| File name: | 7l_csgo_setup.exe |
| Full analysis: | https://app.any.run/tasks/f916dc03-8d8e-477b-ac2d-ec9a85b68a3b |
| Verdict: | Malicious activity |
| Analysis date: | December 10, 2023, 16:36:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 86B89FB6E0D9686ED80102BBFD407E0F |
| SHA1: | 52F572AC1A311AEF284E68346774E9886922B16C |
| SHA256: | 1EBC12DB1D7131C46443AFBEEC0E3474D4834C1AC7A4DA9DBC726CF48F27BD94 |
| SSDEEP: | 98304:10wIjV3fxSSqNPo6IMH9l1BxJPq+zbed4eKq4BFGgH5BflYtqBxx0BWktD3EEzN3:roNZR |
| .exe | | | Win32 Executable Delphi generic (57.2) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (18.2) |
| .exe | | | Win16/32 Executable Delphi generic (8.3) |
| .exe | | | Generic Win/DOS Executable (8) |
| .exe | | | DOS Executable Generic (8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:06:14 15:27:46+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 66560 |
| InitializedDataSize: | 240640 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1181c |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | SE7EN Solutions |
| FileDescription: | 7Launcher CS:GO Setup |
| FileVersion: | 1.4.3 |
| LegalCopyright: | SE7EN Solutions |
| ProductName: | 7Launcher CS:GO |
| ProductVersion: | 1.4.3 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 284 | timeout /t 1 /nobreak | C:\Windows\System32\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1556 | "C:\Users\admin\AppData\Local\Temp\is-V57PI.tmp\7l_csgo_setup.tmp" /SL5="$1B0142,1749487,308224,C:\Users\admin\AppData\Local\Temp\7l_csgo_setup.exe" | C:\Users\admin\AppData\Local\Temp\is-V57PI.tmp\7l_csgo_setup.tmp | — | 7l_csgo_setup.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2404 | "taskkill.exe" /f /im "Run_CSGO.exe" | C:\Windows\System32\taskkill.exe | — | upt.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2764 | "taskkill.exe" /f /im "Run_CSGO.exe" | C:\Windows\System32\taskkill.exe | — | 7l_csgo_setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2856 | "C:\Program Files\Counter-Strike Global Offensive\Run_CS2.exe" /gnp 1 | C:\Program Files\Counter-Strike Global Offensive\Run_CS2.exe | explorer.exe | ||||||||||||
User: admin Company: SE7EN Solutions Ltd. Integrity Level: HIGH Description: 7Launcher − Counter-Strike 2 / CS:GO Exit code: 0 Version: 1.5.3.2 Modules
| |||||||||||||||
| 2968 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3044 | "C:\Program Files\Counter-Strike Global Offensive\Run_CSGO.exe" - forceupdate forcesteamcmd | C:\Program Files\Counter-Strike Global Offensive\Run_CSGO.exe | 7l_csgo_setup.tmp | ||||||||||||
User: admin Company: SE7EN Solutions, Ltd. Integrity Level: HIGH Description: 7Launcher − CS: GO Exit code: 0 Version: 1.4.3.0 Modules
| |||||||||||||||
| 3224 | "C:\Program Files\Counter-Strike Global Offensive\upt.exe" | C:\Program Files\Counter-Strike Global Offensive\upt.exe | — | Run_CSGO.exe | |||||||||||
User: admin Company: SE7EN Solutions Integrity Level: HIGH Description: 7Launcher - CS2 - CSGO Setup Exit code: 0 Version: 1.5.3.2 Modules
| |||||||||||||||
| 3240 | "C:\Program Files\Counter-Strike Global Offensive\Run_CS2.exe" /gnp 1 | C:\Program Files\Counter-Strike Global Offensive\Run_CS2.exe | — | explorer.exe | |||||||||||
User: admin Company: SE7EN Solutions Ltd. Integrity Level: MEDIUM Description: 7Launcher − Counter-Strike 2 / CS:GO Exit code: 3221226540 Version: 1.5.3.2 Modules
| |||||||||||||||
| 3264 | "C:\Users\admin\AppData\Local\Temp\7l_csgo_setup.exe" | C:\Users\admin\AppData\Local\Temp\7l_csgo_setup.exe | — | explorer.exe | |||||||||||
User: admin Company: SE7EN Solutions Integrity Level: MEDIUM Description: 7Launcher CS:GO Setup Exit code: 0 Version: 1.4.3 Modules
| |||||||||||||||
| (PID) Process: | (3964) 7l_csgo_setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3964) 7l_csgo_setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3964) 7l_csgo_setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3964) 7l_csgo_setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3044) Run_CSGO.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3044) Run_CSGO.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3044) Run_CSGO.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3044) Run_CSGO.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3044) Run_CSGO.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3044) Run_CSGO.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3964 | 7l_csgo_setup.tmp | C:\Program Files\Counter-Strike Global Offensive\platform\is-QRQJM.tmp | image | |
MD5:D7317EA62F2BBB651FAADA64FD23255B | SHA256:9B083A55C40B18426C872A78E4F3F2580B5326D4C8A1EDF5F96BFB8003B3322C | |||
| 3964 | 7l_csgo_setup.tmp | C:\Program Files\Counter-Strike Global Offensive\Run_CSGO.exe | executable | |
MD5:A2705FD332C70F6165E9F9CC9034014F | SHA256:601F72DF3A7D61E8313E38E296B95A3C26ADB93E8ED70BF1DF116B175CF6C72F | |||
| 3964 | 7l_csgo_setup.tmp | C:\Users\admin\AppData\Local\Temp\is-4J533.tmp\_isetup\_iscrypt.dll | executable | |
MD5:A69559718AB506675E907FE49DEB71E9 | SHA256:2F6294F9AA09F59A574B5DCD33BE54E16B39377984F3D5658CDA44950FA0F8FC | |||
| 3964 | 7l_csgo_setup.tmp | C:\Program Files\Counter-Strike Global Offensive\uninstall7l\unins000.exe | executable | |
MD5:69632FF882D0F1036A20FB022F20FFD0 | SHA256:1C74EB44D461F967CF877D29027C12AF25CA5DABB788760BB72E2C66BCC0ACCE | |||
| 3964 | 7l_csgo_setup.tmp | C:\Program Files\Counter-Strike Global Offensive\uninstall7l\is-9CE5L.tmp | executable | |
MD5:69632FF882D0F1036A20FB022F20FFD0 | SHA256:1C74EB44D461F967CF877D29027C12AF25CA5DABB788760BB72E2C66BCC0ACCE | |||
| 3964 | 7l_csgo_setup.tmp | C:\Program Files\Counter-Strike Global Offensive\platform\csgo_icon.ico | image | |
MD5:D7317EA62F2BBB651FAADA64FD23255B | SHA256:9B083A55C40B18426C872A78E4F3F2580B5326D4C8A1EDF5F96BFB8003B3322C | |||
| 3964 | 7l_csgo_setup.tmp | C:\Program Files\Counter-Strike Global Offensive\is-66S02.tmp | executable | |
MD5:A2705FD332C70F6165E9F9CC9034014F | SHA256:601F72DF3A7D61E8313E38E296B95A3C26ADB93E8ED70BF1DF116B175CF6C72F | |||
| 3964 | 7l_csgo_setup.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7Launcher\Counter-Strike Global Offensive\Run Counter-Strike Global Offensive.lnk | binary | |
MD5:87114369BABCD0B33516F1EF7A5F98A4 | SHA256:E754645FF1200350A1C2FD5259076DAB04024B5CEFA670BA65C9E5B7FE32A82C | |||
| 3964 | 7l_csgo_setup.tmp | C:\Users\admin\Desktop\Counter-Strike Global Offensive [7L].lnk | binary | |
MD5:A103EA212EFF28551155B21ABB94113D | SHA256:63DB6E2FAF62300BFA9470E0CDAC0BF2556580122FBF9DEA0F5712DE84DC7188 | |||
| 3044 | Run_CSGO.exe | C:\Program Files\Counter-Strike Global Offensive\inf.ini | text | |
MD5:F8A9FE81876F45AAD0E9775FD1FF42AA | SHA256:6187E6F27A1494742BC79A7D6F49AE1895E27F4EABD7B9336881291E2B9D2F2A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3044 | Run_CSGO.exe | GET | 200 | 188.114.96.3:80 | http://updater.se7enkills.net/csgo/inf.ini | unknown | text | 1.76 Kb | unknown |
3044 | Run_CSGO.exe | GET | 200 | 188.114.96.3:80 | http://updater.se7enkills.net/csgo/inf.ini | unknown | text | 1.76 Kb | unknown |
3044 | Run_CSGO.exe | GET | 200 | 188.114.96.3:80 | http://updater.se7enkills.net/csgo/upt.exe.lzma | unknown | binary | 2.72 Mb | unknown |
3044 | Run_CSGO.exe | GET | — | 188.114.96.3:80 | http://updater.se7enkills.net/cs2/en/ | unknown | — | — | unknown |
3792 | Run_CS2.exe | GET | 200 | 188.114.96.3:80 | http://updater.se7enkills.net/cs2/inf.ini | unknown | text | 2.31 Kb | unknown |
3792 | Run_CS2.exe | GET | 200 | 188.114.96.3:80 | http://updater.se7enkills.net/cs2/en/ | unknown | html | 1.20 Kb | unknown |
3792 | Run_CS2.exe | GET | 200 | 188.114.96.3:80 | http://updater.se7enkills.net/images/eng/gta-iv-dl.png | unknown | image | 24.7 Kb | unknown |
3792 | Run_CS2.exe | GET | 200 | 188.114.96.3:80 | http://updater.se7enkills.net/images/7l-cs2-header.png | unknown | image | 13.7 Kb | unknown |
3792 | Run_CS2.exe | GET | 200 | 216.58.206.35:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | binary | 1.41 Kb | unknown |
3792 | Run_CS2.exe | GET | 200 | 216.58.206.35:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | unknown | binary | 724 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3044 | Run_CSGO.exe | 188.114.96.3:80 | updater.se7enkills.net | CLOUDFLARENET | NL | unknown |
3792 | Run_CS2.exe | 188.114.96.3:80 | updater.se7enkills.net | CLOUDFLARENET | NL | unknown |
3792 | Run_CS2.exe | 142.250.185.232:443 | www.googletagmanager.com | GOOGLE | US | unknown |
3792 | Run_CS2.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
3792 | Run_CS2.exe | 216.58.206.35:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
3792 | Run_CS2.exe | 142.250.186.46:443 | www.google-analytics.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
updater.se7enkills.net |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
www.google-analytics.com |
| whitelisted |
region1.analytics.google.com |
| whitelisted |
stats.g.doubleclick.net |
| whitelisted |
www.google.sk |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3044 | Run_CSGO.exe | Potential Corporate Privacy Violation | AV POLICY User-Agent (Launcher) |
3792 | Run_CS2.exe | Potential Corporate Privacy Violation | AV POLICY User-Agent (Launcher) |
3792 | Run_CS2.exe | Potential Corporate Privacy Violation | AV POLICY User-Agent (Launcher) |
3792 | Run_CS2.exe | Potential Corporate Privacy Violation | AV POLICY User-Agent (Launcher) |
2856 | Run_CS2.exe | Potential Corporate Privacy Violation | AV POLICY User-Agent (Launcher) |
2856 | Run_CS2.exe | Potential Corporate Privacy Violation | AV POLICY User-Agent (Launcher) |
2856 | Run_CS2.exe | Potential Corporate Privacy Violation | AV POLICY User-Agent (Launcher) |