File name:

101 Okey Domino ve Kart Oyunlari 2024.exe

Full analysis: https://app.any.run/tasks/91c6d3a4-3048-4e71-a6c7-4cf15c53af4e
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 06, 2025, 00:26:27
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

A6AD4912255CF65402893F84BCA1382A

SHA1:

9EF74D4A8C1794136B3BD509F6F142CA69AE80C1

SHA256:

E624EDDCA0AB3A27DEEE8515A2E434F80C5C18484CB51BA44C0F4C8E0337469E

SSDEEP:

98304:63eiIfN9IWYMQUu1Uo5nVu0UfUqHRNpat4t3t9TvrD66GRxO5aRlrgd1lpKgscp+:NPaq9G1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • 101 Okey Domino ve Kart Oyunlari 2024.exe (PID: 2136)
    • Executable content was dropped or overwritten

      • 101 Okey Domino ve Kart Oyunlari 2024.exe (PID: 2136)
    • Reads Internet Explorer settings

      • 101 Okey Domino ve Kart Oyunlari 2024.exe (PID: 2136)
    • Reads security settings of Internet Explorer

      • 101 Okey Domino ve Kart Oyunlari 2024.exe (PID: 2136)
    • Process requests binary or script from the Internet

      • 101 Okey Domino ve Kart Oyunlari 2024.exe (PID: 2136)
  • INFO

    • The sample compiled with turkish language support

      • 101 Okey Domino ve Kart Oyunlari 2024.exe (PID: 2136)
    • Checks supported languages

      • 101 Okey Domino ve Kart Oyunlari 2024.exe (PID: 2136)
    • Reads the computer name

      • 101 Okey Domino ve Kart Oyunlari 2024.exe (PID: 2136)
    • Reads the machine GUID from the registry

      • 101 Okey Domino ve Kart Oyunlari 2024.exe (PID: 2136)
    • Checks proxy server information

      • 101 Okey Domino ve Kart Oyunlari 2024.exe (PID: 2136)
    • Creates files or folders in the user directory

      • 101 Okey Domino ve Kart Oyunlari 2024.exe (PID: 2136)
    • Create files in a temporary directory

      • 101 Okey Domino ve Kart Oyunlari 2024.exe (PID: 2136)
    • Compiled with Borland Delphi (YARA)

      • 101 Okey Domino ve Kart Oyunlari 2024.exe (PID: 2136)
      • slui.exe (PID: 3932)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (generic) (62.6)
.exe | Win32 Executable Delphi generic (21.3)
.exe | Win32 Executable (generic) (6.7)
.exe | Win16/32 Executable Delphi generic (3.1)
.exe | Generic Win/DOS Executable (3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 2738688
InitializedDataSize: 9051136
UninitializedDataSize: -
EntryPoint: 0x29d678
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.43.0.0
ProductVersionNumber: 1.43.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Turkish
CharacterSet: Windows, Turkish
CompanyName: Doğu Port İnternet Hizmetleri San ve Tic Ltd Şti
FileDescription: 34, 51, 101, Okey, KDVli Okey,Kastet, Kelimatik, Harftet, Harfbank, Domino, Aznif, Batak, Okşin ve Yanık Oyunları
FileVersion: 1.43.0.0
InternalName: -
LegalCopyright: Bu programın tüm telif hakları saklıdır
LegalTrademarks: T.C. Kültür ve Turizm Bakanlığı Telif Hakları Genel Müdürlüğü Kayıt Tescil Numarası: İEE/29-09052007
OriginalFileName: -
ProductName: 34, 51, 101, Okey, KDVli Okey,Kastet, Kelimatik, Harftet, Harfbank, Domino, Aznif, Batak, Okşin ve Yanık Oyunları
ProductVersion: 1.43
Comments: -
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 101 okey domino ve kart oyunlari 2024.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2136"C:\Users\admin\AppData\Local\Temp\101 Okey Domino ve Kart Oyunlari 2024.exe" C:\Users\admin\AppData\Local\Temp\101 Okey Domino ve Kart Oyunlari 2024.exe
explorer.exe
User:
admin
Company:
Doğu Port İnternet Hizmetleri San ve Tic Ltd Şti
Integrity Level:
MEDIUM
Description:
34, 51, 101, Okey, KDVli Okey,Kastet, Kelimatik, Harftet, Harfbank, Domino, Aznif, Batak, Okşin ve Yanık Oyunları
Version:
1.43.0.0
Modules
Images
c:\users\admin\appdata\local\temp\101 okey domino ve kart oyunlari 2024.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3932C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
1 533
Read events
1 510
Write events
22
Delete events
1

Modification events

(PID) Process:(2136) 101 Okey Domino ve Kart Oyunlari 2024.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Media\WMSDK\General
Operation:writeName:UniqueID
Value:
{247E720B-6DF2-4FCE-8838-CD9DD2DA7885}
(PID) Process:(2136) 101 Okey Domino ve Kart Oyunlari 2024.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Media\WMSDK\General
Operation:writeName:ComputerName
Value:
DESKTOP-JGLLJLD
(PID) Process:(2136) 101 Okey Domino ve Kart Oyunlari 2024.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Media\WMSDK\General
Operation:writeName:VolumeSerialNumber
Value:
649566714
(PID) Process:(2136) 101 Okey Domino ve Kart Oyunlari 2024.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\MediaPlayer\Player\Settings
Operation:delete valueName:Client ID
Value:
{CECDFD5C-8F08-4FEF-8713-FAA895A422EB}
(PID) Process:(2136) 101 Okey Domino ve Kart Oyunlari 2024.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Media\WMSDK\Namespace
Operation:writeName:LocalBase
Value:
C:\Users\admin\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML
(PID) Process:(2136) 101 Okey Domino ve Kart Oyunlari 2024.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Media\WMSDK\Namespace
Operation:writeName:DTDFile
Value:
C:\Users\admin\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD
(PID) Process:(2136) 101 Okey Domino ve Kart Oyunlari 2024.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Media\WMSDK\Namespace
Operation:writeName:LocalDelta
Value:
C:\Users\admin\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNSD.XML
(PID) Process:(2136) 101 Okey Domino ve Kart Oyunlari 2024.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Media\WMSDK\Namespace
Operation:writeName:RemoteDelta
Value:
C:\Users\admin\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNSR.XML
(PID) Process:(2136) 101 Okey Domino ve Kart Oyunlari 2024.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\MediaPlayer\Preferences\ProxySettings\HTTP
Operation:writeName:ProxyStyle
Value:
1
(PID) Process:(2136) 101 Okey Domino ve Kart Oyunlari 2024.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\MediaPlayer\Preferences\ProxySettings\HTTP
Operation:writeName:ProxyName
Value:
Executable files
1
Suspicious files
1
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
2136101 Okey Domino ve Kart Oyunlari 2024.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\reklamframegirisyeni[1].htmhtml
MD5:93BD9DDCC2FAC15BD48BC1DFA41D42D8
SHA256:6989E16A4215331815F710C931B84AE5F69C3FA19BFC6300D0676986A6713DCF
2136101 Okey Domino ve Kart Oyunlari 2024.exeC:\Users\admin\AppData\Local\Temp\rsdr223.dattext
MD5:475002D0F33B6C8CB966704B968D8192
SHA256:D34659714BCBD4470FBCB792AD14DCB2AF51F5E541F2F272D6744B6D5F2C888F
2136101 Okey Domino ve Kart Oyunlari 2024.exeC:\Users\admin\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XMLtext
MD5:5433EAB10C6B5C6D55B7CBD302426A39
SHA256:23DBF7014E99E93AF5F2760F18EE1370274F06A453145C8D539B66D798DAD131
2136101 Okey Domino ve Kart Oyunlari 2024.exeC:\Users\admin\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTDxml
MD5:90BE2701C8112BEBC6BD58A7DE19846E
SHA256:644FBCDC20086E16D57F31C5BAD98BE68D02B1C061938D2F5F91CBE88C871FBF
2136101 Okey Domino ve Kart Oyunlari 2024.exeC:\Users\admin\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML.baktext
MD5:7050D5AE8ACFBE560FA11073FEF8185D
SHA256:CB87767C4A384C24E4A0F88455F59101B1AE7B4FB8DE8A5ADB4136C5F7EE545B
2136101 Okey Domino ve Kart Oyunlari 2024.exeC:\Users\admin\Desktop\101 Okey Domino ve Kart Oyunlari 2024.exeexecutable
MD5:A6AD4912255CF65402893F84BCA1382A
SHA256:E624EDDCA0AB3A27DEEE8515A2E434F80C5C18484CB51BA44C0F4C8E0337469E
2136101 Okey Domino ve Kart Oyunlari 2024.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\urchin[1].jstext
MD5:1F36E699091DAED40331072860CCE88A
SHA256:65B488811BD504ECD9037C0AEE94C56A7BCD0870C2AE8818F6CF60CB3BA51621
2136101 Okey Domino ve Kart Oyunlari 2024.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\gldbanner1[1].jpgimage
MD5:C678CD6D77163D3E98B9E2BD0778AC40
SHA256:8C1D6FEDE91C7C06AA1300072B2486D24EAB79804AF3CD73C167D44ACBCA8831
2136101 Okey Domino ve Kart Oyunlari 2024.exeC:\Users\admin\AppData\Local\Temp\prs.xmmbinary
MD5:0099FF6BADDFC5866ACEDBBBECB47EFF
SHA256:3C4AEAF1D5DD82D022681592567D17D84AE493E3525D3314A6D45F03AEA0C311
2136101 Okey Domino ve Kart Oyunlari 2024.exeC:\Users\admin\AppData\Local\Temp\tsmpsdr2224.dattext
MD5:288E4C8445AB56464D4252D0FA18701A
SHA256:2837415F86CF8EAA348E5012F6DFBEEFA396D55ECB54E97D8D425B6975A3DC6A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
27
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1700
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2136
101 Okey Domino ve Kart Oyunlari 2024.exe
GET
200
152.89.37.90:80
http://reklam.hakkarim.net/reklamframegirisyeni.htm
unknown
2136
101 Okey Domino ve Kart Oyunlari 2024.exe
GET
200
142.250.185.174:80
http://www.google-analytics.com/urchin.js
unknown
whitelisted
2136
101 Okey Domino ve Kart Oyunlari 2024.exe
GET
200
152.89.37.90:80
http://salonlist.hakkarim.net/salonlar12.txt
unknown
2136
101 Okey Domino ve Kart Oyunlari 2024.exe
GET
200
185.169.52.209:80
http://radyo.hakkarim.net/radyo/radyolar.txt
unknown
2136
101 Okey Domino ve Kart Oyunlari 2024.exe
GET
200
152.89.37.90:80
http://reklam.hakkarim.net/gldbanner1.jpg
unknown
2136
101 Okey Domino ve Kart Oyunlari 2024.exe
GET
200
142.250.185.174:80
http://www.google-analytics.com/__utm.gif?utmwv=1.4&utmn=1526271926&utmcs=iso-8859-9&utmsr=1280x720&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=-&utmcn=1&utmdt=101%20Oyunu&utmhn=reklam.hakkarim.net&utmhid=363916166&utmr=-&utmp=/reklamframegirisyeni.htm&utmac=UA-1545574-1&utmcc=__utma%3D8651702.1526271926.1751761606.1751761606.1751761606.1%3B%2B__utmz%3D8651702.1751761606.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none)%3B%2B
unknown
whitelisted
2220
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6368
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1700
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1700
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.174
whitelisted
crl.microsoft.com
  • 23.53.40.176
  • 23.53.40.178
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 40.126.32.76
  • 40.126.32.133
  • 20.190.160.2
  • 20.190.160.131
  • 20.190.160.130
  • 20.190.160.132
  • 40.126.32.74
  • 20.190.160.3
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
reklam.hakkarim.net
  • 152.89.37.90
unknown
salonlist.hakkarim.net
  • 152.89.37.90
unknown
www.google-analytics.com
  • 142.250.185.174
whitelisted
radyo.hakkarim.net
  • 185.169.52.209
unknown

Threats

No threats detected
No debug info