| URL: | https://www.wargaming.net |
| Full analysis: | https://app.any.run/tasks/2f5e1594-ec9a-4408-aa0d-e185e22a0a2e |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | March 14, 2021, 20:16:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | D8FBC7755C9A1E137B71AA44C3B5040A |
| SHA1: | 4F2A0ADEEE9D54B4E4D4024DF7577CEB5C630962 |
| SHA256: | BE2965B263F922A686DB5D62B61D45345A093E9F2EDF27957686CF76700C8C4B |
| SSDEEP: | 3:N8DSLHIKCLo:2OLHIZLo |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 752 | "C:\ProgramData\Wargaming.net\GameCenter\dlls\wgc_renderer_host.exe" --type=gpu-process --field-trial-handle=1276,6899340747612527998,10406876570720108393,131072 --disable-features=MimeHandlerViewInCrossProcessFrame --no-sandbox --log-file="C:\ProgramData\Wargaming.net\GameCenter\logs\cef_20210314_201938_858.log" --log-severity=info --product-version="Chrome/78.0.3904.87 WGC/21.01.00.4239" --lang=en-US --gpu-preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\ProgramData\Wargaming.net\GameCenter\logs\cef_20210314_201938_858.log" --service-request-channel-token=12633622073802723763 --mojo-platform-channel-handle=1284 /prefetch:2 | C:\ProgramData\Wargaming.net\GameCenter\dlls\wgc_renderer_host.exe | wgc.exe | ||||||||||||
User: admin Company: Wargaming.net Integrity Level: MEDIUM Description: Wargaming.net Game Center Exit code: 4 Version: 21.01.00.4239 Modules
| |||||||||||||||
| 912 | "C:\Users\admin\AppData\Local\Temp\is-1K0FD.tmp\7za.exe" t "C:\Users\admin\AppData\Local\Temp\is-1K0FD.tmp\WGCArchive7z0 | C:\Users\admin\AppData\Local\Temp\is-1K0FD.tmp\7za.exe | — | world_of_warplanes_ww_install_eu_c9xcnl915num.tmp | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip Standalone Console Exit code: 0 Version: 16.04 Modules
| |||||||||||||||
| 1448 | "C:\ProgramData\Wargaming.net\GameCenter\wgc.exe" --install -g WOWP.WW.PRODUCTION@https://wgus-ru.wargaming.net/ --setLang -l en --session-id 72B8084FE9E8417DA5AD3D38E6A207F4 --event-sequence-number 12 --skipJobCheck | C:\ProgramData\Wargaming.net\GameCenter\wgc.exe | wgc.exe | ||||||||||||
User: admin Company: Wargaming.net Integrity Level: MEDIUM Description: Wargaming.net Game Center Exit code: 0 Version: 21.01.00.4239 Modules
| |||||||||||||||
| 1576 | "C:\Games\World_of_Warplanes\updates\redist\dxwebsetup.exe" /Q | C:\Games\World_of_Warplanes\updates\redist\dxwebsetup.exe | 1516810735_dx9.0c_light.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: DirectX 9.0 Web setup Exit code: 0 Version: 9.29.1974.0 Modules
| |||||||||||||||
| 1960 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1000,11023472415796012155,6024947416443873472,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5728708644261754466 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2140 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 2148 | "C:\Users\admin\Downloads\world_of_warplanes_ww_install_eu_c9xcnl915num.exe" | C:\Users\admin\Downloads\world_of_warplanes_ww_install_eu_c9xcnl915num.exe | chrome.exe | ||||||||||||
User: admin Company: Wargaming.net Integrity Level: MEDIUM Description: Wargaming.net Game Center Exit code: 0 Version: 21.01.00.4239 Modules
| |||||||||||||||
| 2304 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2348 | "C:\Users\admin\AppData\Local\Temp\is-3QUCF.tmp\world_of_warplanes_ww_install_eu_c9xcnl915num.tmp" /SL5="$30190,4614494,797696,C:\Users\admin\Downloads\world_of_warplanes_ww_install_eu_c9xcnl915num.exe" | C:\Users\admin\AppData\Local\Temp\is-3QUCF.tmp\world_of_warplanes_ww_install_eu_c9xcnl915num.tmp | world_of_warplanes_ww_install_eu_c9xcnl915num.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2424 | "C:\ProgramData\Wargaming.net\GameCenter\WargamingErrorMonitor.exe" --pipe "parent_pid_14483301c2c4-e169-463c-9088-7d9049ab79f2" --superuserid "WGC" --self_crash_handling_folder "C:\ProgramData\Wargaming.net\GameCenter\cat " --self_crash_handling_receiver_url "http://cat.wargaming.net " --logs_folder_path " " | C:\ProgramData\Wargaming.net\GameCenter\WargamingErrorMonitor.exe | wgc.exe | ||||||||||||
User: admin Company: Wargaming.net Integrity Level: MEDIUM Description: Wargaming.net Error Monitor Exit code: 0 Version: 03.01.01.2857 Modules
| |||||||||||||||
| 2476 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1000,11023472415796012155,6024947416443873472,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=16203952543806707605 --mojo-platform-channel-handle=1008 --ignored=" --type=renderer " /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| (PID) Process: | (2880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3072) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 2880-13260226614533375 |
Value: 259 | |||
| (PID) Process: | (2880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2880) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3252-13245750958665039 |
Value: 0 | |||
| (PID) Process: | (2880) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-604E6F37-B40.pma | — | |
MD5:— | SHA256:— | |||
| 2880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\07a0a40e-fa9d-4a9f-9270-2efa1a63153a.tmp | — | |
MD5:— | SHA256:— | |||
| 2880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF14f192.TMP | text | |
MD5:— | SHA256:— | |||
| 2880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2880 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF14f49f.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2348 | world_of_warplanes_ww_install_eu_c9xcnl915num.tmp | POST | 200 | 92.223.20.10:80 | http://wgusst-wgceu.wargaming.net/wgc/client_installation_finished | LU | — | — | whitelisted |
2628 | chrome.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX%2BJrHYM%3D | US | der | 471 b | whitelisted |
2348 | world_of_warplanes_ww_install_eu_c9xcnl915num.tmp | POST | 200 | 92.223.20.10:80 | http://wgusst-wgceu.wargaming.net/v2/wgc_installer_launch_v1 | LU | — | — | whitelisted |
2348 | world_of_warplanes_ww_install_eu_c9xcnl915num.tmp | POST | 200 | 92.223.20.10:80 | http://wgusst-wgceu.wargaming.net/wgc/client_download_started | LU | — | — | whitelisted |
2348 | world_of_warplanes_ww_install_eu_c9xcnl915num.tmp | POST | 200 | 92.223.20.10:80 | http://wgusst-wgceu.wargaming.net/v2/wgc_download_start_v1 | LU | — | — | whitelisted |
2348 | world_of_warplanes_ww_install_eu_c9xcnl915num.tmp | POST | 200 | 92.223.20.10:80 | http://wgusst-wgceu.wargaming.net/wgc/successful_client_install_click | LU | — | — | whitelisted |
— | — | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D | US | der | 471 b | whitelisted |
— | — | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPJvUY%2Bsl%2Bj4yzQuAcL2oQno5fCgQUUWj%2FkK8CB3U8zNllZGKiErhZcjsCEAWNXRQaLO7zNLUa%2BEDcDk0%3D | US | der | 471 b | whitelisted |
2628 | chrome.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJ9L2KGL92BpjF3kAtaDtxauTmhgQUPdNQpdagre7zSmAKZdMh1Pj41g8CEALO4Yw8%2BofLjvtgWz4Ku2Q%3D | US | der | 471 b | whitelisted |
— | — | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEA6oletf73%2FpUbOiVapyvd4%3D | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2628 | chrome.exe | 185.12.240.10:443 | www.wargaming.net | G-Core Labs S.A. | NL | unknown |
2628 | chrome.exe | 172.217.16.141:443 | accounts.google.com | Google Inc. | US | suspicious |
— | — | 185.12.240.10:443 | www.wargaming.net | G-Core Labs S.A. | NL | unknown |
2628 | chrome.exe | 185.12.240.10:80 | www.wargaming.net | G-Core Labs S.A. | NL | unknown |
2628 | chrome.exe | 92.223.124.254:443 | cdn-cm.gcdn.co | G-Core Labs S.A. | DE | suspicious |
2628 | chrome.exe | 142.250.186.168:443 | www.googletagmanager.com | Google Inc. | US | suspicious |
2628 | chrome.exe | 217.69.133.145:443 | top-fwz1.mail.ru | Limited liability company Mail.Ru | RU | suspicious |
2628 | chrome.exe | 92.223.20.117:443 | cm-ru.wargaming.net | G-Core Labs S.A. | LU | unknown |
2628 | chrome.exe | 142.250.185.142:443 | www.google-analytics.com | Google Inc. | US | whitelisted |
2628 | chrome.exe | 204.79.197.200:443 | bat.bing.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.wargaming.net |
| unknown |
accounts.google.com |
| shared |
ru.wargaming.net |
| unknown |
cdn-cm.gcdn.co |
| suspicious |
www.googletagmanager.com |
| whitelisted |
cm-ru.wargaming.net |
| unknown |
wgsw-ru.gcdn.co |
| suspicious |
www.google-analytics.com |
| whitelisted |
bat.bing.com |
| whitelisted |
top-fwz1.mail.ru |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET P2P BitTorrent DHT ping request |
1448 | wgc.exe | Potential Corporate Privacy Violation | ET P2P Libtorrent User-Agent |
1448 | wgc.exe | Potential Corporate Privacy Violation | ET P2P Libtorrent User-Agent |
1448 | wgc.exe | Potential Corporate Privacy Violation | GPL P2P BitTorrent announce request |
1448 | wgc.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
1448 | wgc.exe | Potential Corporate Privacy Violation | ET P2P Libtorrent User-Agent |
1448 | wgc.exe | Potential Corporate Privacy Violation | GPL P2P BitTorrent announce request |
— | — | Potential Corporate Privacy Violation | ET P2P possible torrent download |
— | — | Potential Corporate Privacy Violation | ET P2P BitTorrent - Torrent File Downloaded |
— | — | Potential Corporate Privacy Violation | ET P2P possible torrent download |
Process | Message |
|---|---|
wgc_renderer_host.exe | [0314/201941.110:ERROR:gl_surface_egl.cc(612)] EGL Driver message (Critical) eglInitialize: No available renderers.
|
wgc_renderer_host.exe | [0314/201941.113:ERROR:gl_surface_egl.cc(1057)] eglInitialize D3D11 failed with error EGL_NOT_INITIALIZED, trying next display type
|
wgc_renderer_host.exe | [0314/201942.303:ERROR:gl_surface_egl.cc(612)] EGL Driver message (Critical) eglInitialize: No available renderers.
|
wgc_renderer_host.exe | [0314/201942.309:ERROR:gl_surface_egl.cc(1057)] eglInitialize D3D9 failed with error EGL_NOT_INITIALIZED
|
wgc_renderer_host.exe | [0314/201942.315:ERROR:gl_initializer_win.cc(196)] GLSurfaceEGL::InitializeOneOff failed.
|
wgc_renderer_host.exe | [0314/201942.354:ERROR:viz_main_impl.cc(176)] Exiting GPU process due to errors during initialization
|
wgc.exe | [0314/201943.490:WARNING:gpu_process_host.cc(1220)] The GPU process has crashed 1 time(s)
|
wgc_renderer_host.exe | [0314/201944.266:ERROR:viz_main_impl.cc(176)] Exiting GPU process due to errors during initialization
|
wgc.exe | [0314/201945.347:WARNING:gpu_process_host.cc(1220)] The GPU process has crashed 2 time(s)
|
wgc.exe | [0314/201945.351:ERROR:browser_gpu_channel_host_factory.cc(138)] Failed to launch GPU process.
|