| File name: | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe |
| Full analysis: | https://app.any.run/tasks/0d0ac600-d9ef-4636-b797-9ef2fe3e15ba |
| Verdict: | Malicious activity |
| Analysis date: | January 09, 2024, 22:43:47 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | A4AE1C1CC91971D50878C1A89BE063D1 |
| SHA1: | 44CE4ED596D5CBE8FC255BE3BC35D9AE26D136F8 |
| SHA256: | 71ADA8FD6C6C7887F10BC0A7A68E645D5332778955D859A2F8FDA3AD73B7B270 |
| SSDEEP: | 98304:yHSiVzrWM7Fqzj+j5udTEbli5x8/ShiBfK6wWkkxLzYxpbB0YTMBL4J4aV7O/7PA:b |
| .exe | | | Win32 Executable (generic) (3.6) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (1.6) |
| .exe | | | DOS Executable Generic (1.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:03:06 02:42:17+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 2605568 |
| InitializedDataSize: | 968704 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2210c6 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.1 |
| ProductVersionNumber: | 1.0.0.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| FileDescription: | Uptodown GameLoop Downloader |
| ProductName: | Uptodown GameLoop Downloader |
| CompanyName: | Tencent |
| FileVersion: | 1, 0, 0, 1 |
| InternalName: | TGBDownloader.exe |
| LegalCopyright: | Copyright ? 2020 Tencent. All Rights Reserved. |
| OriginalFileName: | TGBDownloader.exe |
| ProductVersion: | 1, 0, 0, 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2040 | "C:\Users\admin\AppData\Local\Temp\Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe" | C:\Users\admin\AppData\Local\Temp\Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | — | explorer.exe | |||||||||||
User: admin Company: Tencent Integrity Level: MEDIUM Description: Uptodown GameLoop Downloader Exit code: 3221226540 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 2268 | "C:\Users\admin\AppData\Local\Temp\Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe" | C:\Users\admin\AppData\Local\Temp\Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | explorer.exe | ||||||||||||
User: admin Company: Tencent Integrity Level: HIGH Description: Uptodown GameLoop Downloader Exit code: 0 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| (PID) Process: | (2268) Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: Explorer.EXE | |||
| (PID) Process: | (2268) Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | C:\Users\admin\AppData\Local\Tencent\TxGameAssistant\TGBDownloader\dr.dll | executable | |
MD5:2814ACBD607BA47BDBCDF6AC3076EE95 | SHA256:5904A7E4D97EEAC939662C3638A0E145F64FF3DD0198F895C4BF0337595C6A67 | |||
| 2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | C:\Users\admin\AppData\Roaming\Tencent\DeskUpdate\GlobalMgr.db | text | |
MD5:8CDD2558D98B4A8E924575F8C97B7475 | SHA256:11C9004AEDA5FA30E4F03083546DEE226DB390CCBCEB7CC2D7F9F9B0CD8A1065 | |||
| 2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | C:\test.tmp | binary | |
MD5:726CBD7E9D7FB0581727A5B0B8CFD512 | SHA256:BA416E17E1114635CAB171E05A72DFC90891332F04A9EA68E05E7BB6505FFBD0 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 101.33.47.206:8081 | oth.eve.mdt.qq.com | Tencent Building, Kejizhongyi Avenue | SG | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 157.255.4.39:443 | master.etl.desktop.qq.com | China Unicom Guangdong IP network | CN | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 121.14.76.247:443 | yybadaccess.3g.qq.com | Chinanet | CN | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 121.14.76.43:443 | yybadaccess.3g.qq.com | Chinanet | CN | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 113.1.0.204:80 | dldir1.qq.com | CHINA UNICOM China169 Backbone | CN | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 113.105.95.120:443 | — | Chinanet | CN | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 36.248.43.193:80 | dldir1.qq.com | CHINA UNICOM China169 Backbone | CN | unknown |
Domain | IP | Reputation |
|---|---|---|
master.etl.desktop.qq.com |
| whitelisted |
oth.eve.mdt.qq.com |
| unknown |
yybadaccess.3g.qq.com |
| unknown |
dns.msftncsi.com |
| shared |
dldir1.qq.com |
| whitelisted |
Process | Message |
|---|---|
Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | Standard VGA Graphics Adapter |