File name: | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe |
Full analysis: | https://app.any.run/tasks/0d0ac600-d9ef-4636-b797-9ef2fe3e15ba |
Verdict: | Malicious activity |
Analysis date: | January 09, 2024, 22:43:47 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | A4AE1C1CC91971D50878C1A89BE063D1 |
SHA1: | 44CE4ED596D5CBE8FC255BE3BC35D9AE26D136F8 |
SHA256: | 71ADA8FD6C6C7887F10BC0A7A68E645D5332778955D859A2F8FDA3AD73B7B270 |
SSDEEP: | 98304:yHSiVzrWM7Fqzj+j5udTEbli5x8/ShiBfK6wWkkxLzYxpbB0YTMBL4J4aV7O/7PA:b |
.exe | | | Win32 Executable (generic) (3.6) |
---|---|---|
.exe | | | Generic Win/DOS Executable (1.6) |
.exe | | | DOS Executable Generic (1.5) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2023:03:06 02:42:17+01:00 |
ImageFileCharacteristics: | Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 14 |
CodeSize: | 2605568 |
InitializedDataSize: | 968704 |
UninitializedDataSize: | - |
EntryPoint: | 0x2210c6 |
OSVersion: | 5.1 |
ImageVersion: | - |
SubsystemVersion: | 5.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 1.0.0.1 |
ProductVersionNumber: | 1.0.0.1 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Windows, Latin1 |
FileDescription: | Uptodown GameLoop Downloader |
ProductName: | Uptodown GameLoop Downloader |
CompanyName: | Tencent |
FileVersion: | 1, 0, 0, 1 |
InternalName: | TGBDownloader.exe |
LegalCopyright: | Copyright ? 2020 Tencent. All Rights Reserved. |
OriginalFileName: | TGBDownloader.exe |
ProductVersion: | 1, 0, 0, 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2040 | "C:\Users\admin\AppData\Local\Temp\Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe" | C:\Users\admin\AppData\Local\Temp\Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | — | explorer.exe | |||||||||||
User: admin Company: Tencent Integrity Level: MEDIUM Description: Uptodown GameLoop Downloader Exit code: 3221226540 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
2268 | "C:\Users\admin\AppData\Local\Temp\Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe" | C:\Users\admin\AppData\Local\Temp\Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | explorer.exe | ||||||||||||
User: admin Company: Tencent Integrity Level: HIGH Description: Uptodown GameLoop Downloader Exit code: 0 Version: 1, 0, 0, 1 Modules
|
(PID) Process: | (2268) Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
Operation: | write | Name: | Name |
Value: Explorer.EXE | |||
(PID) Process: | (2268) Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US |
PID | Process | Filename | Type | |
---|---|---|---|---|
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | C:\Users\admin\AppData\Local\Tencent\TxGameAssistant\TGBDownloader\dr.dll | executable | |
MD5:2814ACBD607BA47BDBCDF6AC3076EE95 | SHA256:5904A7E4D97EEAC939662C3638A0E145F64FF3DD0198F895C4BF0337595C6A67 | |||
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | C:\test.tmp | binary | |
MD5:726CBD7E9D7FB0581727A5B0B8CFD512 | SHA256:BA416E17E1114635CAB171E05A72DFC90891332F04A9EA68E05E7BB6505FFBD0 | |||
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | C:\Users\admin\AppData\Roaming\Tencent\DeskUpdate\GlobalMgr.db | text | |
MD5:8CDD2558D98B4A8E924575F8C97B7475 | SHA256:11C9004AEDA5FA30E4F03083546DEE226DB390CCBCEB7CC2D7F9F9B0CD8A1065 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 101.33.47.206:8081 | oth.eve.mdt.qq.com | Tencent Building, Kejizhongyi Avenue | SG | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 157.255.4.39:443 | master.etl.desktop.qq.com | China Unicom Guangdong IP network | CN | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 121.14.76.247:443 | yybadaccess.3g.qq.com | Chinanet | CN | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 121.14.76.43:443 | yybadaccess.3g.qq.com | Chinanet | CN | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 113.1.0.204:80 | dldir1.qq.com | CHINA UNICOM China169 Backbone | CN | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 113.105.95.120:443 | — | Chinanet | CN | unknown |
2268 | Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | 36.248.43.193:80 | dldir1.qq.com | CHINA UNICOM China169 Backbone | CN | unknown |
Domain | IP | Reputation |
---|---|---|
master.etl.desktop.qq.com |
| unknown |
oth.eve.mdt.qq.com |
| unknown |
yybadaccess.3g.qq.com |
| unknown |
dns.msftncsi.com |
| unknown |
dldir1.qq.com |
| unknown |
Process | Message |
---|---|
Gameloop Chinese 64-pc-androidemulator.com-1000224174.exe | Standard VGA Graphics Adapter |