| File name: | GPT_Chorme_installer.exe |
| Full analysis: | https://app.any.run/tasks/1243145f-81da-4f85-8e56-8888137252d2 |
| Verdict: | Malicious activity |
| Analysis date: | January 20, 2025, 14:29:06 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | AD90E265345CD45C02B3698D60A53337 |
| SHA1: | B2DC1C2D1E8162DED9D83248F4453D4B0C8B0BE1 |
| SHA256: | 04E45B9D973EABE61733CB378B607C7A8EB8890E0F1C588B2DB0AADD1C03F9B5 |
| SSDEEP: | 98304:CjC+FubTuta5+ag0hfIJvnEgAZHEt7Rt+/KMagvVQQzhCR2hELS/2u2LwIBQIQ:z |
| .exe | | | Win64 Executable (generic) (18) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (2.9) |
| .exe | | | Generic Win/DOS Executable (1.3) |
| .exe | | | DOS Executable Generic (1.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:08:22 17:03:04+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.35 |
| CodeSize: | 927232 |
| InitializedDataSize: | 1783296 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb83be |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 109.0.5414.185 |
| ProductVersionNumber: | 109.0.5414.185 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | Guangxi Yuehai Yinghua Network Technology Co., Ltd. |
| FileDescription: | GPT浏览器安装程序 |
| FileVersion: | 109.0.5414.185 |
| InternalName: | GptChrome |
| LegalCopyright: | Copyright (C) 2024 |
| OriginalFileName: | GptChrome |
| ProductName: | GPT浏览器 |
| ProductVersion: | 109.0.5414.185 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 8 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --extension-process --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --field-trial-handle=3696,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=3624 /prefetch:2 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: LOW Description: GptBrowser Exit code: 0 Version: 128.0.6541.212 Modules
| |||||||||||||||
| 556 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --field-trial-handle=5448,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=5572 /prefetch:1 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: LOW Description: GptBrowser Exit code: 0 Version: 128.0.6541.212 Modules
| |||||||||||||||
| 1200 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --no-startup-window | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptChromeService.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: MEDIUM Description: GptBrowser Exit code: 0 Version: 128.0.6541.212 Modules
| |||||||||||||||
| 1216 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --extension-process --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --field-trial-handle=6316,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=6328 /prefetch:2 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: LOW Description: GptBrowser Exit code: 0 Version: 128.0.6541.212 Modules
| |||||||||||||||
| 1292 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=32 --field-trial-handle=8004,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=7804 /prefetch:1 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: LOW Description: GptBrowser Exit code: 0 Version: 128.0.6541.212 Modules
| |||||||||||||||
| 1472 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=19 --field-trial-handle=5824,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=5840 /prefetch:1 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: LOW Description: GptBrowser Version: 128.0.6541.212 Modules
| |||||||||||||||
| 1476 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\SPChrome\User Data" /prefetch:4 --no-periodic-tasks --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\SPChrome\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=GptBrowser --annotation=ver=128.0.6541.212 --initial-client-data=0xf8,0x130,0x134,0x1ac,0x12c,0x7ff7a1488bf8,0x7ff7a1488c04,0x7ff7a1488c10 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: MEDIUM Description: GptBrowser Exit code: 0 Version: 128.0.6541.212 Modules
| |||||||||||||||
| 1476 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=60 --field-trial-handle=6376,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=9492 /prefetch:1 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: LOW Description: GptBrowser Exit code: 0 Version: 128.0.6541.212 | |||||||||||||||
| 1540 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-GB --service-sandbox-type=none --field-trial-handle=7836,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=7676 /prefetch:8 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: MEDIUM Description: GptBrowser Exit code: 0 Version: 128.0.6541.212 Modules
| |||||||||||||||
| 1668 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --extension-process --init-isolate-as-foreground --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --field-trial-handle=4140,i,2724400198797629123,14658473061197605353,262144 --variations-seed-version --mojo-platform-channel-handle=4296 /prefetch:2 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: LOW Description: GptBrowser Exit code: 0 Version: 128.0.6541.212 Modules
| |||||||||||||||
| (PID) Process: | (6324) GPT_Chorme_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Users\admin\AppData\Local\GptChrome\VisualElements\logo.ico | |||
| (PID) Process: | (6324) GPT_Chorme_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | DisplayName |
Value: GPT Chrome | |||
| (PID) Process: | (6324) GPT_Chorme_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | InstallLocation |
Value: C:\Users\admin\AppData\Local\GptChrome | |||
| (PID) Process: | (6324) GPT_Chorme_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | Publisher |
Value: Guangxi Yuehai Yinghua Network Technology Co., Ltd. | |||
| (PID) Process: | (6324) GPT_Chorme_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | UninstallString |
Value: "C:\Users\admin\AppData\Local\GptChrome\uninstall.exe" --uninstall | |||
| (PID) Process: | (6324) GPT_Chorme_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | PackageName |
Value: GPT_Chorme_installer.exe | |||
| (PID) Process: | (6324) GPT_Chorme_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | DisplayVersion |
Value: 109.0.5414.185 | |||
| (PID) Process: | (6324) GPT_Chorme_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | InstallDate |
Value: 1737383449 | |||
| (PID) Process: | (6324) GPT_Chorme_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TSBrowserHTM.pdf\Application |
| Operation: | write | Name: | ApplicationCompany |
Value: The GPT Chrome Authors | |||
| (PID) Process: | (6324) GPT_Chorme_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TSBrowserHTM.pdf\Application |
| Operation: | write | Name: | ApplicationDescription |
Value: 访问互联网 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6324 | GPT_Chorme_installer.exe | C:\Users\admin\AppData\Local\GptChrome\GInstallerPkg | — | |
MD5:— | SHA256:— | |||
| 6292 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\chrome.dll | — | |
MD5:— | SHA256:— | |||
| 6292 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\icudtl.dat | — | |
MD5:— | SHA256:— | |||
| 6292 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\icudtlex.dat | — | |
MD5:— | SHA256:— | |||
| 6292 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\dxcompiler.dll | executable | |
MD5:DC77A97306BC35125690AEAB2AE84F55 | SHA256:DCDF50A6AD628FB18D345B7EE4EE69B648217DFFEDD6667D385C5822ACA0230A | |||
| 6292 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\128.0.6541.212.manifest | text | |
MD5:0142BCBD86A1AC81441BFB68177C27D4 | SHA256:59DD0BA4811F8390C8DEFA50CC8C852F5C864B774747E12E1930E3867B297548 | |||
| 6292 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\Extensions\external_extensions.json | text | |
MD5:280A9277B0E605E905D7F18B6148EEB7 | SHA256:A68CAFD7D78D5C671C2560656653F2A4D83AB66D87A8728356A88FB1F477B3E6 | |||
| 6292 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\libGLESv2.dll | executable | |
MD5:6FBFB478AA179B57DC40332B6FED96D9 | SHA256:D5AB90F63DB2FADD77BD7059CBBC724CA422B46A53B52992FF1FD25404383FC2 | |||
| 6292 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\chrome_100_percent.pak | binary | |
MD5:A03FA168AFB041E27788865B74F96730 | SHA256:75EA7BCF8FE9C4414D5C25F70250D733FFF3E00BD1213DDEAC2B564322AA3CB5 | |||
| 6292 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.212\Locales\ar.pak | binary | |
MD5:8F9EAE4B4EF9C547CA1CF92F1EA4B447 | SHA256:21C0A8AA20F96310B7364486A02F1BB7971C4AF0C8BD31A64C3D944FDAEBDA56 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.72:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6324 | GPT_Chorme_installer.exe | GET | 200 | 121.199.42.172:80 | http://work.yhyhtech.com/mm/ | unknown | — | — | unknown |
6324 | GPT_Chorme_installer.exe | GET | 200 | 121.199.42.172:80 | http://work.yhyhtech.com/afg/?para=GNXYbx/fYXOcz4idWG2NxA6U4GaFOKaXneGrhDZGy4nkxnZAnuJbWf/SS+C+uPvuK5uidHj0ba6Pz6+cO7d8OXjN4VJIJMcT1IjsGQdENW/W9Rt2hyxCH4lxmq8PCxIFtIR1S+fDWhcvEll5FVqP9SHJ9/B9Bu5P92ouK0VYUryLcOdRnAwvRlxaEfD7kerNgwIyWlY1o7R0jlkfc8kDedn3pN0SVNc1MepS6bIwS4w= | unknown | — | — | unknown |
6324 | GPT_Chorme_installer.exe | GET | — | 112.47.51.147:80 | http://dw.gptchrome.net/bropkg/GInstallerx64-185 | unknown | — | — | unknown |
6324 | GPT_Chorme_installer.exe | GET | 200 | 121.199.42.172:80 | http://work.yhyhtech.com/afg/?para=45mAVULeOfWtJoodWPmEwQ6U4GaFOKaXneGrhDZGy4nkxnZAnuJbWf/SS+C+uPvuK5uidHj0ba6Pz6+cO7d8OXjN4VJIJMcT1IjsGQdENW/W9Rt2hyxCH4lxmq8PCxIFtIR1S+fDWhcvEll5FVqP9SHJ9/B9Bu5P92ouK0VYUryLcOdRnAwvRlxaEfD7kerNgwIyWlY1o7R0jlkfc8kDedn3pN0SVNc1MepS6bIwS4w= | unknown | — | — | unknown |
4712 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
6324 | GPT_Chorme_installer.exe | GET | 200 | 121.199.42.172:80 | http://work.yhyhtech.com/afg/?para=+VJCMTVAyvGG0tTizjEIow6U4GaFOKaXneGrhDZGy4nkxnZAnuJbWf/SS+C+uPvuK5uidHj0ba6Pz6+cO7d8OXjN4VJIJMcT1IjsGQdENW/W9Rt2hyxCH4lxmq8PCxIFtIR1S+fDWhcvEll5FVqP9SHJ9/B9Bu5P92ouK0VYUryLcOdRnAwvRlxaEfD7kerNgwIyWlY1o7R0jlkfc8kDedn3pN0SVNc1MepS6bIwS4w= | unknown | — | — | unknown |
6572 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6572 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.16.164.72:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 2.23.227.208:443 | www.bing.com | Ooredoo Q.S.C. | QA | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1076 | svchost.exe | 2.23.242.9:443 | go.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
6324 | GPT_Chorme_installer.exe | 121.199.42.172:80 | work.yhyhtech.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
5064 | SearchApp.exe | 2.23.227.208:443 | www.bing.com | Ooredoo Q.S.C. | QA | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
work.yhyhtech.com |
| unknown |
www.bing.com |
| whitelisted |
dw.gptchrome.net |
| unknown |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6520 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
6520 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
6520 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
6520 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
Process | Message |
|---|---|
GptChromeService.exe | GptChromeSrv start init communicator |
GptChromeService.exe | GptChromeSrv start init communicator done |