PID: 4968)
      • GptBrowser.exe (PID: 6984)
      • GptBrowser.exe (PID: 7532)
      • SpUpdate.exe (PID: 5764)
      • GptBrowser.exe (PID: 7772)
      • GptBrowser.exe (PID: 7836)
      • GptBrowser.exe (PID: 7948)
      • GptBrowser.exe (PID: 7284)
      • GptBrowser.exe (PID: 7648)
      • GptBrowser.exe (PID: 8004)
      • GptBrowser.exe (PID: 7044)
      • GptBrowser.exe (PID: 7036)
      • GptBrowser.exe (PID: 7684)
      • GptBrowser.exe (PID: 7908)
      • GptBrowser.exe (PID: 7296)
      • GptBrowser.exe (PID: 7824)
      • GptBrowser.exe (PID: 7344)
      • GptBrowser.exe (PID: 8048)
      • GptBrowser.exe (PID: 7476)
      • GptBrowser.exe (PID: 5092)
      • GptBrowser.exe (PID: 6096)
      • GptBrowser.exe (PID: 3080)
    • Creates files or folders in the user directory

      • 7za.exe (PID: 6292)
      • GPT_Chorme_installer.exe (PID: 6324)
      • GptBrowser.exe (PID: 4648)
      • GptBrowser.exe (PID: 6520)
      • GptBrowser.exe (PID: 1200)
      • SpUpdate.exe (PID: 6344)
      • GptBrowser.exe (PID: 7948)
      • GptBrowser.exe (PID: 4024)
    • Reads the computer name

      • GPT_Chorme_installer.exe (PID: 5616)
      • GptBrowser.exe (PID: 4648)
      • GptBrowser.exe (PID: 6524)
      • 7za.exe (PID: 6292)
      • GPT_Chorme_installer.exe (PID: 6324)
      • GptBrowser.exe (PID: 1200)
      • GptChromeService.exe (PID: 3632)
      • GptBrowser.exe (PID: 7568)
      • GptBrowser.exe (PID: 8060)
      • GptBrowser.exe (PID: 7648)
      • GptBrowser.exe (PID: 4024)
    • The process uses the downloaded file

      • GPT_Chorme_installer.exe (PID: 5616)
      • GPT_Chorme_installer.exe (PID: 6324)
      • GptBrowser.exe (PID: 7948)
      • GptBrowser.exe (PID: 4024)
    • Process checks computer location settings

      • GPT_Chorme_installer.exe (PID: 5616)
      • GPT_Chorme_installer.exe (PID: 6324)
      • GptBrowser.exe (PID: 4648)
      • GptBrowser.exe (PID: 7136)
      • GptBrowser.exe (PID: 7160)
      • GptBrowser.exe (PID: 3688)
      • GptBrowser.exe (PID: 4144)
      • GptBrowser.exe (PID: 1668)
      • GptBrowser.exe (PID: 4628)
      • GptBrowser.exe (PID: 4968)
      • GptBrowser.exe (PID: 4528)
      • GptBrowser.exe (PID: 7824)
      • GptBrowser.exe (PID: 7684)
      • GptBrowser.exe (PID: 5092)
      • GptBrowser.exe (PID: 8048)
    • The sample compiled with english language support

      • GPT_Chorme_installer.exe (PID: 6324)
      • 7za.exe (PID: 6292)
    • The sample compiled with chinese language support

      • 7za.exe (PID: 6292)
    • Checks proxy server information

      • GptBrowser.exe (PID: 4648)
      • GptBrowser.exe (PID: 7284)
      • GptBrowser.exe (PID: 7292)
      • GptBrowser.exe (PID: 8060)
      • GptBrowser.exe (PID: 4024)
    • Creates files in the program directory

      • GPT_Chorme_installer.exe (PID: 6324)
    • Sends debugging messages

      • GptChromeService.exe (PID: 3632)
    • Reads the machine GUID from the registry

      • GptBrowser.exe (PID: 4648)
    • Manual execution by a user

      • GptBrowser.exe (PID: 5236)
    • Create files in a temporary directory

      • GptBrowser.exe (PID: 4648)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (18)
.exe | Win32 Executable (generic) (2.9)
.exe | Generic Win/DOS Executable (1.3)
.exe | DOS Executable Generic (1.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:08:22 17:03:04+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.35
CodeSize: 927232
InitializedDataSize: 1783296
UninitializedDataSize: -
EntryPoint: 0xb83be
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 109.0.5414.185
ProductVersionNumber: 109.0.5414.185
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: Guangxi Yuehai Yinghua Network Technology Co., Ltd.
FileDescription: GPT浏览器安装程序
FileVersion: 109.0.5414.185
InternalName: GptChrome
LegalCopyright: Copyright (C) 2024
OriginalFileName: GptChrome
ProductName: GPT浏览器
ProductVersion: 109.0.5414.185
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
222
Monitored processes
89
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start gpt_chorme_installer.exe no specs gpt_chorme_installer.exe 7za.exe conhost.exe no specs explorer.exe no specs explorer.exe no specs gptbrowser.exe gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe gptbrowser.exe no specs gptbrowser.exe no specs gptchromeservice.exe gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs spupdate.exe gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs spupdate.exe gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs gptbrowser.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
8"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --extension-process --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --field-trial-handle=3696,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=3624 /prefetch:2C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
LOW
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.212
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.212\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
556"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --field-trial-handle=5448,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=5572 /prefetch:1C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
LOW
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.212
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.212\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1200"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --no-startup-windowC:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptChromeService.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
MEDIUM
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.212
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.212\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
1216"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --extension-process --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --field-trial-handle=6316,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=6328 /prefetch:2C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
LOW
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.212
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.212\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1292"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=32 --field-trial-handle=8004,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=7804 /prefetch:1C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
LOW
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.212
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
1472"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=19 --field-trial-handle=5824,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=5840 /prefetch:1C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
LOW
Description:
GptBrowser
Version:
128.0.6541.212
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.212\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1476C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\SPChrome\User Data" /prefetch:4 --no-periodic-tasks --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\SPChrome\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=GptBrowser --annotation=ver=128.0.6541.212 --initial-client-data=0xf8,0x130,0x134,0x1ac,0x12c,0x7ff7a1488bf8,0x7ff7a1488c04,0x7ff7a1488c10C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
MEDIUM
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.212
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.212\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
1476"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=60 --field-trial-handle=6376,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=9492 /prefetch:1C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
LOW
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.212
1540"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-GB --service-sandbox-type=none --field-trial-handle=7836,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=7676 /prefetch:8C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
MEDIUM
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.212
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.212\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
1668"C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --extension-process --init-isolate-as-foreground --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --field-trial-handle=4140,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=4296 /prefetch:2C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exeGptBrowser.exe
User:
admin
Company:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
Integrity Level:
LOW
Description:
GptBrowser
Exit code:
0
Version:
128.0.6541.212
Modules
Images
c:\users\admin\appdata\local\gptchrome\gptbrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gptchrome\128.0.6541.212\chrome_elf.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
Total events
22 200
Read events
21 972
Write events
221
Delete events
7

Modification events

(PID) Process:(6324) GPT_Chorme_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\GptChrome\VisualElements\logo.ico
(PID) Process:(6324) GPT_Chorme_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:DisplayName
Value:
GPT Chrome
(PID) Process:(6324) GPT_Chorme_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\GptChrome
(PID) Process:(6324) GPT_Chorme_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:Publisher
Value:
Guangxi Yuehai Yinghua Network Technology Co., Ltd.
(PID) Process:(6324) GPT_Chorme_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\GptChrome\uninstall.exe" --uninstall
(PID) Process:(6324) GPT_Chorme_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:PackageName
Value:
GPT_Chorme_installer.exe
(PID) Process:(6324) GPT_Chorme_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:DisplayVersion
Value:
109.0.5414.185
(PID) Process:(6324) GPT_Chorme_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome
Operation:writeName:InstallDate
Value:
1737383449
(PID) Process:(6324) GPT_Chorme_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TSBrowserHTM.pdf\Application
Operation:writeName:ApplicationCompany
Value:
The GPT Chrome Authors
(PID) Process:(6324) GPT_Chorme_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TSBrowserHTM.pdf\Application
Operation:writeName:ApplicationDescription
Value:
访问互联网
Executable files
29
Suspicious files
424
Text files
69
Unknown types
6

Dropped files

PID
Process
Filename
Type
6324GPT_Chorme_installer.exeC:\Users\admin\AppData\Local\GptChrome\GInstallerPkg
MD5:
SHA256:
62927za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\chrome.dll
MD5:
SHA256:
62927za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\icudtl.dat
MD5:
SHA256:
62927za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\icudtlex.dat
MD5:
SHA256:
62927za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\dxcompiler.dllexecutable
MD5:DC77A97306BC35125690AEAB2AE84F55
SHA256:DCDF50A6AD628FB18D345B7EE4EE69B648217DFFEDD6667D385C5822ACA0230A
62927za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\128.0.6541.212.manifesttext
MD5:0142BCBD86A1AC81441BFB68177C27D4
SHA256:59DD0BA4811F8390C8DEFA50CC8C852F5C864B774747E12E1930E3867B297548
62927za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\Extensions\external_extensions.jsontext
MD5:280A9277B0E605E905D7F18B6148EEB7
SHA256:A68CAFD7D78D5C671C2560656653F2A4D83AB66D87A8728356A88FB1F477B3E6
62927za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\libGLESv2.dllexecutable
MD5:6FBFB478AA179B57DC40332B6FED96D9
SHA256:D5AB90F63DB2FADD77BD7059CBBC724CA422B46A53B52992FF1FD25404383FC2
62927za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\chrome_100_percent.pakbinary
MD5:A03FA168AFB041E27788865B74F96730
SHA256:75EA7BCF8FE9C4414D5C25F70250D733FFF3E00BD1213DDEAC2B564322AA3CB5
62927za.exeC:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\Locales\ar.pakbinary
MD5:8F9EAE4B4EF9C547CA1CF92F1EA4B447
SHA256:21C0A8AA20F96310B7364486A02F1BB7971C4AF0C8BD31A64C3D944FDAEBDA56
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
42
TCP/UDP connections
144
DNS requests
106
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6324
GPT_Chorme_installer.exe
GET
200
121.199.42.172:80
http://work.yhyhtech.com/mm/
unknown
unknown
6324
GPT_Chorme_installer.exe
GET
200
121.199.42.172:80
http://work.yhyhtech.com/afg/?para=GNXYbx/fYXOcz4idWG2NxA6U4GaFOKaXneGrhDZGy4nkxnZAnuJbWf/SS+C+uPvuK5uidHj0ba6Pz6+cO7d8OXjN4VJIJMcT1IjsGQdENW/W9Rt2hyxCH4lxmq8PCxIFtIR1S+fDWhcvEll5FVqP9SHJ9/B9Bu5P92ouK0VYUryLcOdRnAwvRlxaEfD7kerNgwIyWlY1o7R0jlkfc8kDedn3pN0SVNc1MepS6bIwS4w=
unknown
unknown
6324
GPT_Chorme_installer.exe
GET
112.47.51.147:80
http://dw.gptchrome.net/bropkg/GInstallerx64-185
unknown
unknown
6324
GPT_Chorme_installer.exe
GET
200
121.199.42.172:80
http://work.yhyhtech.com/afg/?para=45mAVULeOfWtJoodWPmEwQ6U4GaFOKaXneGrhDZGy4nkxnZAnuJbWf/SS+C+uPvuK5uidHj0ba6Pz6+cO7d8OXjN4VJIJMcT1IjsGQdENW/W9Rt2hyxCH4lxmq8PCxIFtIR1S+fDWhcvEll5FVqP9SHJ9/B9Bu5P92ouK0VYUryLcOdRnAwvRlxaEfD7kerNgwIyWlY1o7R0jlkfc8kDedn3pN0SVNc1MepS6bIwS4w=
unknown
unknown
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6324
GPT_Chorme_installer.exe
GET
200
121.199.42.172:80
http://work.yhyhtech.com/afg/?para=+VJCMTVAyvGG0tTizjEIow6U4GaFOKaXneGrhDZGy4nkxnZAnuJbWf/SS+C+uPvuK5uidHj0ba6Pz6+cO7d8OXjN4VJIJMcT1IjsGQdENW/W9Rt2hyxCH4lxmq8PCxIFtIR1S+fDWhcvEll5FVqP9SHJ9/B9Bu5P92ouK0VYUryLcOdRnAwvRlxaEfD7kerNgwIyWlY1o7R0jlkfc8kDedn3pN0SVNc1MepS6bIwS4w=
unknown
unknown
6572
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6572
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.72:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1076
svchost.exe
2.23.242.9:443
go.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
6324
GPT_Chorme_installer.exe
121.199.42.172:80
work.yhyhtech.com
Hangzhou Alibaba Advertising Co.,Ltd.
CN
unknown
5064
SearchApp.exe
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.181.238
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.9
  • 2.16.164.106
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.246.101
whitelisted
go.microsoft.com
  • 2.23.242.9
whitelisted
work.yhyhtech.com
  • 121.199.42.172
unknown
www.bing.com
  • 2.23.227.208
  • 2.23.227.221
  • 2.23.227.215
whitelisted
dw.gptchrome.net
  • 112.47.51.147
  • 112.47.51.148
  • 112.47.51.146
unknown
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

PID
Process
Class
Message
6520
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
6520
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
6520
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
6520
GptBrowser.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
Process
Message
GptChromeService.exe
GptChromeSrv start init communicator
GptChromeService.exe
GptChromeSrv start init communicator done