| File name: | ChormeGPT_install.exe |
| Full analysis: | https://app.any.run/tasks/fce7cc3c-60e0-4eee-958d-dfe2507a65e2 |
| Verdict: | Malicious activity |
| Analysis date: | November 11, 2024, 07:51:03 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | AD90E265345CD45C02B3698D60A53337 |
| SHA1: | B2DC1C2D1E8162DED9D83248F4453D4B0C8B0BE1 |
| SHA256: | 04E45B9D973EABE61733CB378B607C7A8EB8890E0F1C588B2DB0AADD1C03F9B5 |
| SSDEEP: | 98304:CjC+FubTuta5+ag0hfIJvnEgAZHEt7Rt+/KMagvVQQzhCR2hELS/2u2LwIBQIQ:z |
| .exe | | | Win64 Executable (generic) (18) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (2.9) |
| .exe | | | Generic Win/DOS Executable (1.3) |
| .exe | | | DOS Executable Generic (1.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:08:22 17:03:04+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.35 |
| CodeSize: | 927232 |
| InitializedDataSize: | 1783296 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb83be |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 109.0.5414.185 |
| ProductVersionNumber: | 109.0.5414.185 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | Guangxi Yuehai Yinghua Network Technology Co., Ltd. |
| FileDescription: | GPT浏览器安装程序 |
| FileVersion: | 109.0.5414.185 |
| InternalName: | GptChrome |
| LegalCopyright: | Copyright (C) 2024 |
| OriginalFileName: | GptChrome |
| ProductName: | GPT浏览器 |
| ProductVersion: | 109.0.5414.185 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 780 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --extension-process --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=3992,i,12448589670985195433,15541092309644490407,262144 --variations-seed-version --mojo-platform-channel-handle=4004 /prefetch:2 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: LOW Description: GptBrowser Exit code: 0 Version: 128.0.6541.205 Modules
| |||||||||||||||
| 848 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --field-trial-handle=5316,i,12448589670985195433,15541092309644490407,262144 --variations-seed-version --mojo-platform-channel-handle=5444 /prefetch:1 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: LOW Description: GptBrowser Exit code: 0 Version: 128.0.6541.205 Modules
| |||||||||||||||
| 1112 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=14 --field-trial-handle=5292,i,12448589670985195433,15541092309644490407,262144 --variations-seed-version --mojo-platform-channel-handle=5308 /prefetch:1 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: LOW Description: GptBrowser Exit code: 0 Version: 128.0.6541.205 Modules
| |||||||||||||||
| 1432 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --extension-process --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --field-trial-handle=4372,i,12448589670985195433,15541092309644490407,262144 --variations-seed-version --mojo-platform-channel-handle=4388 /prefetch:2 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: LOW Description: GptBrowser Exit code: 0 Version: 128.0.6541.205 Modules
| |||||||||||||||
| 1792 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=renderer --video-capture-use-gpu-memory-buffer --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=19 --field-trial-handle=5888,i,12448589670985195433,15541092309644490407,262144 --variations-seed-version --mojo-platform-channel-handle=5288 /prefetch:1 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: LOW Description: GptBrowser Version: 128.0.6541.205 Modules
| |||||||||||||||
| 1884 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | explorer.exe | ||||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: MEDIUM Description: GptBrowser Version: 128.0.6541.205 Modules
| |||||||||||||||
| 2100 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\SPChrome\User Data" /prefetch:4 --monitor-self --monitor-self-argument=--type=crashpad-handler "--monitor-self-argument=--user-data-dir=C:\Users\admin\AppData\Local\SPChrome\User Data" --monitor-self-argument=/prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\SPChrome\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=GptBrowser --annotation=ver=128.0.6541.205 --initial-client-data=0x128,0x12c,0x130,0x100,0x134,0x7ffbca57fea8,0x7ffbca57feb4,0x7ffbca57fec0 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: MEDIUM Description: GptBrowser Exit code: 0 Version: 128.0.6541.205 Modules
| |||||||||||||||
| 2376 | "C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --start-stack-profiler --field-trial-handle=2200,i,12448589670985195433,15541092309644490407,262144 --variations-seed-version --mojo-platform-channel-handle=2320 /prefetch:3 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | GptBrowser.exe | ||||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: MEDIUM Description: GptBrowser Version: 128.0.6541.205 Modules
| |||||||||||||||
| 2428 | "C:\Users\admin\AppData\Local\GptChrome\7za.exe" x "C:\Users\admin\AppData\Local\GptChrome\GInstallerPkg" -o"C:\Users\admin\AppData\Local\GptChrome" -aoa -y -p"ydhffhJsffFEfvgyu" | C:\Users\admin\AppData\Local\GptChrome\7za.exe | ChormeGPT_install.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7-Zip Standalone Console Exit code: 0 Version: 19.00 Modules
| |||||||||||||||
| 2576 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\SPChrome\User Data" /prefetch:4 --no-periodic-tasks --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\SPChrome\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=GptBrowser --annotation=ver=128.0.6541.205 --initial-client-data=0x164,0x168,0x16c,0x160,0x170,0x7ff6f4e18bf8,0x7ff6f4e18c04,0x7ff6f4e18c10 | C:\Users\admin\AppData\Local\GptChrome\GptBrowser.exe | — | GptBrowser.exe | |||||||||||
User: admin Company: Guangxi Yuehai Yinghua Network Technology Co., Ltd. Integrity Level: MEDIUM Description: GptBrowser Exit code: 0 Version: 128.0.6541.205 Modules
| |||||||||||||||
| (PID) Process: | (4508) ChormeGPT_install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Users\admin\AppData\Local\GptChrome\VisualElements\logo.ico | |||
| (PID) Process: | (4508) ChormeGPT_install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | DisplayName |
Value: GPT Chrome | |||
| (PID) Process: | (4508) ChormeGPT_install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | InstallLocation |
Value: C:\Users\admin\AppData\Local\GptChrome | |||
| (PID) Process: | (4508) ChormeGPT_install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | Publisher |
Value: Guangxi Yuehai Yinghua Network Technology Co., Ltd. | |||
| (PID) Process: | (4508) ChormeGPT_install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | UninstallString |
Value: "C:\Users\admin\AppData\Local\GptChrome\uninstall.exe" --uninstall | |||
| (PID) Process: | (4508) ChormeGPT_install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | PackageName |
Value: ChormeGPT_install.exe | |||
| (PID) Process: | (4508) ChormeGPT_install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | DisplayVersion |
Value: 109.0.5414.185 | |||
| (PID) Process: | (4508) ChormeGPT_install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GptChrome |
| Operation: | write | Name: | InstallDate |
Value: 1731311551 | |||
| (PID) Process: | (4508) ChormeGPT_install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TSBrowserHTM.pdf\Application |
| Operation: | write | Name: | ApplicationCompany |
Value: The GPT Chrome Authors | |||
| (PID) Process: | (4508) ChormeGPT_install.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TSBrowserHTM.pdf\Application |
| Operation: | write | Name: | ApplicationDescription |
Value: 访问互联网 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4508 | ChormeGPT_install.exe | C:\Users\admin\AppData\Local\GptChrome\GInstallerPkg | — | |
MD5:— | SHA256:— | |||
| 2428 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\chrome.dll | — | |
MD5:— | SHA256:— | |||
| 2428 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\icudtl.dat | — | |
MD5:— | SHA256:— | |||
| 2428 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\icudtlex.dat | — | |
MD5:— | SHA256:— | |||
| 2428 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\chrome_pwa_launcher.exe | executable | |
MD5:4A045F2A32E2FF6AECA13997C680F4F2 | SHA256:7932C54BECE0F013F3318AD5181475C3640EBD16A19D532B51C27749F96CA05C | |||
| 2428 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\chrome_100_percent.pak | binary | |
MD5:A03FA168AFB041E27788865B74F96730 | SHA256:75EA7BCF8FE9C4414D5C25F70250D733FFF3E00BD1213DDEAC2B564322AA3CB5 | |||
| 2428 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\chrome_wer.dll | executable | |
MD5:9E734A474804E05A70D78817640F930A | SHA256:B653855E7E7AFB59BC50288B048F6D3D5B002A7C3346853B0B78F659E1EFB8F3 | |||
| 2428 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\Locales\af.pak | mmw | |
MD5:167427A06792D7687A6F4A9ABFDB5CDD | SHA256:74329D124075805A3C2968D8953A6D81B694A0022FC589CF5FC02B153F7D208A | |||
| 2428 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\chrome_200_percent.pak | pgc | |
MD5:4ECE10C466D301B83BDBF9F59EBBC905 | SHA256:E2D6D21A799C8E2BB34C24CA5405E1BA67389BB833FF0CFC0AB6A17BF124E77E | |||
| 2428 | 7za.exe | C:\Users\admin\AppData\Local\GptChrome\128.0.6541.205\dxcompiler.dll | executable | |
MD5:DA3E2B1B3F8DF28835C7E6A8370968D1 | SHA256:57E1E35752E8C16FAA067542BA6EF5D75BDD2A451174B6765AFC96B9E69FA996 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4508 | ChormeGPT_install.exe | GET | 200 | 121.199.42.172:80 | http://work.yhyhtech.com/afg/?para=+VJCMTVAyvGG0tTizjEIow6U4GaFOKaXneGrhDZGy4mmUQMXwzGBmHwmsI3pRq5pPRwQxF/oSWZpWLktQYP056AIOl78FP6Iop7LkBuvQ64RQ3o+qeSes71T9F7T2wz2GwD5npbTPrZxo8oDA1XcXxlyR3ziM8K+xkFULz/q/Vd57af0C0w/2Ayl9UGO7lLeodQmAKqeS8r80m3grrWmm1EFQHV9kAJBfcTjF/mAD/Y= | unknown | — | — | unknown |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
4508 | ChormeGPT_install.exe | GET | 200 | 121.199.42.172:80 | http://work.yhyhtech.com/mm/ | unknown | — | — | unknown |
4508 | ChormeGPT_install.exe | GET | — | 121.199.42.172:80 | http://work.yhyhtech.com/afg/?para=GNXYbx/fYXOcz4idWG2NxA6U4GaFOKaXneGrhDZGy4mmUQMXwzGBmHwmsI3pRq5pPRwQxF/oSWZpWLktQYP056AIOl78FP6Iop7LkBuvQ64RQ3o+qeSes71T9F7T2wz2GwD5npbTPrZxo8oDA1XcXxlyR3ziM8K+xkFULz/q/Vd57af0C0w/2Ayl9UGO7lLeodQmAKqeS8r80m3grrWmm1EFQHV9kAJBfcTjF/mAD/Y= | unknown | — | — | unknown |
5488 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4376 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | GET | 200 | 23.53.40.178:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4508 | ChormeGPT_install.exe | GET | — | 221.178.86.52:80 | http://dw.gptchrome.net/bropkg/GInstallerx64-185 | unknown | — | — | unknown |
7124 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
7124 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6944 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5488 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
7060 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4360 | SearchApp.exe | 2.23.209.154:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4508 | ChormeGPT_install.exe | 121.199.42.172:80 | work.yhyhtech.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
4376 | svchost.exe | 20.190.159.4:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4376 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
work.yhyhtech.com |
| unknown |
login.live.com |
| whitelisted |
th.bing.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2376 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2376 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2376 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2376 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2376 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2376 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2376 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2376 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2376 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2376 | GptBrowser.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |