| File name: | Installer_burgershop.exe |
| Full analysis: | https://app.any.run/tasks/9289eb2b-5c8d-4aa5-82dc-d0fd2f6b27db |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | April 06, 2024, 07:54:55 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | 8B0EBB18492BE058604154774312197A |
| SHA1: | 0BCFAD0CEEC4B44869FD222AB078785AD2114572 |
| SHA256: | D02E1834916DEA4F4FBFDBE30B05CB21F8D2DDB1DEC35F6EBA61C28ACF29A454 |
| SSDEEP: | 24576:QWm9pPS3y1NzgZ9MftmGCPA9h2v89q6jkffCs2Ho4RF5gZbu2fzu:QWkpPS3y1NzK9MftmGCY9h2v89q6jAfK |
| .exe | | | UPX compressed Win32 Executable (39.3) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (38.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (9.5) |
| .exe | | | Win32 Executable (generic) (6.5) |
| .exe | | | Generic Win/DOS Executable (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2017:02:22 15:43:34+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 356352 |
| InitializedDataSize: | 24576 |
| UninitializedDataSize: | 585728 |
| EntryPoint: | 0xe69a0 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.31.143.0 |
| ProductVersionNumber: | 1.31.143.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | RealNetworks, Inc. |
| FileDescription: | ActiveMARK Game Installer |
| FileVersion: | 1.31.143 |
| InternalName: | ActiveMARK Game Installer |
| LegalCopyright: | Copyright 2000-2017 RealNetworks, Inc. |
| OriginalFileName: | acid.exe |
| ProductName: | ActiveMARK(R) Installer |
| ProductVersion: | ActiveMARK Installer R1.31.143 [Acid R1.31] |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 292 | "C:\GameHouse Games\Burger Shop\BurgerShop.exe" cbbd5e26ca762a0c058c4dd31ce4cb3cb24bd49494040000 | C:\GameHouse Games\Burger Shop\BurgerShop.exe | BurgerShop.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: BurgerSh Application Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 948 | "C:\Program Files\Online Games Manager\ogmservice.exe" --service-run | C:\Program Files\Online Games Manager\ogmservice.exe | — | services.exe | |||||||||||
User: SYSTEM Company: RealNetworks, Inc. Integrity Level: SYSTEM Description: Online Games Manager Version: 1.50.4 Modules
| |||||||||||||||
| 1172 | "C:\GameHouse Games\Burger Shop\BurgerShop.exe" | C:\GameHouse Games\Burger Shop\BurgerShop.exe | Installer_burgershop.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: BurgerSh Application Exit code: 1 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 2120 | "C:\Users\admin\AppData\Local\Temp\Installer_burgershop.exe" | C:\Users\admin\AppData\Local\Temp\Installer_burgershop.exe | — | explorer.exe | |||||||||||
User: admin Company: RealNetworks, Inc. Integrity Level: MEDIUM Description: ActiveMARK Game Installer Exit code: 3221226540 Version: 1.31.143 Modules
| |||||||||||||||
| 2148 | wscript.exe //E:JScript /B /T:30 "C:\ProgramData\com.gamehouse.acid\uninstall\7f722365cb4cc3994e5250f8a4b58dfa.dat" --no-del-conf | C:\Windows\System32\wscript.exe | — | Installer_burgershop.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Windows Based Script Host Exit code: 1 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 2308 | "C:\Program Files\Online Games Manager\ogmservice.exe" --service-install-and-start --quiet | C:\Program Files\Online Games Manager\ogmservice.exe | — | ogmservice-setup.exe | |||||||||||
User: admin Company: RealNetworks, Inc. Integrity Level: HIGH Description: Online Games Manager Exit code: 0 Version: 1.50.4 Modules
| |||||||||||||||
| 2384 | "C:\Users\admin\AppData\Local\Temp\amtemp-09680001ffe6\installogm.exe" | C:\Users\admin\AppData\Local\Temp\amtemp-09680001ffe6\installogm.exe | Installer_burgershop.exe | ||||||||||||
User: admin Company: RealNetworks, Inc. Integrity Level: HIGH Description: Download And Install OGM Exit code: 0 Version: 1.31.143 Modules
| |||||||||||||||
| 2408 | "C:\Users\admin\AppData\Local\Temp\Installer_burgershop.exe" | C:\Users\admin\AppData\Local\Temp\Installer_burgershop.exe | explorer.exe | ||||||||||||
User: admin Company: RealNetworks, Inc. Integrity Level: HIGH Description: ActiveMARK Game Installer Exit code: 0 Version: 1.31.143 Modules
| |||||||||||||||
| 2772 | C:\Users\admin\AppData\Local\Temp\ogmservice-setup.exe | C:\Users\admin\AppData\Local\Temp\ogmservice-setup.exe | — | installogm.exe | |||||||||||
User: admin Company: Real Networks, Inc. Integrity Level: HIGH Description: Online Games Manager Exit code: 0 Version: 1.50.4 Modules
| |||||||||||||||
| 3376 | wscript.exe //E:JScript /B "C:\Users\admin\AppData\Local\Temp\amtemp-09680002fff0" | C:\Windows\System32\wscript.exe | — | Installer_burgershop.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| (PID) Process: | (2408) Installer_burgershop.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2408) Installer_burgershop.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2408) Installer_burgershop.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2408) Installer_burgershop.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2408) Installer_burgershop.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2408) Installer_burgershop.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2408) Installer_burgershop.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2408) Installer_burgershop.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2408) Installer_burgershop.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (2408) Installer_burgershop.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2408 | Installer_burgershop.exe | C:\Users\admin\AppData\Local\com.gamehouse.acid\params.dat | binary | |
MD5:— | SHA256:— | |||
| 2408 | Installer_burgershop.exe | C:\Users\admin\AppData\Local\Temp\dat25D2.tmp | binary | |
MD5:— | SHA256:— | |||
| 2408 | Installer_burgershop.exe | C:\Users\admin\AppData\Local\Temp\dat25F3.tmp | binary | |
MD5:— | SHA256:— | |||
| 2408 | Installer_burgershop.exe | C:\Users\admin\AppData\Local\Temp\dat2603.tmp | binary | |
MD5:— | SHA256:— | |||
| 2408 | Installer_burgershop.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\eula[1].htm | html | |
MD5:— | SHA256:— | |||
| 2408 | Installer_burgershop.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\jquery.json[1].js | text | |
MD5:— | SHA256:— | |||
| 2408 | Installer_burgershop.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\gamehouse[1].css | text | |
MD5:— | SHA256:— | |||
| 2408 | Installer_burgershop.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\jquery.min[1].js | text | |
MD5:— | SHA256:— | |||
| 2408 | Installer_burgershop.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\bootstrap.min[1].css | text | |
MD5:— | SHA256:— | |||
| 2408 | Installer_burgershop.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\bootbox.min[1].js | html | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2408 | Installer_burgershop.exe | GET | 200 | 91.192.226.210:80 | http://installer-manager.gamehouse.com/InstallerManager/getinstallersettings?installationid=671c515bae02435c953a02d1371e300f&component=acid&version=1.31&userid=9e9a524ce9a54ca4e91070aebf415e1792d21367&execid=017acfc4cd18f2f9&os=w7&arch=x86&browserversion=11.0.9600.19596&language=en-us&affiliate=z_syn_gh_g12&_=1712390104444 | NL | binary | 1.67 Kb | unknown |
2408 | Installer_burgershop.exe | GET | 200 | 91.192.226.177:80 | http://activemark.gamehouse.com/ping/start?slide=startup.html&sessiontime=191&rfs=true&ogm=false&component=acid&version=1.31&userid=9e9a524ce9a54ca4e91070aebf415e1792d21367&execid=017acfc4cd18f2f9&os=w7&arch=x86&browserversion=11.0.9600.19596&language=en-us&affiliate=z_syn_gh_g12×tamp=1712389501&extratracking=4e1dbadbac52700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000&price=0000006000&tracking=84bb7de92c90855f63b6867240df6600&contentid=7f722365cb4cc3994e5250f8a4b58dfa&offering=dip_nt_zy_en&gameid=1af1839b5b7afe94928044c741e5a86b¤cy=310000000000&state=start | NL | — | — | unknown |
2408 | Installer_burgershop.exe | GET | 200 | 91.192.226.150:80 | http://media.zylom.com/images/activemark/acid/1.31/ui/eula.html | NL | compressed | 982 b | unknown |
2408 | Installer_burgershop.exe | GET | 200 | 91.192.226.150:80 | http://media.zylom.com/images/activemark/acid/1.31/ui/js/jquery.json.js | NL | compressed | 871 b | unknown |
2408 | Installer_burgershop.exe | GET | 200 | 91.192.226.150:80 | http://media.zylom.com/images/activemark/acid/1.31/ui/css/bootstrap.min.css | NL | compressed | 18.1 Kb | unknown |
2408 | Installer_burgershop.exe | GET | 200 | 91.192.226.150:80 | http://media.zylom.com/images/activemark/acid/1.31/ui/css/gamehouse.css | NL | compressed | 2.19 Kb | unknown |
2408 | Installer_burgershop.exe | GET | 200 | 91.192.226.150:80 | http://media.zylom.com/images/activemark/acid/1.31/ui/js/bootstrap.min.js | NL | compressed | 7.64 Kb | unknown |
2408 | Installer_burgershop.exe | GET | 200 | 91.192.226.150:80 | http://media.zylom.com/images/activemark/acid/1.31/ui/js/bootbox.min.js | NL | html | 6.05 Kb | unknown |
2408 | Installer_burgershop.exe | GET | 200 | 91.192.226.150:80 | http://media.zylom.com/images/activemark/acid/1.31/ui/js/acid.native.js | NL | compressed | 2.01 Kb | unknown |
2408 | Installer_burgershop.exe | GET | 200 | 91.192.226.150:80 | http://media.zylom.com/images/activemark/acid/1.31/ui/js/acid.localization.js | NL | text | 22.9 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
2408 | Installer_burgershop.exe | 91.192.226.210:80 | installer-manager.gamehouse.com | GameHouse Europe BV | NL | unknown |
2408 | Installer_burgershop.exe | 35.234.70.82:80 | logging.gamehouse.com | GOOGLE-CLOUD-PLATFORM | DE | unknown |
2408 | Installer_burgershop.exe | 91.192.226.177:80 | activemark.gamehouse.com | GameHouse Europe BV | NL | unknown |
2408 | Installer_burgershop.exe | 91.192.226.150:80 | media.zylom.com | GameHouse Europe BV | NL | unknown |
2408 | Installer_burgershop.exe | 152.195.133.75:80 | cdn.media.zylom.com | EDGECAST | US | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2408 | Installer_burgershop.exe | 192.229.220.12:80 | games-dl.gamehouse.com | EDGECAST | US | unknown |
Domain | IP | Reputation |
|---|---|---|
installer-manager.gamehouse.com |
| unknown |
activemark.gamehouse.com |
| unknown |
logging.gamehouse.com |
| unknown |
media.zylom.com |
| unknown |
cdn.media.zylom.com |
| unknown |
games-dl.gamehouse.com |
| unknown |
cdn.ghstatic.com |
| unknown |
www.gamehouse.com |
| malicious |
www.google-analytics.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2384 | installogm.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3800 | BurgerShop.exe | A Network Trojan was detected | ET USER_AGENTS Suspicious User-Agent (Internet HTTP Request) |
3800 | BurgerShop.exe | A Network Trojan was detected | ET USER_AGENTS Suspicious User-Agent (Internet HTTP Request) |
— | — | Potential Corporate Privacy Violation | ET GAMES GameHouse License Check |
Process | Message |
|---|---|
BurgerShop.exe | Application requests 800 x 600 [ 4: 3]
|
BurgerShop.exe | Display is 1280 x 720 [16: 9]
|
BurgerShop.exe | Desktop is 1280 x 720 [16: 9]
|
BurgerShop.exe | Window is 800 x 600 [ 4: 3]
|
BurgerShop.exe | Hack aspect is [ 4: 3]
|
BurgerShop.exe | Application requests 800 x 600 [ 4: 3]
|
BurgerShop.exe | Hack aspect is [ 4: 3]
|
BurgerShop.exe | Window is 800 x 600 [ 4: 3]
|
BurgerShop.exe | Application requests 800 x 600 [ 4: 3]
|