File name:

GLP_installer_1000218273_com.tencent.ig.exe

Full analysis: https://app.any.run/tasks/bfbd5174-9b79-49fb-b668-81d6a5cb7ebb
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: July 06, 2025, 19:30:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
adware
tgbdownloader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

0370C0A49A3C2E2F10914862FD09C984

SHA1:

81211CC163871771ED718466F1E7E9F6A1DCFD0B

SHA256:

6579FA2FE1804A6F821BA5F14C9A0E22055723B2569862846655219A5E10FF47

SSDEEP:

98304:eSYwh3j6c6lplIDiK+dMSDFd9UHZy2hk4x8ZXb62cVEvNlJPWAOS9g8Vdw0rilQV:+Iq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • TGBDOWNLOADER has been detected

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
      • Market.exe (PID: 1132)
    • Creates file in the systems drive root

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
    • There is functionality for taking screenshot (YARA)

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
      • Market.exe (PID: 1132)
    • Reads security settings of Internet Explorer

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
    • Process drops legitimate windows executable

      • Market.exe (PID: 1132)
    • The process drops C-runtime libraries

      • Market.exe (PID: 1132)
  • INFO

    • The sample compiled with english language support

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
      • Market.exe (PID: 1132)
    • Checks supported languages

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
      • Market.exe (PID: 1132)
    • Reads the computer name

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
      • Market.exe (PID: 1132)
    • Creates files or folders in the user directory

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
    • Create files in a temporary directory

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
    • Reads the machine GUID from the registry

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
    • The sample compiled with chinese language support

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
      • Market.exe (PID: 1132)
    • Creates files in the program directory

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
    • Process checks computer location settings

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
    • Reads the software policy settings

      • GLP_installer_1000218273_com.tencent.ig.exe (PID: 1356)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (3.6)
.exe | Generic Win/DOS Executable (1.6)
.exe | DOS Executable Generic (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:02:23 20:10:37+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 2630144
InitializedDataSize: 1226752
UninitializedDataSize: -
EntryPoint: 0x2261ee
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
FileDescription: TGBDownloader
ProductName: TGBDownloader
CompanyName: Tencent
FileVersion: 1, 0, 0, 1
InternalName: TGBDownloader.exe
LegalCopyright: Copyright ? 2020 Tencent. All Rights Reserved.
OriginalFileName: TGBDownloader.exe
ProductVersion: 1, 0, 0, 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start glp_installer_1000218273_com.tencent.ig.exe market.exe slui.exe no specs glp_installer_1000218273_com.tencent.ig.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1132"C:\Temp\TxGameDownload\Component\AppMarket\0ffa9228adbeeeb0adfb65c2ef40f630\Market.exe" C:\Temp\TxGameDownload\Component\AppMarket\0ffa9228adbeeeb0adfb65c2ef40f630\Market.exe
GLP_installer_1000218273_com.tencent.ig.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\temp\txgamedownload\component\appmarket\0ffa9228adbeeeb0adfb65c2ef40f630\market.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3996_none_d954cb49e10154a6\gdiplus.dll
1356"C:\Users\admin\AppData\Local\Temp\GLP_installer_1000218273_com.tencent.ig.exe" C:\Users\admin\AppData\Local\Temp\GLP_installer_1000218273_com.tencent.ig.exe
explorer.exe
User:
admin
Company:
Tencent
Integrity Level:
HIGH
Description:
TGBDownloader
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\appdata\local\temp\glp_installer_1000218273_com.tencent.ig.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\psapi.dll
6408C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6808"C:\Users\admin\AppData\Local\Temp\GLP_installer_1000218273_com.tencent.ig.exe" C:\Users\admin\AppData\Local\Temp\GLP_installer_1000218273_com.tencent.ig.exeexplorer.exe
User:
admin
Company:
Tencent
Integrity Level:
MEDIUM
Description:
TGBDownloader
Exit code:
3221226540
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\appdata\local\temp\glp_installer_1000218273_com.tencent.ig.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
876
Read events
869
Write events
7
Delete events
0

Modification events

(PID) Process:(1356) GLP_installer_1000218273_com.tencent.ig.exeKey:HKEY_CURRENT_USER\SOFTWARE\Tencent\MobileGamePC\Beacon
Operation:writeName:Last_Sid_GLP_installer_1000218273_com.tencent.ig.exe
Value:
D604C3C4-D204-4C42-A7C4-24E0980130D7
(PID) Process:(1356) GLP_installer_1000218273_com.tencent.ig.exeKey:HKEY_CURRENT_USER\SOFTWARE\Tencent\MobileGamePC
Operation:writeName:TempPath
Value:
C:\Temp\TxGameDownload\Component\
(PID) Process:(1356) GLP_installer_1000218273_com.tencent.ig.exeKey:HKEY_CURRENT_USER\SOFTWARE\Tencent\MobileGamePC
Operation:writeName:UserLanguage
Value:
en
(PID) Process:(1356) GLP_installer_1000218273_com.tencent.ig.exeKey:HKEY_CURRENT_USER\SOFTWARE\Tencent\MobileGamePC
Operation:writeName:abtestid
Value:
{"Component":"0"}
(PID) Process:(1356) GLP_installer_1000218273_com.tencent.ig.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tencent\MobileGamePC
Operation:writeName:SupplyId
Value:
(PID) Process:(1356) GLP_installer_1000218273_com.tencent.ig.exeKey:HKEY_CURRENT_USER\SOFTWARE\Tencent\MobileGamePC\GameDownload
Operation:writeName:DownloadSpeed
Value:
0
(PID) Process:(1356) GLP_installer_1000218273_com.tencent.ig.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Tencent\MobileGamePC\AppMarket
Operation:writeName:InstallPath
Value:
C:\Program Files\TxGameAssistant\AppMarket
Executable files
184
Suspicious files
125
Text files
668
Unknown types
0

Dropped files

PID
Process
Filename
Type
1356GLP_installer_1000218273_com.tencent.ig.exeC:\Temp\TxGameDownload\Component\AppMarket\0ffa9228adbeeeb0adfb65c2ef40f630\Market.exe
MD5:
SHA256:
1356GLP_installer_1000218273_com.tencent.ig.exeC:\Users\admin\AppData\Local\Tencent\TxGameAssistant\TGBDownloader\dr.dllexecutable
MD5:DCCC58E47D693A626FE384B86F3EE094
SHA256:CF42D5B750058D2FE19016DB401EE26F6F2EC51A618F68ED231DE88CC23CB50E
1132Market.exeC:\Temp\TxGameDownload\Component\AppMarket\0ffa9228adbeeeb0adfb65c2ef40f630\Setup\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:9F3CF9F22836C32D988D7C7E0A977E1B
SHA256:7D588A5A958E32875D7BD346D1371E6EBFD9D5D2EDE47755942BADFC9C74E207
1132Market.exeC:\Temp\TxGameDownload\Component\AppMarket\0ffa9228adbeeeb0adfb65c2ef40f630\Setup\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:11E55839FCB3A53BDFED2A27FB7D5E80
SHA256:F6BDC8FFD172B44F4D169707D9A457AEEF619872661229B8629EE4F15EEFFF0D
1132Market.exeC:\Temp\TxGameDownload\Component\AppMarket\0ffa9228adbeeeb0adfb65c2ef40f630\Setup\AowGame.xmltext
MD5:5FD0B9F7612369BCA18996D8AAA9F62C
SHA256:9937ADDC0F2EEA66EF456A53B21F93E8AE2732CB83F3E0E08E94E763F0150537
1132Market.exeC:\Temp\TxGameDownload\Component\AppMarket\0ffa9228adbeeeb0adfb65c2ef40f630\Setup\androws_logo.pngimage
MD5:022FC5C29D8CF5EC7ABE4EAE57E5E311
SHA256:88DCCC3165B30052117C4FB9A17D8BD08AE014C8D6EC65366331FC078ABB54AC
1132Market.exeC:\Temp\TxGameDownload\Component\AppMarket\0ffa9228adbeeeb0adfb65c2ef40f630\Setup\api-ms-win-core-file-l1-2-0.dllexecutable
MD5:EC4F2CB68DCF7E96516EB284003BE8BB
SHA256:3816BBB7DD76D8FC6A7B83A0ED2F61B23DD5FC0843D3308EE077CB725D5C9088
1132Market.exeC:\Temp\TxGameDownload\Component\AppMarket\0ffa9228adbeeeb0adfb65c2ef40f630\Setup\api-ms-win-core-handle-l1-1-0.dllexecutable
MD5:6A35A52D536E34BA060A19D06B1DAC80
SHA256:A369EF130749BF8CD9F67055179E6F537F200C060AF47493D49473912A95021E
1132Market.exeC:\Temp\TxGameDownload\Component\AppMarket\0ffa9228adbeeeb0adfb65c2ef40f630\Setup\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:9D74D89F2679C0C5DDB35A1EF30BD182
SHA256:E207FFC6FEF144E5D393E79DE75F8F20D223F1AC33A011EEB822D30FA2031046
1132Market.exeC:\Temp\TxGameDownload\Component\AppMarket\0ffa9228adbeeeb0adfb65c2ef40f630\Setup\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:64978E199A7239D2C911876447A7F05B
SHA256:92B947F1D6236F86ED7E105CFF19E23C13D1968861426511B775905E1D26B47A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
37
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5424
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5424
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2876
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3588
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1356
GLP_installer_1000218273_com.tencent.ig.exe
157.255.4.39:443
master.etl.desktop.qq.com
China Unicom Guangdong IP network
CN
whitelisted
1356
GLP_installer_1000218273_com.tencent.ig.exe
101.33.47.206:8081
oth.eve.mdt.qq.com
Tencent Building, Kejizhongyi Avenue
SG
whitelisted
4
System
192.168.100.255:138
whitelisted
1356
GLP_installer_1000218273_com.tencent.ig.exe
49.51.129.71:443
unifiedaccess.gameloop.com
Tencent Building, Kejizhongyi Avenue
DE
unknown
1356
GLP_installer_1000218273_com.tencent.ig.exe
43.152.26.142:443
down.gameloop.com
ACE
DE
suspicious
2876
svchost.exe
20.190.160.14:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.110
whitelisted
master.etl.desktop.qq.com
  • 157.255.4.39
whitelisted
oth.eve.mdt.qq.com
  • 101.33.47.206
  • 101.33.47.68
whitelisted
unifiedaccess.gameloop.com
  • 49.51.129.71
  • 49.51.131.79
unknown
down.gameloop.com
  • 43.152.26.142
  • 43.152.29.101
  • 43.152.26.209
  • 43.152.29.72
  • 43.152.29.148
  • 43.152.26.239
  • 43.152.26.110
  • 43.152.26.154
  • 43.152.28.77
  • 43.152.28.41
  • 43.152.27.98
  • 43.152.26.151
  • 43.152.26.197
  • 43.152.28.43
  • 43.152.26.238
unknown
login.live.com
  • 20.190.160.14
  • 20.190.160.20
  • 20.190.160.65
  • 40.126.32.136
  • 20.190.160.4
  • 20.190.160.66
  • 20.190.160.3
  • 40.126.32.140
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted

Threats

No threats detected
No debug info