File name:

GSE-3.210.1.zip

Full analysis: https://app.any.run/tasks/0289454a-d75a-4e67-804d-eac5487d3dac
Verdict: Malicious activity
Analysis date: December 27, 2024, 05:22:04
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

972CBA51BE5400DD9D2FCC9650BAC020

SHA1:

8C6C5643FE9A3434DC8E95234EF7D4C90CA00B23

SHA256:

930EA0CD403E8C4290986717E3BFD383E17042E5F86BBCDF0AC45BC250F066C8

SSDEEP:

98304:8LE9HFmt7rZcfD43fHIqqImah4dbwm+C4bIMX75i953QwjSZ+e7xZTF0tveoM+3A:P41TtLHivtR7w3pcp7wkQ9nmbBIzOM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • steamclient_loader_x64.exe (PID: 3140)
      • steamclient_loader_x64.exe (PID: 3140)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • steamclient_loader_x64.exe (PID: 3140)
      • steamclient_loader_x64.exe (PID: 3140)
    • Manual execution by a user

      • steamclient_loader_x64.exe (PID: 3140)
      • steamclient_loader_x64.exe (PID: 3140)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3060)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 3060)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 3060)
    • Reads the computer name

      • steamclient_loader_x64.exe (PID: 3140)
      • steamclient_loader_x64.exe (PID: 3140)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:12:27 01:46:52
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: GSE-3.210.1/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
131
Monitored processes
4
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs steamclient_loader_x64.exe no specs steamclient_loader_x64.exe

Process information

PID
CMD
Path
Indicators
Parent process
3060"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\GSE-3.210.1.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3140"C:\Users\admin\Desktop\GSE-3.210.1\steamclient_loader_x64.exe" C:\Users\admin\Desktop\GSE-3.210.1\steamclient_loader_x64.exeexplorer.exe
User:
admin
Company:
GSE
Integrity Level:
MEDIUM
Description:
GSE
Exit code:
1
Version:
08.56.38.63
Modules
Images
c:\users\admin\desktop\gse-3.210.1\steamclient_loader_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3140"C:\Users\admin\Desktop\GSE-3.210.1\steamclient_loader_x64.exe" C:\Users\admin\Desktop\GSE-3.210.1\steamclient_loader_x64.exe
explorer.exe
User:
admin
Company:
GSE
Integrity Level:
HIGH
Description:
GSE
Exit code:
1
Version:
08.56.38.63
Modules
Images
c:\users\admin\desktop\gse-3.210.1\steamclient_loader_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5776C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
Total events
1 714
Read events
1 706
Write events
8
Delete events
0

Modification events

(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\GSE-3.210.1.zip
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3060) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
6
Suspicious files
0
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\ColdClientLoader.initext
MD5:9AD33B3F612A146420BD5634223DD78E
SHA256:FB6F962E440CF142FCAADB2FF9B504961F1E7940AE6D90AEA9171D79DC7EBD2E
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steam_settings\steam_appid.txttext
MD5:E24F4CB16AB4586E223B605D6BA629CD
SHA256:AE84565AACFB83921176F26C40246E27E3E82DC20797F626F0996428A9CCB0DD
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steamclient64.dllexecutable
MD5:AC93F40932BC06432A233D438EF95E67
SHA256:0FDEDBF2C631F479E69D65382459F0B00538E294F849C127DD1FD212E27B455E
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steam_settings\achievements.jsonini
MD5:0BA8444ED2ED996C751C8DBB0931480C
SHA256:0FABA3147FB7A7B1B4BD000202FE03D996D04DDEE276A4C5D63D71FAD7D94E0C
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steam_settings\configs.app.initext
MD5:D41CFF4C1A63C00ED4BE736FA00BB0B6
SHA256:5B6EE459B696F288C2E728A7510CEB756F9870A357DE49C2DF968D2CB59A6D5A
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steam_settings\branches.jsontext
MD5:ECA8BE13948C29CBCE7297214BF33CF4
SHA256:6C9146633DBE6BF7E53235FA65B0C5C353D2A0B618BEEA98B48382AA06648449
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steam_settings\supported_languages.txttext
MD5:D653CE9605A808C3903F1386641FCA8D
SHA256:6019E45CCA175010F1F7545C330129D521E6016A20E35B688BF875A23F9746A3
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\steamclient.dllexecutable
MD5:E69D2F02B850FAD6815C7AB91F784438
SHA256:EF6873E97671AFDB20AAF16DD1193D08C0D320382DA5057EB90A5C4FB5865382
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\GameOverlayRenderer64.dllexecutable
MD5:C64E952442AE0D07A61B89AC3D6EE3BC
SHA256:B1D71165977664285F3738B311732C313CD4E78F5E3764D2E8DE3E8BE9BC9E90
3060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3060.25822\GSE-3.210.1\GameOverlayRenderer.dllexecutable
MD5:0B4BDA9C479FAEA9F82E4131AEC71771
SHA256:7F53FD62F533D15CA9F7952863BF1EF426F4FED3E7E9701B674ED48F2ADAAA1E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
32
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4536
svchost.exe
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4536
svchost.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5388
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5320
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5388
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5448
RUXIMICS.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4536
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4536
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4536
svchost.exe
23.216.77.42:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4536
svchost.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.23.209.187:443
www.bing.com
Akamai International B.V.
GB
whitelisted
1176
svchost.exe
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.216.77.42
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 2.23.181.156
  • 95.101.149.131
whitelisted
www.bing.com
  • 2.23.209.187
  • 2.23.209.133
  • 2.23.209.149
  • 2.23.209.130
  • 2.23.209.182
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.2
  • 20.190.159.75
  • 20.190.159.23
  • 20.190.159.71
  • 40.126.31.71
  • 20.190.159.73
  • 40.126.31.67
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

No threats detected
No debug info