File name:

Tarisland1.1.4.exe

Full analysis: https://app.any.run/tasks/2835e2e8-1767-421f-b08d-0d53a4b40f13
Verdict: Malicious activity
Analysis date: March 16, 2024, 12:16:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

26E647F39AA6B3850969F146D944D5C1

SHA1:

5F7ACF9506F98EDBC69506EE2901AAFF492253F4

SHA256:

227B9BAF0E33010007F93B0D86AD7BD3E76ED2ABC78151D80FEBC7DD8ADD9EF9

SSDEEP:

98304:bt/s7930pT3X4z+I6K92x9fSJKlGc/hZ0HLIe/7A5HlpgJELDPyYjGH4kNCdCL5X:56KYheGyyjd6e

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Tarisland1.1.4.exe (PID: 4044)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Tarisland1.1.4.exe (PID: 4044)
    • Connects to the server without a host name

      • TinyDL.exe (PID: 2364)
  • INFO

    • Reads the computer name

      • Tarisland1.1.4.exe (PID: 4044)
      • WeGameMiniLoader.exe (PID: 2208)
      • TinyDL.exe (PID: 2364)
    • Checks supported languages

      • Tarisland1.1.4.exe (PID: 4044)
      • WeGameMiniLoader.exe (PID: 2208)
      • TinyDL.exe (PID: 2364)
    • Create files in a temporary directory

      • Tarisland1.1.4.exe (PID: 4044)
    • Creates files in the program directory

      • WeGameMiniLoader.exe (PID: 2208)
      • TinyDL.exe (PID: 2364)
    • Reads the machine GUID from the registry

      • TinyDL.exe (PID: 2364)
      • WeGameMiniLoader.exe (PID: 2208)
    • Creates files or folders in the user directory

      • Tarisland1.1.4.exe (PID: 4044)
      • WeGameMiniLoader.exe (PID: 2208)
      • TinyDL.exe (PID: 2364)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:02 02:11:19+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27648
InitializedDataSize: 122880
UninitializedDataSize: 1024
EntryPoint: 0x396c
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.3.14.1700
ProductVersionNumber: 5.3.14.1700
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Windows, Chinese (Simplified)
Comments: -
CompanyName: Tencent
FileDescription: -
FileVersion: 5.3.14.1700
LegalCopyright: -
LegalTrademarks: -
ProductName: WeGame
ProductVersion: 5.3.14.1700
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
4
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start tarisland1.1.4.exe wegameminiloader.exe tinydl.exe tarisland1.1.4.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Users\admin\AppData\Local\Temp\Tarisland1.1.4.exe" C:\Users\admin\AppData\Local\Temp\Tarisland1.1.4.exeexplorer.exe
User:
admin
Company:
Tencent
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
5.3.14.1700
Modules
Images
c:\users\admin\appdata\local\temp\tarisland1.1.4.exe
c:\windows\system32\ntdll.dll
2208"C:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\WeGameMiniLoader.exe" C:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\WeGameMiniLoader.exe
Tarisland1.1.4.exe
User:
admin
Integrity Level:
HIGH
Description:
WeGame下载器
Exit code:
0
Version:
5.3.14.1700
Modules
Images
c:\users\admin\appdata\local\wegame\wegameminiloader(2001860)\wegameminiloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2364session=1 uid=0 parent="C:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\WeGameMiniLoader.exe"C:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\tiny_dl\TinyDL.exe
WeGameMiniLoader.exe
User:
admin
Company:
Tencent
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.4.0
Modules
Images
c:\users\admin\appdata\local\wegame\wegameminiloader(2001860)\tiny_dl\tinydl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
4044"C:\Users\admin\AppData\Local\Temp\Tarisland1.1.4.exe" C:\Users\admin\AppData\Local\Temp\Tarisland1.1.4.exe
explorer.exe
User:
admin
Company:
Tencent
Integrity Level:
HIGH
Exit code:
0
Version:
5.3.14.1700
Modules
Images
c:\users\admin\appdata\local\temp\tarisland1.1.4.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
2 924
Read events
2 924
Write events
0
Delete events
0

Modification events

No data
Executable files
4
Suspicious files
5
Text files
4
Unknown types
8

Dropped files

PID
Process
Filename
Type
4044Tarisland1.1.4.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\bugreport.exeexecutable
MD5:2CDD44528C02A3BB1113105043A1BC49
SHA256:2D6E2F10D468546346DE48285ECE4C8B2C4F6ACE7D4820222715D630349089CD
4044Tarisland1.1.4.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\WeGameMiniLoader.exeexecutable
MD5:21E7B7213687A4E753F5B3F008A7708C
SHA256:2F2C98472F913AF93260D346C98389E5A9BCB1FA27D18F94949AA517065FAAF9
2364TinyDL.exeC:\Program Files\塔瑞斯世界(2001860)\tiny_cache\1065_12_cdn.wgjbinary
MD5:C0630FA13245A973D24B4252039A7411
SHA256:7E63087005E361796E41047241FE6BA457A9B23610BAD07A2FE8BE873058BAD1
4044Tarisland1.1.4.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\LogConfig.iniini
MD5:D964FA19360CAB52E1192C890F5D5C6F
SHA256:DD6589E9649D503FABD58DA196DF3B675E377EA3059FCFF83F48F162FE67CCBB
4044Tarisland1.1.4.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\tiny_dl\signature.datbinary
MD5:3B5CEEDF73C612298FE6B7C682DC77BD
SHA256:CA02C9A448AC3F7F096494BD408A0445A1B88EB0DBB13E88B26B01E85B748FE9
4044Tarisland1.1.4.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\bugreport.initext
MD5:27EC1E105337C0AD4BDDB8F2A9551F6C
SHA256:ED60CA6895464814F9E5BC132F41645630CC785FAE9FC7DA6362B5690B3A97CD
4044Tarisland1.1.4.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\res.zipcompressed
MD5:1422CD98BDFFDFF73B37F3D59738A1C2
SHA256:1014386ADB0B926FAA12172C39F100E8D9ED0DA6D9CE792F16A61E65F8D1F1FE
4044Tarisland1.1.4.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\Minidown.xmlbinary
MD5:87AA5165E8FC17A6EF89AAED742BDA91
SHA256:DED7DE9B5F5B1CEAD4E71B196B1749A32821BF76691775049F86B1ED15F6F954
2364TinyDL.exeC:\Program Files\塔瑞斯世界(2001860)\tiny_cache\1063_4_cdn.wgjbinary
MD5:E1EC8B3FA4470AA12D89CB3F10C5ADE2
SHA256:DCFECFDCCCA09F127E1D4D0AAEF8316F24CD8F07AE1FCA0F10C514BBC16D7A76
2208WeGameMiniLoader.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(2001860)\LocalEncry.xmlbinary
MD5:1D7F541F36414B07B42354A5B93DEC1B
SHA256:306DBFF9FC393B9982CF192AEE4D5AA7379F0AE3CDCE28FA61A93F383F6DA616
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
40
DNS requests
8
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2364
TinyDL.exe
GET
200
43.152.137.29:80
http://down.qq.com/tgc/werepository/rid.1063-r.3f5f0/manifest/1063_4_cdn.wgj
unknown
binary
64.7 Kb
unknown
2364
TinyDL.exe
GET
200
43.152.29.12:80
http://down.qq.com/tgc/werepository/rid.1061-r.39a4b/manifest/1061_20_cdn.wgj
unknown
binary
5.95 Kb
unknown
2364
TinyDL.exe
GET
200
43.152.29.15:80
http://down.qq.com/tgc/werepository/rid.1066-r.8df1e/manifest/1066_12_cdn.wgj
unknown
binary
1.30 Kb
unknown
2364
TinyDL.exe
GET
119.29.29.98:80
http://119.29.29.98/d?dn=c942de88f5db0d1b9d440878c8bd46863e0e9a1b4baf9558&id=86616
unknown
unknown
2364
TinyDL.exe
GET
60.221.17.186:80
http://wegame.taris.qq.com/wegame/rid.12672-r.fc68d/manifestv2/12672_3198251187778403356_0.manifest
unknown
unknown
2364
TinyDL.exe
GET
182.254.118.118:80
http://182.254.118.118/d?dn=56851e6efb14ebb7f1b666e59c0b13b13023749e88bce486&id=1011
unknown
unknown
2364
TinyDL.exe
GET
182.254.116.116:80
http://182.254.116.116/d?dn=56851e6efb14ebb7f1b666e59c0b13b13023749e88bce486&id=1011
unknown
unknown
2364
TinyDL.exe
GET
14.205.47.205:80
http://wegame.taris.qq.com/wegame/rid.12672-r.fc68d/manifestv2/12672_3198251187778403356_0.manifest
unknown
unknown
2364
TinyDL.exe
GET
182.254.118.118:80
http://182.254.118.118/d?dn=56851e6efb14ebb7f1b666e59c0b13b13023749e88bce486&id=1011
unknown
unknown
2364
TinyDL.exe
GET
119.29.29.98:80
http://119.29.29.98/d?dn=c942de88f5db0d1b9d440878c8bd46863e0e9a1b4baf9558&id=86616
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2208
WeGameMiniLoader.exe
116.130.229.213:8000
ied-tqos.qq.com
unknown
2208
WeGameMiniLoader.exe
49.51.20.228:443
www.wegame.com.cn
Tencent Building, Kejizhongyi Avenue
CA
unknown
2364
TinyDL.exe
49.51.20.228:443
www.wegame.com.cn
Tencent Building, Kejizhongyi Avenue
CA
unknown
2364
TinyDL.exe
43.152.29.12:80
down.qq.com
ACE
SG
unknown
2364
TinyDL.exe
43.152.137.29:80
down.qq.com
ACE
SG
unknown
2364
TinyDL.exe
14.205.47.205:80
wegame.taris.qq.com
CHINA UNICOM China169 Backbone
CN
unknown

DNS requests

Domain
IP
Reputation
ied-tqos.qq.com
  • 116.130.229.213
unknown
www.wegame.com.cn
  • 49.51.20.228
unknown
wegame.taris.qq.com
  • 14.205.47.205
  • 61.54.7.145
  • 60.221.17.186
  • 101.72.233.183
  • 27.195.127.206
  • 61.54.7.105
  • 101.72.233.163
unknown
down.qq.com
  • 43.152.29.12
  • 43.152.29.20
  • 43.152.29.15
  • 43.152.137.29
unknown

Threats

PID
Process
Class
Message
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
2364
TinyDL.exe
Misc activity
ET INFO DNS Over HTTP Style Request (GET)
No debug info