| File name: | GSE-3.210.1.zip |
| Full analysis: | https://app.any.run/tasks/0289454a-d75a-4e67-804d-eac5487d3dac |
| Verdict: | Malicious activity |
| Analysis date: | December 27, 2024, 05:22:04 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | 972CBA51BE5400DD9D2FCC9650BAC020 |
| SHA1: | 8C6C5643FE9A3434DC8E95234EF7D4C90CA00B23 |
| SHA256: | 930EA0CD403E8C4290986717E3BFD383E17042E5F86BBCDF0AC45BC250F066C8 |
| SSDEEP: | 98304:8LE9HFmt7rZcfD43fHIqqImah4dbwm+C4bIMX75i953QwjSZ+e7xZTF0tveoM+3A:P41TtLHivtR7w3pcp7wkQ9nmbBIzOM |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2024:12:27 01:46:52 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | GSE-3.210.1/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3060 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\GSE-3.210.1.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 3140 | "C:\Users\admin\Desktop\GSE-3.210.1\steamclient_loader_x64.exe" | C:\Users\admin\Desktop\GSE-3.210.1\steamclient_loader_x64.exe | — | explorer.exe | |||||||||||
User: admin Company: GSE Integrity Level: MEDIUM Description: GSE Exit code: 1 Version: 08.56.38.63 Modules
| |||||||||||||||
| 3140 | "C:\Users\admin\Desktop\GSE-3.210.1\steamclient_loader_x64.exe" | C:\Users\admin\Desktop\GSE-3.210.1\steamclient_loader_x64.exe | explorer.exe | ||||||||||||
User: admin Company: GSE Integrity Level: HIGH Description: GSE Exit code: 1 Version: 08.56.38.63 Modules
| |||||||||||||||
| 5776 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\GSE-3.210.1.zip | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3060) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\ColdClientLoader.ini | text | |
MD5:9AD33B3F612A146420BD5634223DD78E | SHA256:FB6F962E440CF142FCAADB2FF9B504961F1E7940AE6D90AEA9171D79DC7EBD2E | |||
| 3060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steam_settings\steam_appid.txt | text | |
MD5:E24F4CB16AB4586E223B605D6BA629CD | SHA256:AE84565AACFB83921176F26C40246E27E3E82DC20797F626F0996428A9CCB0DD | |||
| 3060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steamclient64.dll | executable | |
MD5:AC93F40932BC06432A233D438EF95E67 | SHA256:0FDEDBF2C631F479E69D65382459F0B00538E294F849C127DD1FD212E27B455E | |||
| 3060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steam_settings\achievements.json | ini | |
MD5:0BA8444ED2ED996C751C8DBB0931480C | SHA256:0FABA3147FB7A7B1B4BD000202FE03D996D04DDEE276A4C5D63D71FAD7D94E0C | |||
| 3060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steam_settings\configs.app.ini | text | |
MD5:D41CFF4C1A63C00ED4BE736FA00BB0B6 | SHA256:5B6EE459B696F288C2E728A7510CEB756F9870A357DE49C2DF968D2CB59A6D5A | |||
| 3060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steam_settings\branches.json | text | |
MD5:ECA8BE13948C29CBCE7297214BF33CF4 | SHA256:6C9146633DBE6BF7E53235FA65B0C5C353D2A0B618BEEA98B48382AA06648449 | |||
| 3060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steam_settings\supported_languages.txt | text | |
MD5:D653CE9605A808C3903F1386641FCA8D | SHA256:6019E45CCA175010F1F7545C330129D521E6016A20E35B688BF875A23F9746A3 | |||
| 3060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steamclient.dll | executable | |
MD5:E69D2F02B850FAD6815C7AB91F784438 | SHA256:EF6873E97671AFDB20AAF16DD1193D08C0D320382DA5057EB90A5C4FB5865382 | |||
| 3060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\GameOverlayRenderer64.dll | executable | |
MD5:C64E952442AE0D07A61B89AC3D6EE3BC | SHA256:B1D71165977664285F3738B311732C313CD4E78F5E3764D2E8DE3E8BE9BC9E90 | |||
| 3060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\GameOverlayRenderer.dll | executable | |
MD5:0B4BDA9C479FAEA9F82E4131AEC71771 | SHA256:7F53FD62F533D15CA9F7952863BF1EF426F4FED3E7E9701B674ED48F2ADAAA1E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4536 | svchost.exe | GET | 200 | 23.216.77.42:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
4536 | svchost.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5388 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
5320 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
5388 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5448 | RUXIMICS.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4536 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4536 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4536 | svchost.exe | 23.216.77.42:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4536 | svchost.exe | 2.23.181.156:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 2.23.209.187:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
1176 | svchost.exe | 20.190.159.64:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |