File name:

Tarisland1.1.4.exe

Full analysis: https://app.any.run/tasks/2835e2e8-1767-421f-b08d-0d53a4b40f13
Verdict: Malicious activity
Analysis date: March 16, 2024, 12:16:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

26E647F39AA6B3850969F146D944D5C1

SHA1:

5F7ACF9506F98EDBC69506EE2901AAFF492253F4

SHA256:

227B9BAF0E33010007F93B0D86AD7BD3E76ED2ABC78151D80FEBC7DD8ADD9EF9

SSDEEP:

98304:bt/s7930pT3X4z+I6K92x9fSJKlGc/hZ0HLIe/7A5HlpgJELDPyYjGH4kNCdCL5X:56KYheGyyjd6e

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Tarisland1.1.4.exe (PID: 4044)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Tarisland1.1.4.exe (PID: 4044)
    • Connects to the server without a host name

      • TinyDL.exe (PID: 2364)
  • INFO

    • Create files in a temporary directory

      • Tarisland1.1.4.exe (PID: 4044)
    • Checks supported languages

      • Tarisland1.1.4.exe (PID: 4044)
      • WeGameMiniLoader.exe (PID: 2208)
      • TinyDL.exe (PID: 2364)
    • Reads the computer name

      • Tarisland1.1.4.exe (PID: 4044)
      • WeGameMiniLoader.exe (PID: 2208)
      • TinyDL.exe (PID: 2364)
    • Creates files or folders in the user directory

      • Tarisland1.1.4.exe (PID: 4044)
      • WeGameMiniLoader.exe (PID: 2208)
      • TinyDL.exe (PID: 2364)
    • Reads the machine GUID from the registry

      • WeGameMiniLoader.exe (PID: 2208)
      • TinyDL.exe (PID: 2364)
    • Creates files in the program directory

      • WeGameMiniLoader.exe (PID: 2208)
      • TinyDL.exe (PID: 2364)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:02 02:11:19+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27648
InitializedDataSize: 122880
UninitializedDataSize: 1024
EntryPoint: 0x396c
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.3.14.1700
ProductVersionNumber: 5.3.14.1700
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Windows, Chinese (Simplified)
Comments: -
CompanyName: Tencent
FileDescription: -
FileVersion: 5.3.14.1700
LegalCopyright: -
LegalTrademarks: -
ProductName: WeGame
ProductVersion: 5.3.14.1700
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
4
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start tarisland1.1.4.exe wegameminiloader.exe tinydl.exe tarisland1.1.4.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Users\admin\AppData\Local\Temp\Tarisland1.1.4.exe" C:\Users\admin\AppData\Local\Temp\Tarisland1.1.4.exeexplorer.exe
User:
admin
Company:
Tencent
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
5.3.14.1700
Modules
Images
c:\users\admin\appdata\local\temp\tarisland1.1.4.exe
c:\windows\system32\ntdll.dll
2208"C:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\WeGameMiniLoader.exe" C:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\WeGameMiniLoader.exe
Tarisland1.1.4.exe
User:
admin
Integrity Level:
HIGH
Description:
WeGame下载器
Exit code:
0
Version:
5.3.14.1700
Modules
Images
c:\users\admin\appdata\local\wegame\wegameminiloader(2001860)\wegameminiloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2364session=1 uid=0 parent="C:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\WeGameMiniLoader.exe"C:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\tiny_dl\TinyDL.exe
WeGameMiniLoader.exe
User:
admin
Company:
Tencent
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.4.0
Modules
Images
c:\users\admin\appdata\local\wegame\wegameminiloader(2001860)\tiny_dl\tinydl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
4044"C:\Users\admin\AppData\Local\Temp\Tarisland1.1.4.exe" C:\Users\admin\AppData\Local\Temp\Tarisland1.1.4.exe
explorer.exe
User:
admin
Company:
Tencent
Integrity Level:
HIGH
Exit code:
0
Version:
5.3.14.1700
Modules
Images
c:\users\admin\appdata\local\temp\tarisland1.1.4.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
2 924
Read events
2 924
Write events
0
Delete events
0

Modification events

No data
Executable files
4
Suspicious files
5
Text files
4
Unknown types
8

Dropped files

PID
Process
Filename
Type
4044Tarisland1.1.4.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\tiny_dl\signature.datbinary
MD5:3B5CEEDF73C612298FE6B7C682DC77BD
SHA256:CA02C9A448AC3F7F096494BD408A0445A1B88EB0DBB13E88B26B01E85B748FE9
4044Tarisland1.1.4.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\res.zipcompressed
MD5:1422CD98BDFFDFF73B37F3D59738A1C2
SHA256:1014386ADB0B926FAA12172C39F100E8D9ED0DA6D9CE792F16A61E65F8D1F1FE
4044Tarisland1.1.4.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\bugreport.initext
MD5:27EC1E105337C0AD4BDDB8F2A9551F6C
SHA256:ED60CA6895464814F9E5BC132F41645630CC785FAE9FC7DA6362B5690B3A97CD
2364TinyDL.exeC:\Program Files\塔瑞斯世界(2001860)\tiny_cache\Game_2001860.localbinary
MD5:E5C0297CC60A12FEE47F48E1A7EFF757
SHA256:34584A6B19BA56FF50280F255ABB61B46F6F951D81928BF06ABA260B5D3C0EBD
2208WeGameMiniLoader.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\Local.xmlxml
MD5:A6619BCB25F8D87E384689967797A176
SHA256:10ACEE66F9297D9BF3242473F54FE7362B34D078BFF67A5870216954E4C1AD03
4044Tarisland1.1.4.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\tiny_dl\TinyDLProxy.dllexecutable
MD5:2FDDA82869A6CF6C340D0993DC16AC44
SHA256:1F966A56FBB01840DEA8292EDC2BB0B18DF8F77350D21220726B0674D867C1E0
2208WeGameMiniLoader.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\LocalEncry.xmlbinary
MD5:1D7F541F36414B07B42354A5B93DEC1B
SHA256:306DBFF9FC393B9982CF192AEE4D5AA7379F0AE3CDCE28FA61A93F383F6DA616
2364TinyDL.exeC:\Program Files\塔瑞斯世界(2001860)\tiny_cache\1065_12_cdn.wgjbinary
MD5:C0630FA13245A973D24B4252039A7411
SHA256:7E63087005E361796E41047241FE6BA457A9B23610BAD07A2FE8BE873058BAD1
2364TinyDL.exeC:\Program Files\塔瑞斯世界(2001860)\tiny_cache\1061_20_cdn.wgjbinary
MD5:0353B04C016EA81986E78B4C20920BCF
SHA256:278B5CDB9C392BF77A186B724448DB0A9DCFA676046F914F4AC55FC6ABF5EF29
2364TinyDL.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\log\TinyDL.20240316-121649-230.logbinary
MD5:FFDF406EBFA63DD297C339B4281B4AC0
SHA256:1DB4971936502811AA551FBF1BDC0FEAC775656D1ACECC01CEA80EACD8AB02A8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
40
DNS requests
8
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2364
TinyDL.exe
GET
200
43.152.29.12:80
http://down.qq.com/tgc/werepository/rid.1061-r.39a4b/manifest/1061_20_cdn.wgj
unknown
binary
5.95 Kb
unknown
2364
TinyDL.exe
GET
200
43.152.137.29:80
http://down.qq.com/tgc/werepository/rid.1065-r.b88fe/manifest/1065_12_cdn.wgj
unknown
binary
9.95 Kb
unknown
2364
TinyDL.exe
GET
200
43.152.137.29:80
http://down.qq.com/tgc/werepository/rid.1063-r.3f5f0/manifest/1063_4_cdn.wgj
unknown
binary
64.7 Kb
unknown
2364
TinyDL.exe
GET
14.205.47.205:80
http://wegame.taris.qq.com/wegame/rid.12672-r.fc68d/manifestv2/12672_3198251187778403356_0.manifest
unknown
unknown
2364
TinyDL.exe
GET
200
43.152.29.15:80
http://down.qq.com/tgc/werepository/rid.1066-r.8df1e/manifest/1066_12_cdn.wgj
unknown
binary
1.30 Kb
unknown
2364
TinyDL.exe
GET
119.29.29.98:80
http://119.29.29.98/d?dn=c942de88f5db0d1b9d440878c8bd46863e0e9a1b4baf9558&id=86616
unknown
unknown
2364
TinyDL.exe
GET
60.221.17.186:80
http://wegame.taris.qq.com/wegame/rid.12672-r.fc68d/manifestv2/12672_3198251187778403356_0.manifest
unknown
unknown
2364
TinyDL.exe
GET
182.254.118.118:80
http://182.254.118.118/d?dn=56851e6efb14ebb7f1b666e59c0b13b13023749e88bce486&id=1011
unknown
unknown
2364
TinyDL.exe
GET
182.254.116.116:80
http://182.254.116.116/d?dn=56851e6efb14ebb7f1b666e59c0b13b13023749e88bce486&id=1011
unknown
unknown
2364
TinyDL.exe
GET
182.254.116.116:80
http://182.254.116.116/d?dn=56851e6efb14ebb7f1b666e59c0b13b13023749e88bce486&id=1011
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2208
WeGameMiniLoader.exe
116.130.229.213:8000
ied-tqos.qq.com
unknown
2208
WeGameMiniLoader.exe
49.51.20.228:443
www.wegame.com.cn
Tencent Building, Kejizhongyi Avenue
CA
unknown
2364
TinyDL.exe
49.51.20.228:443
www.wegame.com.cn
Tencent Building, Kejizhongyi Avenue
CA
unknown
2364
TinyDL.exe
43.152.29.12:80
down.qq.com
ACE
SG
unknown
2364
TinyDL.exe
43.152.137.29:80
down.qq.com
ACE
SG
unknown
2364
TinyDL.exe
14.205.47.205:80
wegame.taris.qq.com
CHINA UNICOM China169 Backbone
CN
unknown

DNS requests

Domain
IP
Reputation
ied-tqos.qq.com
  • 116.130.229.213
unknown
www.wegame.com.cn
  • 49.51.20.228
unknown
wegame.taris.qq.com
  • 14.205.47.205
  • 61.54.7.145
  • 60.221.17.186
  • 101.72.233.183
  • 27.195.127.206
  • 61.54.7.105
  • 101.72.233.163
unknown
down.qq.com
  • 43.152.29.12
  • 43.152.29.20
  • 43.152.29.15
  • 43.152.137.29
unknown

Threats

PID
Process
Class
Message
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
No debug info