File name:

WeGameMiniLoader.std.5.11.28.1030.exe

Full analysis: https://app.any.run/tasks/8f2cc46a-eb89-4fc5-983a-bb00453f0512
Verdict: Malicious activity
Analysis date: February 06, 2024, 06:29:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
qrcode
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

14123EC5FC1E474E0B5FF0004695EF1E

SHA1:

6DD4F5901B3DC1CB782D96B747D540D4A05AEE4B

SHA256:

2BE77164014A3D42D47B58F821CFF220694CA716A6A730D2117E2280730BF999

SSDEEP:

98304:ZeYdoovr08bED6LPL6+ANly6bX92WrDqagc7hqcRvoyaBNi8sx0Iyb5K0hnxVEsX:ocnztK6Vpy+AY6ce10

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WeGameMiniLoader.std.5.11.28.1030.exe (PID: 1288)
      • TinyDL.exe (PID: 3136)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WeGameMiniLoader.std.5.11.28.1030.exe (PID: 1288)
      • TinyDL.exe (PID: 3136)
    • Process drops legitimate windows executable

      • TinyDL.exe (PID: 3136)
    • Drops 7-zip archiver for unpacking

      • TinyDL.exe (PID: 3136)
    • The process creates files with name similar to system file names

      • TinyDL.exe (PID: 3136)
    • The process drops C-runtime libraries

      • TinyDL.exe (PID: 3136)
    • Drops a system driver (possible attempt to evade defenses)

      • TinyDL.exe (PID: 3136)
  • INFO

    • Checks supported languages

      • WeGameMiniLoader.std.5.11.28.1030.exe (PID: 1288)
      • WeGameMiniLoader.exe (PID: 2032)
      • TinyDL.exe (PID: 3136)
    • Reads the computer name

      • WeGameMiniLoader.std.5.11.28.1030.exe (PID: 1288)
      • WeGameMiniLoader.exe (PID: 2032)
      • TinyDL.exe (PID: 3136)
    • Create files in a temporary directory

      • WeGameMiniLoader.std.5.11.28.1030.exe (PID: 1288)
    • Creates files or folders in the user directory

      • WeGameMiniLoader.std.5.11.28.1030.exe (PID: 1288)
      • WeGameMiniLoader.exe (PID: 2032)
      • TinyDL.exe (PID: 3136)
    • Creates files in the program directory

      • WeGameMiniLoader.exe (PID: 2032)
      • TinyDL.exe (PID: 3136)
    • Reads the machine GUID from the registry

      • WeGameMiniLoader.exe (PID: 2032)
      • TinyDL.exe (PID: 3136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:02 04:11:19+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27648
InitializedDataSize: 122880
UninitializedDataSize: 1024
EntryPoint: 0x396c
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.11.28.1030
ProductVersionNumber: 5.11.28.1030
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Windows, Chinese (Simplified)
Comments: -
CompanyName: Tencent
FileDescription: -
FileVersion: 5.11.28.1030
LegalCopyright: -
LegalTrademarks: -
ProductName: WeGame
ProductVersion: 5.11.28.1030
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wegameminiloader.std.5.11.28.1030.exe wegameminiloader.exe tinydl.exe wegameminiloader.std.5.11.28.1030.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1264"C:\Users\admin\AppData\Local\Temp\WeGameMiniLoader.std.5.11.28.1030.exe" C:\Users\admin\AppData\Local\Temp\WeGameMiniLoader.std.5.11.28.1030.exeexplorer.exe
User:
admin
Company:
Tencent
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
5.11.28.1030
Modules
Images
c:\users\admin\appdata\local\temp\wegameminiloader.std.5.11.28.1030.exe
c:\windows\system32\ntdll.dll
1288"C:\Users\admin\AppData\Local\Temp\WeGameMiniLoader.std.5.11.28.1030.exe" C:\Users\admin\AppData\Local\Temp\WeGameMiniLoader.std.5.11.28.1030.exe
explorer.exe
User:
admin
Company:
Tencent
Integrity Level:
HIGH
Exit code:
0
Version:
5.11.28.1030
Modules
Images
c:\users\admin\appdata\local\temp\wegameminiloader.std.5.11.28.1030.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2032"C:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(55555)\WeGameMiniLoader.exe" C:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(55555)\WeGameMiniLoader.exe
WeGameMiniLoader.std.5.11.28.1030.exe
User:
admin
Integrity Level:
HIGH
Description:
WeGame下载器
Exit code:
0
Version:
5.11.28.1030
Modules
Images
c:\users\admin\appdata\local\wegame\wegameminiloader(55555)\wegameminiloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3136session=1 uid=0 parent="C:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(55555)\WeGameMiniLoader.exe"C:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(55555)\tiny_dl\TinyDL.exe
WeGameMiniLoader.exe
User:
admin
Company:
Tencent
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.3.0
Modules
Images
c:\users\admin\appdata\local\wegame\wegameminiloader(55555)\tiny_dl\tinydl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
Total events
1 326
Read events
1 326
Write events
0
Delete events
0

Modification events

No data
Executable files
659
Suspicious files
207
Text files
1 143
Unknown types
0

Dropped files

PID
Process
Filename
Type
3136TinyDL.exeC:\Program Files\WeGame\qbblinktrial\libcef.dll
MD5:
SHA256:
3136TinyDL.exeC:\Program Files\WeGame\data\json_db\base_game_oss.local
MD5:
SHA256:
1288WeGameMiniLoader.std.5.11.28.1030.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(55555)\LogConfig.initext
MD5:D964FA19360CAB52E1192C890F5D5C6F
SHA256:DD6589E9649D503FABD58DA196DF3B675E377EA3059FCFF83F48F162FE67CCBB
1288WeGameMiniLoader.std.5.11.28.1030.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(55555)\icon.icoimage
MD5:B1BD0B6DDD17CA3ACEA5A8DE95D5BF95
SHA256:77559382F19D9E7C362B1C21C21E5B1BAB7E8DBEFA51B7DA95A1A49D5943079E
1288WeGameMiniLoader.std.5.11.28.1030.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(55555)\WeGameMiniLoader.exeexecutable
MD5:B6063C8385849A2E4352B0B650E7D173
SHA256:5D958D47086A3C743F588C333A70A73D9FAE23FD238EC50578C0818049313894
3136TinyDL.exeC:\Program Files\WeGame\apps\Pallas\lolguide\LOLRes.vfs
MD5:
SHA256:
1288WeGameMiniLoader.std.5.11.28.1030.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(55555)\bugreport.initext
MD5:27EC1E105337C0AD4BDDB8F2A9551F6C
SHA256:ED60CA6895464814F9E5BC132F41645630CC785FAE9FC7DA6362B5690B3A97CD
3136TinyDL.exeC:\Program Files\WeGame\qbblinktrial\icudtl.dat
MD5:
SHA256:
1288WeGameMiniLoader.std.5.11.28.1030.exeC:\Users\admin\AppData\Local\WeGame\WeGameMiniLoader(55555)\tiny_dl\signature.datbinary
MD5:74E2FFC3824F444096F95DEC37F162F3
SHA256:6A82710DC240C4DDC576E4CABF4DB9719ED78EDD02C1428E7A13D1306F97E0A2
2032WeGameMiniLoader.exeC:\Users\admin\AppData\Roaming\Tencent\TenioDL\Common.initext
MD5:E6B331EF2264D8B9CDCBE50781FC22AE
SHA256:7AA669E9B46692EAAC702A402E88C9C12B9DAAA7AFD2658294347E3B137583BF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4 899
TCP/UDP connections
17
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3136
TinyDL.exe
GET
200
43.152.137.29:80
http://down.qq.com/tgc/iwerepository/rid.10974-r.d9cf0/chunks/d0/d0eb41899a03c61787ead38ae7cc06f095bf781a1425ddbe6d5fee9dad4d493c.wgc
unknown
binary
357 Kb
unknown
3136
TinyDL.exe
GET
200
43.152.137.29:80
http://down.qq.com/tgc/iwerepository/rid.10974-r.d9cf0/manifest/10974_3198251187778400129_0.wgj
unknown
binary
3.38 Mb
unknown
3136
TinyDL.exe
GET
200
43.152.137.29:80
http://down.qq.com/tgc/iwerepository/rid.10974-r.d9cf0/chunks/46/46a8c93c85cb8b8c68f3a4bb54086276d884409c5cf323c50094218299882956.wgc
unknown
binary
399 Kb
unknown
3136
TinyDL.exe
GET
200
43.152.137.29:80
http://down.qq.com/tgc/iwerepository/rid.10974-r.d9cf0/chunks/a7/a74a87c1c32a47a6f2dcd67a3c1d7525ee951292eda8342bfbf27247199eb0f5.wgc
unknown
binary
312 Kb
unknown
3136
TinyDL.exe
GET
200
43.152.137.29:80
http://down.qq.com/tgc/iwerepository/rid.10974-r.d9cf0/chunks/de/de83d2c6c07dd4f7e9702ea38cbee93b304d7947eda8265a71f8c3b80e405c26.wgc
unknown
binary
394 Kb
unknown
3136
TinyDL.exe
GET
200
43.152.137.29:80
http://down.qq.com/tgc/iwerepository/rid.10974-r.d9cf0/chunks/0e/0e169c9fd822fea4b3fa647a0206e8d44e9b227946dfa45a0a1153746bf2a6c1.wgc
unknown
binary
442 Kb
unknown
3136
TinyDL.exe
GET
200
43.152.137.29:80
http://down.qq.com/tgc/iwerepository/rid.10974-r.d9cf0/chunks/df/df00d88127aeef4709ab3a037b004c6e52ac0a7481d7f2c5e015b4ae1a39121f.wgc
unknown
binary
323 Kb
unknown
3136
TinyDL.exe
GET
200
43.152.137.29:80
http://down.qq.com/tgc/iwerepository/rid.10974-r.d9cf0/chunks/bc/bcfca5c4280707efa2606b74335b175ab834f547e50bd1cda28dc46dee9b9cd2.wgc
unknown
binary
426 Kb
unknown
3136
TinyDL.exe
GET
200
43.152.137.29:80
http://down.qq.com/tgc/iwerepository/rid.10974-r.d9cf0/chunks/73/733aa8390cf2ff33f6f00d51528151187497c76f95950e19471995bc89d09be2.wgc
unknown
binary
397 Kb
unknown
3136
TinyDL.exe
GET
200
43.152.137.29:80
http://down.qq.com/tgc/iwerepository/rid.10974-r.d9cf0/chunks/fd/fd2ceddb9d35cc19c13379e862e89b8bdd13873fae52060d6a4aa477ad8d0f14.wgc
unknown
binary
308 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2032
WeGameMiniLoader.exe
116.130.229.213:8000
ied-tqos.qq.com
unknown
2032
WeGameMiniLoader.exe
119.28.184.49:443
www.wegame.com.cn
Tencent Building, Kejizhongyi Avenue
HK
unknown
3136
TinyDL.exe
119.28.184.49:443
www.wegame.com.cn
Tencent Building, Kejizhongyi Avenue
HK
unknown
3136
TinyDL.exe
43.152.137.29:80
down.qq.com
ACE
SG
unknown

DNS requests

Domain
IP
Reputation
ied-tqos.qq.com
  • 116.130.229.213
unknown
www.wegame.com.cn
  • 119.28.184.49
unknown
down.qq.com
  • 43.152.137.29
  • 43.152.29.20
  • 43.152.29.12
  • 43.152.29.15
unknown

Threats

No threats detected
Process
Message
WeGameMiniLoader.std.5.11.28.1030.exe
[NSISPlugin][TQosReport] Create TQos API Handle Error: tqos_get_qosconnd_iplist fail
WeGameMiniLoader.std.5.11.28.1030.exe
[NSISPlugin][TQosReport] TQos Server Address: , Port: 0, TQos ID: 0
WeGameMiniLoader.std.5.11.28.1030.exe
[NSISPlugin][TQosReport] TQos Server Address: , Port: 0, TQos ID: 0
WeGameMiniLoader.std.5.11.28.1030.exe
[NSISPlugin][TQosReport] Create TQos API Handle Error: tqos_get_qosconnd_iplist fail