File name:

gameloop-beta-installer7-1-gameloop.mobi.exe

Full analysis: https://app.any.run/tasks/c96b8258-d278-4856-bae3-0f57f39e5902
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: November 09, 2020, 03:40:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

92E7D2975E53FA9C4EE5A6A1C446A16F

SHA1:

0EECF801775778F923F68C477D03B28DEE3DFCCC

SHA256:

C273D8D8CA5148C2A120AC1BE7F606F6B15301BF61B9C204C057AC66DC8FAE27

SSDEEP:

24576:W/KiLPCdw5c8RxEUqckhIXrnq7nJVL8ZXFzIohlpSU92RTLv7eofAdVqvyUHaQG:NiLPCG5Icnq7JVQpVIoZM7OqBa3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • gameloop-beta-installer7-1-gameloop.mobi.exe (PID: 3640)
      • QMEmulatorService.exe (PID: 2704)
      • AppMarket.exe (PID: 3176)
      • TBSWebRenderer.exe (PID: 2688)
      • GameDownload.exe (PID: 3016)
    • Adds new firewall rule via NETSH.EXE

      • Tinst.exe (PID: 1300)
    • Application was dropped or rewritten from another process

      • AppMarket.exe (PID: 3176)
      • QMEmulatorService.exe (PID: 2704)
      • syzs_dl_svr.exe (PID: 2972)
      • TBSWebRenderer.exe (PID: 2688)
      • Tinst.exe (PID: 1300)
      • GameDownload.exe (PID: 3016)
    • Changes settings of System certificates

      • AppMarket.exe (PID: 3176)
    • Actions looks like stealing of personal data

      • AppMarket.exe (PID: 3176)
    • Downloads executable files from the Internet

      • gameloop-beta-installer7-1-gameloop.mobi.exe (PID: 3640)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • gameloop-beta-installer7-1-gameloop.mobi.exe (PID: 3640)
      • Market.exe (PID: 3128)
      • Tinst.exe (PID: 1300)
      • GameDownload.exe (PID: 3016)
    • Creates files in the user directory

      • gameloop-beta-installer7-1-gameloop.mobi.exe (PID: 3640)
      • AppMarket.exe (PID: 3176)
      • GameDownload.exe (PID: 3016)
    • Low-level read access rights to disk partition

      • gameloop-beta-installer7-1-gameloop.mobi.exe (PID: 3640)
      • QMEmulatorService.exe (PID: 2704)
      • AppMarket.exe (PID: 3176)
      • GameDownload.exe (PID: 3016)
    • Creates files in the program directory

      • QMEmulatorService.exe (PID: 2704)
      • AppMarket.exe (PID: 3176)
      • syzs_dl_svr.exe (PID: 2972)
      • Tinst.exe (PID: 1300)
      • gameloop-beta-installer7-1-gameloop.mobi.exe (PID: 3640)
    • Executed as Windows Service

      • QMEmulatorService.exe (PID: 2704)
    • Creates files in the Windows directory

      • QMEmulatorService.exe (PID: 2704)
    • Uses NETSH.EXE for network configuration

      • Tinst.exe (PID: 1300)
    • Modifies the open verb of a shell class

      • Tinst.exe (PID: 1300)
    • Creates a software uninstall entry

      • Tinst.exe (PID: 1300)
    • Adds / modifies Windows certificates

      • AppMarket.exe (PID: 3176)
    • Reads Internet Cache Settings

      • GameDownload.exe (PID: 3016)
  • INFO

    • Reads settings of System Certificates

      • AppMarket.exe (PID: 3176)
    • Reads the hosts file

      • AppMarket.exe (PID: 3176)
      • GameDownload.exe (PID: 3016)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (3.6)
.exe | Generic Win/DOS Executable (1.6)
.exe | DOS Executable Generic (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:02:21 02:40:29+01:00
PEType: PE32
LinkerVersion: 14
CodeSize: 819200
InitializedDataSize: 736256
UninitializedDataSize: -
EntryPoint: 0x7c0d1
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 21-Feb-2020 01:40:29
Detected languages:
  • Chinese - PRC
  • English - United States
Debug artifacts:
  • D:\Devops\agent\workspace\p-111758179e0043a5b011650a32a71ea0\src\TGBDownloader\Output\TGBDownloader\Release\TGBDownloader.pdb

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000118

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 8
Time date stamp: 21-Feb-2020 01:40:29
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x000C7F23
0x000C8000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.64604
.rdata
0x000C9000
0x0003163C
0x00031800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.14652
.data
0x000FB000
0x00006504
0x00004C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.6235
.gfids
0x00102000
0x00000CE8
0x00000E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
3.74181
.tls
0x00103000
0x00000009
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0.0203931
.QMGuid
0x00104000
0x00000014
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x00105000
0x0006E480
0x0006E600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.79092
.reloc
0x00174000
0x0000C408
0x0000C600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.53711

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.06216
651
UNKNOWN
English - United States
RT_MANIFEST
7
2.32128
84
UNKNOWN
Chinese - PRC
RT_STRING
107
1.91924
20
UNKNOWN
Chinese - PRC
RT_GROUP_ICON
109
3.24529
80
UNKNOWN
Chinese - PRC
RT_MENU
133
7.99643
354782
UNKNOWN
Chinese - PRC
ZIPRES
134
6.642
9662
UNKNOWN
Chinese - PRC
CUSTOM
135
5.81636
76168
UNKNOWN
Chinese - PRC
CUSTOM

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
IMM32.dll
KERNEL32.dll
NETAPI32.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
VERSION.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
15
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start gameloop-beta-installer7-1-gameloop.mobi.exe market.exe tinst.exe qmemulatorservice.exe netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs appmarket.exe syzs_dl_svr.exe tbswebrenderer.exe gamedownload.exe gameloop-beta-installer7-1-gameloop.mobi.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
536"C:\Windows\system32\Netsh.exe" advfirewall firewall add rule name="GameDownload" dir=in program="c:\program files\txgameassistant\appmarket\GameDownload.exe" action=allowC:\Windows\system32\Netsh.exeTinst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1300"C:\Temp\TxGameDownload\Component\AppMarket\Setup\Tinst.exe" -nodesktopIconC:\Temp\TxGameDownload\Component\AppMarket\Setup\Tinst.exe
gameloop-beta-installer7-1-gameloop.mobi.exe
User:
admin
Integrity Level:
HIGH
Description:
TMarketInst
Exit code:
0
Version:
3.11.814.100
Modules
Images
c:\temp\txgamedownload\component\appmarket\setup\tinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1696"C:\Windows\system32\Netsh.exe" advfirewall firewall add rule name="AppMarket" dir=in program="c:\program files\txgameassistant\appmarket\AppMarket.exe" action=allowC:\Windows\system32\Netsh.exeTinst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2404"C:\Windows\system32\Netsh.exe" advfirewall firewall add rule name="QQExternal" dir=in program="c:\program files\txgameassistant\appmarket\QQExternal.exe" action=allowC:\Windows\system32\Netsh.exeTinst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2540"C:\Windows\system32\Netsh.exe" advfirewall firewall add rule name="TUpdate" dir=in program="c:\program files\txgameassistant\appmarket\GF186\TUpdate.exe" action=allowC:\Windows\system32\Netsh.exeTinst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2688"C:\Program Files\TxGameAssistant\AppMarket\TBSWebRenderer.exe" --type=renderer --enable-smooth-scrolling --force-device-scale-factor=1.00 --no-sandbox --enable-begin-frame-scheduling --client-id=TGB_Market --primordial-pipe-token=3EF0AE438182F2728B682829C4F851FB --user-agent-extra="TGBSdk/3.9.0 Tencent AppMarket/3.11.814.100" --lang=en-US --lang=en-US --log-file="C:\Program Files\TxGameAssistant\AppMarket\debug.log" --dummy-exception-handler --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --mojo-channel-token=7334D3CF1FB6C712395C8640D67420A4 --mojo-application-channel-token=3EF0AE438182F2728B682829C4F851FB --channel="3176.0.1650451196\73029858" --fix-fasa --mojo-platform-channel-handle=2728 /prefetch:1C:\Program Files\TxGameAssistant\AppMarket\TBSWebRenderer.exe
AppMarket.exe
User:
admin
Company:
Tencent
Integrity Level:
HIGH
Description:
TBSWebRenderer
Exit code:
0
Version:
3.11.814.100
Modules
Images
c:\program files\txgameassistant\appmarket\tbswebrenderer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\txgameassistant\appmarket\minicorelib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2704"C:\Program Files\TxGameAssistant\AppMarket\QMEmulatorService.exe"C:\Program Files\TxGameAssistant\AppMarket\QMEmulatorService.exe
services.exe
User:
SYSTEM
Company:
Tencent
Integrity Level:
SYSTEM
Description:
腾讯手游助手
Exit code:
0
Version:
3.11.814.100
Modules
Images
c:\program files\txgameassistant\appmarket\qmemulatorservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2780"C:\Users\admin\AppData\Local\Temp\gameloop-beta-installer7-1-gameloop.mobi.exe" C:\Users\admin\AppData\Local\Temp\gameloop-beta-installer7-1-gameloop.mobi.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\gameloop-beta-installer7-1-gameloop.mobi.exe
c:\systemroot\system32\ntdll.dll
2960"C:\Windows\system32\Netsh.exe" advfirewall firewall add rule name="TInst" dir=in program="c:\program files\txgameassistant\appmarket\TInst.exe" action=allowC:\Windows\system32\Netsh.exeTinst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2972"C:\Program Files\TxGameAssistant\AppMarket\DL\syzs_dl_svr.exe" --conf-path="C:\Program Files\TxGameAssistant\AppMarket\DL\syzs_dl_svr.cfg" --daemon --log="C:\Program Files\TxGameAssistant\AppMarket\DL\syzs_dl_svr.log"C:\Program Files\TxGameAssistant\AppMarket\DL\syzs_dl_svr.exe
AppMarket.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\txgameassistant\appmarket\dl\syzs_dl_svr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
Total events
965
Read events
585
Write events
380
Delete events
0

Modification events

(PID) Process:(3640) gameloop-beta-installer7-1-gameloop.mobi.exeKey:HKEY_CURRENT_USER\Software\Tencent\MobileGamePC
Operation:writeName:TempPath
Value:
C:\Temp\TxGameDownload\Component\
(PID) Process:(3640) gameloop-beta-installer7-1-gameloop.mobi.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Tencent\MobileGamePC
Operation:writeName:SupplyId
Value:
900206429
(PID) Process:(3640) gameloop-beta-installer7-1-gameloop.mobi.exeKey:HKEY_CURRENT_USER\Software\Tencent\MobileGamePC
Operation:writeName:UserLanguage
Value:
en
(PID) Process:(3640) gameloop-beta-installer7-1-gameloop.mobi.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3640) gameloop-beta-installer7-1-gameloop.mobi.exeKey:HKEY_CURRENT_USER\Software\Tencent\MobileGamePC\GameDownload
Operation:writeName:DownloadSpeed
Value:
0
(PID) Process:(3640) gameloop-beta-installer7-1-gameloop.mobi.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Tencent\MobileGamePC\AppMarket
Operation:writeName:InstallPath
Value:
C:\Program Files\TxGameAssistant\AppMarket
(PID) Process:(3640) gameloop-beta-installer7-1-gameloop.mobi.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3640) gameloop-beta-installer7-1-gameloop.mobi.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(1300) Tinst.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1300) Tinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Tencent\MobileGamePC\AppMarket
Operation:writeName:AutoStart
Value:
1
Executable files
234
Suspicious files
117
Text files
1 797
Unknown types
8

Dropped files

PID
Process
Filename
Type
3640gameloop-beta-installer7-1-gameloop.mobi.exeC:\test.tmp
MD5:
SHA256:
3640gameloop-beta-installer7-1-gameloop.mobi.exeC:\Temp\TxGameDownload\Component\AppMarket\Market.exe
MD5:
SHA256:
3640gameloop-beta-installer7-1-gameloop.mobi.exeC:\Users\admin\AppData\Roaming\Tencent\DeskUpdate\GlobalMgr.dbtext
MD5:
SHA256:
3128Market.exeC:\Temp\TxGameDownload\Component\AppMarket\Setup\AECommonDll.dllexecutable
MD5:
SHA256:
3128Market.exeC:\Temp\TxGameDownload\Component\AppMarket\Setup\AowGame.xmltext
MD5:
SHA256:
3640gameloop-beta-installer7-1-gameloop.mobi.exeC:\Users\admin\AppData\Local\Temp\TGBDownload\AD22.tmpxml
MD5:
SHA256:
3128Market.exeC:\Temp\TxGameDownload\Component\AppMarket\Setup\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:11E55839FCB3A53BDFED2A27FB7D5E80
SHA256:F6BDC8FFD172B44F4D169707D9A457AEEF619872661229B8629EE4F15EEFFF0D
3128Market.exeC:\Temp\TxGameDownload\Component\AppMarket\Setup\api-ms-win-core-file-l1-1-0.dllexecutable
MD5:D826D27C73D9F2420FB39FBE0745C7F0
SHA256:C0E5D482BD93BF71A73C01D0C1EC0722EA3260EBA1F4C87E797BAE334B5E9870
3128Market.exeC:\Temp\TxGameDownload\Component\AppMarket\Setup\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:64978E199A7239D2C911876447A7F05B
SHA256:92B947F1D6236F86ED7E105CFF19E23C13D1968861426511B775905E1D26B47A
3128Market.exeC:\Temp\TxGameDownload\Component\AppMarket\Setup\api-ms-win-core-file-l1-2-1.dllexecutable
MD5:A32230B9BFDB8813E94D095222AAFA11
SHA256:7068D2B8AEA252294E6B5C3BF3630475D0A91E11877F11A04E8ED1F91196410F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
194
DNS requests
31
Threats
20

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3176
AppMarket.exe
POST
200
203.205.255.79:8080
http://wup.imtt.qq.com:8080/?encrypt=17&len=1024&v=3&iv=fdf08f1537b94ce2&id=a690d5f54b43ca535af266c3180769c7&qbkey=83E885C029DFB63AE9AB68556D23F2AA1BE93E8ABDE4C43EBBF9E4A91C66ADF88E19F9F6E2E848F8CEDCD1B48B7F754576F8CB0E44A43EA1967C91CB101FF3C698C70BA9DCE3DC566F8C66CDAC8A8D0E523672676F62F419190978DBE23D341952AF28F02F75D07478C2E5B97BD80182E3B89AAF13A51A2C4A43B12407D34DED
CN
binary
160 b
suspicious
3176
AppMarket.exe
POST
200
203.205.255.79:8080
http://wup.imtt.qq.com:8080/?encrypt=17&len=1024&v=3&iv=bc8b118588e94535&id=a690d5f54b43ca535af266c3180769c7&qbkey=ACC4A1DBF7D862562C4CF7ED6012B0DF9699AA6942E7CFC5A2DC37D8245ED3A411BB85D8344295D2F02ECFEE092827492042B6488AD1E32F91E23EEF10B303186D84A3665D296B1B9E39145CDDC3C27198ED9CED0F1CF8BD50BB07839001F1DE358074AAFF590439B57C988F6D3B42725267B3C451CC7706BD0528467BFAE7E0
CN
binary
112 b
suspicious
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCCwQAAAAAAURO8EJH
US
der
1.49 Kb
whitelisted
3176
AppMarket.exe
POST
200
203.205.239.243:80
http://masterconn.qq.com/q.cgi
CN
pi3
165 b
whitelisted
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/gsorganizationvalsha2g2/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQMnk2cPe3vhNiR6XLHz4QGvBl7BwQUlt5h8b0cFilTHMDMfTuDAEDmGnwCDFvr0VyEz0kMgWJYSA%3D%3D
US
der
1.54 Kb
whitelisted
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCCwQAAAAAAURO8EJH
US
der
1.49 Kb
whitelisted
3176
AppMarket.exe
POST
200
203.205.219.54:80
http://qbwup.imtt.qq.com/
CN
binary
54 b
suspicious
GET
200
104.18.21.226:80
http://ocsp2.globalsign.com/gsorganizationvalsha2g2/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQMnk2cPe3vhNiR6XLHz4QGvBl7BwQUlt5h8b0cFilTHMDMfTuDAEDmGnwCDFvr0VyEz0kMgWJYSA%3D%3D
US
der
1.54 Kb
whitelisted
3176
AppMarket.exe
POST
200
203.205.239.243:80
http://masterconn.qq.com/q.cgi
CN
pi3
155 b
whitelisted
3176
AppMarket.exe
POST
200
203.205.239.243:80
http://masterconn.qq.com/q.cgi
CN
pi3
250 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3640
gameloop-beta-installer7-1-gameloop.mobi.exe
58.251.106.185:443
master.etl.desktop.qq.com
China Unicom Guangdong IP network
CN
malicious
3640
gameloop-beta-installer7-1-gameloop.mobi.exe
211.152.136.41:443
s.syzs.qq.com
CN
suspicious
1300
Tinst.exe
211.152.136.41:443
s.syzs.qq.com
CN
suspicious
2704
QMEmulatorService.exe
58.251.106.185:443
master.etl.desktop.qq.com
China Unicom Guangdong IP network
CN
malicious
3640
gameloop-beta-installer7-1-gameloop.mobi.exe
92.122.50.200:80
dldir1.qq.com
Telia Company AB
suspicious
3176
AppMarket.exe
203.205.235.218:8081
oth.eve.mdt.qq.com
CN
unknown
3176
AppMarket.exe
58.251.106.185:443
master.etl.desktop.qq.com
China Unicom Guangdong IP network
CN
malicious
3176
AppMarket.exe
203.205.255.79:8080
wup.imtt.qq.com
CN
suspicious
3176
AppMarket.exe
183.62.104.184:8000
China Telecom (Group)
CN
unknown
3176
AppMarket.exe
203.205.239.243:80
masterconn.qq.com
CN
unknown

DNS requests

Domain
IP
Reputation
master.etl.desktop.qq.com
  • 58.251.106.185
whitelisted
s.syzs.qq.com
  • 211.152.136.41
  • 203.205.224.59
suspicious
dldir1.qq.com
  • 92.122.50.200
  • 92.122.50.219
  • 92.122.50.211
  • 92.122.50.206
whitelisted
masterconn11.qq.com
  • 58.251.106.185
whitelisted
oth.eve.mdt.qq.com
  • 203.205.235.218
  • 203.205.239.248
unknown
wup.imtt.qq.com
  • 203.205.255.79
  • 203.205.255.80
  • 203.205.255.78
suspicious
sy.guanjia.qq.com
  • 203.205.235.145
  • 104.81.60.81
  • 104.81.60.80
whitelisted
masterconn.qq.com
  • 203.205.239.243
whitelisted
masterconn2.qq.com
  • 123.151.71.34
unknown
qbwup.imtt.qq.com
  • 203.205.219.54
suspicious

Threats

PID
Process
Class
Message
3640
gameloop-beta-installer7-1-gameloop.mobi.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3176
AppMarket.exe
Unknown Traffic
ET INFO Suspicious User-Agent (1 space)
3176
AppMarket.exe
Unknown Traffic
ET INFO Suspicious User-Agent (1 space)
3176
AppMarket.exe
Potential Corporate Privacy Violation
ET POLICY QQ Browser WUP Request - qbpcstatf.stat
3176
AppMarket.exe
Unknown Traffic
ET INFO Suspicious User-Agent (1 space)
2972
syzs_dl_svr.exe
A Network Trojan was detected
ET USER_AGENTS Aria2 User-Agent
2972
syzs_dl_svr.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2972
syzs_dl_svr.exe
A Network Trojan was detected
ET USER_AGENTS Aria2 User-Agent
2972
syzs_dl_svr.exe
A Network Trojan was detected
ET USER_AGENTS Aria2 User-Agent
2972
syzs_dl_svr.exe
A Network Trojan was detected
ET USER_AGENTS Aria2 User-Agent
4 ETPRO signatures available at the full report
Process
Message
AppMarket.exe
Standard VGA Graphics Adapter
AppMarket.exe
[1109/034205:INFO:exception_record.cc(518)] [QB]Process ID: 3176 Type: 1
AppMarket.exe
[Downloader] DriverType C: = 3
AppMarket.exe
[Downloader] GetLogicalDrives 4
TBSWebRenderer.exe
[1109/034206:INFO:exception_record.cc(518)] [QB]Process ID: 2688 Type: 2
GameDownload.exe
[Downloader] DriverType C: = 3
GameDownload.exe
[Downloader] GetLogicalDrives 4
GameDownload.exe
[Downloader] GetLogicalDrives 4
GameDownload.exe
[Downloader] DriverType C: = 3
GameDownload.exe
Standard VGA Graphics Adapter