| URL: | https://msnprod.oberon-media.com/view-my-installed-games |
| Full analysis: | https://app.any.run/tasks/088d1e8c-7cde-4982-8186-fb2c74db458f |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | June 19, 2021, 19:00:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | C50E9B7209A1720B88B93A898D014593 |
| SHA1: | 941A95CA5332293077F5AC4BD3E1DBE4A89506B0 |
| SHA256: | 3392CD633019BB1DAAC2836020DFC4DE050CE1D36EAAC1F6A036BD6597002A44 |
| SSDEEP: | 3:N8d9viIkMlvcxXgBICWW:2ajAv/B/WW |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 276 | "C:\Users\admin\AppData\Local\GamesManager_iWin_ugm3\toasterinstaller.exe" /S --no-desktop-shortcut | C:\Users\admin\AppData\Local\GamesManager_iWin_ugm3\toasterinstaller.exe | GamesManagerInstaller.exe | ||||||||||||
User: admin Company: iWin Inc. Integrity Level: HIGH Description: iWin Games Notifier Exit code: 0 Version: 1.0.88.88 Modules
| |||||||||||||||
| 1248 | "C:\Users\admin\Downloads\iWinGamesManager.exe" | C:\Users\admin\Downloads\iWinGamesManager.exe | — | chrome.exe | |||||||||||
User: admin Company: iWin Inc. Integrity Level: MEDIUM Description: iWin Games Manager V4 Exit code: 3221226540 Version: 4.2.1.110 Modules
| |||||||||||||||
| 1452 | "C:\Program Files\iWin Games Manager V4\FGM.exe" -service.run=true | C:\Program Files\iWin Games Manager V4\FGM.exe | — | iWinGamesManager.exe | |||||||||||
User: admin Company: iWin Inc Integrity Level: HIGH Description: iWin Games Manager V4 Exit code: 0 Version: 4.2.1.110 Modules
| |||||||||||||||
| 1564 | "C:\Program Files\iWin Games Manager V4\UssWatcher.exe" -service.start=true | C:\Program Files\iWin Games Manager V4\UssWatcher.exe | — | FGM.exe | |||||||||||
User: SYSTEM Company: iWin Inc Integrity Level: SYSTEM Description: iWin Games Manager (Watcher) V4 Exit code: 1 Version: 4.0.0.14 Modules
| |||||||||||||||
| 1572 | "C:\Users\admin\AppData\Local\GamesManager_iWin_ugm3\GamesManager.exe" --type=gpu-process --no-sandbox --lang=en-US --log-file="C:\Users\admin\AppData\Local\GamesManager_iWin_ugm3\debug.log" --user-agent="Mozilla/5.0 (Windows NT 10.0; Win32; x86) Chromium/61.0.0.0 Chrome/61.0.0.0 Version/3.9.6.631 GamesManager/3.9.6.631 20000006 WinVer/6.1 [x86] CEF/3.3163.1651.gf229796 UAPI" --disable-direct-composition --use-gl=swiftshader-webgl --supports-dual-gpus=false --gpu-driver-bug-workarounds=9,12,13,22,23,24,27,49,84 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --disable-accelerated-video-decode --gpu-vendor-id=0x1234 --gpu-device-id=0x1111 --gpu-driver-vendor="Google Inc." --gpu-driver-version=3.3.0.2 --gpu-driver-date=2017/04/07 --lang=en-US --log-file="C:\Users\admin\AppData\Local\GamesManager_iWin_ugm3\debug.log" --user-agent="Mozilla/5.0 (Windows NT 10.0; Win32; x86) Chromium/61.0.0.0 Chrome/61.0.0.0 Version/3.9.6.631 GamesManager/3.9.6.631 20000006 WinVer/6.1 [x86] CEF/3.3163.1651.gf229796 UAPI" --service-request-channel-token=622BCB8655118245567D37B86D4B79BC --mojo-platform-channel-handle=4396 /prefetch:2 | C:\Users\admin\AppData\Local\GamesManager_iWin_ugm3\GamesManager.exe | GamesManager.exe | ||||||||||||
User: admin Company: iWin Inc Integrity Level: HIGH Description: Download Games Manager Exit code: 3221226356 Version: 3.9.6.631 Modules
| |||||||||||||||
| 1700 | "C:\Program Files\iWin Games Manager V4\UssWatcher.exe" -service.start=true | C:\Program Files\iWin Games Manager V4\UssWatcher.exe | — | FGM.exe | |||||||||||
User: admin Company: iWin Inc Integrity Level: HIGH Description: iWin Games Manager (Watcher) V4 Exit code: 1 Version: 4.0.0.14 Modules
| |||||||||||||||
| 1904 | "C:\Users\admin\AppData\Local\Temp\nsr21D6.tmp\GamesManagerInstaller.exe" -installer.createiwinshortcuts=yes -config.channel=20000006 -config.uri=https://www.iwin.com/ -config.channelName=IWinStreaming -config.iwinrequest="PF/1763443851809546773/chimeras-inhuman-nature-collectors-edition/48/0" | C:\Users\admin\AppData\Local\Temp\nsr21D6.tmp\GamesManagerInstaller.exe | chimeras-inhuman-nature-collectors-editionSetup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 3.9.6.631 Modules
| |||||||||||||||
| 2112 | "C:\Program Files\iWin Games Manager V4\UssWatcher.exe" -service.start=true | C:\Program Files\iWin Games Manager V4\UssWatcher.exe | — | FGM.exe | |||||||||||
User: admin Company: iWin Inc Integrity Level: HIGH Description: iWin Games Manager (Watcher) V4 Exit code: 1 Version: 4.0.0.14 Modules
| |||||||||||||||
| 2116 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,253852563393964562,5180526036754029936,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=4590906872081773021 --renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3472 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2292 | "C:\Program Files\iWin Games Manager V4\FGM.exe" | C:\Program Files\iWin Games Manager V4\FGM.exe | — | services.exe | |||||||||||
User: SYSTEM Company: iWin Inc Integrity Level: SYSTEM Description: iWin Games Manager V4 Exit code: 0 Version: 4.2.1.110 Modules
| |||||||||||||||
| (PID) Process: | (2508) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2508) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2508) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2508) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2508) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2676) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 2508-13268602856849875 |
Value: 259 | |||
| (PID) Process: | (2508) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2508) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2508) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3252-13245750958665039 |
Value: 0 | |||
| (PID) Process: | (2508) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2508 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-60CE3EE9-9CC.pma | — | |
MD5:— | SHA256:— | |||
| 2508 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\5b196f12-8815-4505-801a-e1b43565c8c5.tmp | — | |
MD5:— | SHA256:— | |||
| 2508 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2508 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2508 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF141b66.TMP | text | |
MD5:— | SHA256:— | |||
| 2508 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF141b56.TMP | text | |
MD5:— | SHA256:— | |||
| 2508 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2508 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT | text | |
MD5:— | SHA256:— | |||
| 2508 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2508 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF141e35.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3492 | opera.exe | GET | 200 | 142.250.186.110:80 | http://clients1.google.com/complete/search?q=where+is+my+i&client=opera-suggest-omnibox&hl=de | US | text | 95 b | whitelisted |
3492 | opera.exe | GET | 302 | 142.250.185.131:80 | http://www.google.com.ua/search?q=where+is+my+ip&sourceid=opera&ie=utf-8&oe=utf-8&channel=suggest | US | html | 414 b | whitelisted |
3492 | opera.exe | GET | 200 | 142.250.185.67:80 | http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEHlkb7u6VvSqCgAAAADY%2Fcs%3D | US | der | 471 b | whitelisted |
3492 | opera.exe | GET | 200 | 142.250.186.110:80 | http://clients1.google.com/complete/search?q=where+is+my&client=opera-suggest-omnibox&hl=de | US | text | 152 b | whitelisted |
3492 | opera.exe | GET | 200 | 216.58.212.163:80 | http://crl.pki.goog/gsr1/gsr1.crl | US | der | 1.61 Kb | whitelisted |
3492 | opera.exe | GET | 200 | 93.184.220.29:80 | http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl | US | der | 592 b | whitelisted |
3492 | opera.exe | GET | 200 | 142.250.186.110:80 | http://clients1.google.com/complete/search?q=duckduck&client=opera-suggest-omnibox&hl=de | US | text | 130 b | whitelisted |
3492 | opera.exe | GET | 302 | 142.250.185.131:80 | http://www.google.com.ua/search?q=duckduckgo&sourceid=opera&ie=utf-8&oe=utf-8&channel=suggest | US | html | 404 b | whitelisted |
3492 | opera.exe | GET | 200 | 142.250.186.110:80 | http://clients1.google.com/complete/search?q=where+is&client=opera-suggest-omnibox&hl=de | US | text | 154 b | whitelisted |
3492 | opera.exe | GET | 200 | 142.250.185.67:80 | http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDHqi0hddL3kwoAAAAA2QMW | US | der | 472 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2384 | chrome.exe | 18.204.184.87:443 | msnprod.oberon-media.com | — | US | suspicious |
2384 | chrome.exe | 142.250.184.237:443 | accounts.google.com | Google Inc. | US | suspicious |
2384 | chrome.exe | 104.16.38.47:443 | js.maxmind.com | Cloudflare Inc | US | shared |
2384 | chrome.exe | 68.232.35.54:443 | static.iwincdn.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | malicious |
2384 | chrome.exe | 216.58.212.168:443 | www.googletagmanager.com | Google Inc. | US | whitelisted |
2384 | chrome.exe | 143.204.98.75:443 | quantcast.mgr.consensu.org | — | US | malicious |
2384 | chrome.exe | 142.250.186.110:443 | clients1.google.com | Google Inc. | US | whitelisted |
2384 | chrome.exe | 104.18.11.239:443 | geoip-js.com | Cloudflare Inc | US | unknown |
2384 | chrome.exe | 143.204.98.9:443 | rules.quantcount.com | — | US | whitelisted |
2384 | chrome.exe | 66.102.1.155:443 | stats.g.doubleclick.net | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
msnprod.oberon-media.com |
| suspicious |
accounts.google.com |
| shared |
static.iwincdn.com |
| malicious |
ugm3-msn.iwin.com |
| suspicious |
js.maxmind.com |
| whitelisted |
play.iwincdn.com |
| malicious |
ssl.google-analytics.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
quantcast.mgr.consensu.org |
| whitelisted |
clients1.google.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3956 | iWinGamesManager.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
3956 | iWinGamesManager.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
3796 | chimeras-inhuman-nature-collectors-editionSetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
1904 | GamesManagerInstaller.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
2624 | GamesManagerInstaller.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
1904 | GamesManagerInstaller.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |