| URL: | https://gtarcade.com |
| Full analysis: | https://app.any.run/tasks/01803ea4-959c-4b22-8aee-0202b4e1c918 |
| Verdict: | Malicious activity |
| Analysis date: | April 01, 2023, 15:34:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 1B3BD6F83012AFC0F0B5F53AA69AC3B5 |
| SHA1: | DD6571F4C0FB4616704FA17EFAB9CDA64823EA70 |
| SHA256: | F3651C6DF89FFFC22CFF9CCD118A3EAFA3403F6B6419B7BF89FB1FF618FA0B56 |
| SSDEEP: | 3:N8wvK:2wi |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 572 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=1040,2721312467202938198,16138510272847829393,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=604 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 848 | "C:\Users\admin\AppData\Local\Gtarcade\app\gamehall\GTarExternal.exe" --start-from-gtarapp=3.1.11.3290 | C:\Users\admin\AppData\Local\Gtarcade\app\gamehall\GTarExternal.exe | Gtarcade.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Chromium Embedded Framework (CEF) Client Application Exit code: 0 Version: 3.3440.1806.g65046b7 Modules
| |||||||||||||||
| 1164 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1040,2721312467202938198,16138510272847829393,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --extension-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3156 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1400 | "C:\Users\admin\Downloads\setup-gtarcade-64284f6ed5cfd.exe" | C:\Users\admin\Downloads\setup-gtarcade-64284f6ed5cfd.exe | chrome.exe | ||||||||||||
User: admin Company: Shanghai Youzu Information Technology Corporation Integrity Level: MEDIUM Description: GTarcade Game Installer Exit code: 0 Version: 2.0.0.1 Modules
| |||||||||||||||
| 1436 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --field-trial-handle=1040,2721312467202938198,16138510272847829393,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=2716 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1460 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1040,2721312467202938198,16138510272847829393,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2976 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1632 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --field-trial-handle=1040,2721312467202938198,16138510272847829393,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3860 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1840 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1040,2721312467202938198,16138510272847829393,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=1748 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 2148 | "C:\Users\admin\AppData\Local\Gtarcade\app\GTarBugReport.exe" /prod=gtar_report | C:\Users\admin\AppData\Local\Gtarcade\app\GTarBugReport.exe | Gtarcade.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 4294967295 Modules
| |||||||||||||||
| 2228 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1040,2721312467202938198,16138510272847829393,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=3036 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| (PID) Process: | (2668) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2668) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2668) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2668) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2668) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2668) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2668) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
| (PID) Process: | (2668) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_installdate |
Value: 0 | |||
| (PID) Process: | (2668) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | metricsid_enableddate |
Value: 0 | |||
| (PID) Process: | (2668) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-64284EF3-A6C.pma | — | |
MD5:— | SHA256:— | |||
| 2440 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma | binary | |
MD5:03C4F648043A88675A920425D824E1B3 | SHA256:F91DBB7C64B4582F529C968C480D2DCE1C8727390482F31E4355A27BB3D9B450 | |||
| 2668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ba5b4278-5d8f-402f-b028-c68c201d36a6.tmp | text | |
MD5:— | SHA256:— | |||
| 2668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences | text | |
MD5:— | SHA256:— | |||
| 2668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version | text | |
MD5:00046F773EFDD3C8F8F6D0F87A2B93DC | SHA256:593EDE11D17AF7F016828068BCA2E93CF240417563FB06DC8A579110AEF81731 | |||
| 2668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:8FF312A95D60ED89857FEB720D80D4E1 | SHA256:946A57FAFDD28C3164D5AB8AB4971B21BD5EC5BFFF7554DBF832CB58CC37700B | |||
| 2668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF24f618.TMP | text | |
MD5:936EB7280DA791E6DD28EF3A9B46D39C | SHA256:CBAF2AFD831B32F6D1C12337EE5D2F090D6AE1F4DCB40B08BEF49BF52AD9721F | |||
| 2668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:5BD3C311F2136A7A88D3E197E55CF902 | SHA256:FA331915E1797E59979A3E4BCC2BD0D3DEAA039B94D4DB992BE251FD02A224B9 | |||
| 2668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF24f638.TMP | text | |
MD5:64AD8ED3E666540337BA541C549F72F7 | SHA256:BECBDB08B5B37D203A85F2E974407334053BB1D2270F0B3C9A4DB963896F2206 | |||
| 2668 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat | binary | |
MD5:9C016064A1F864C8140915D77CF3389A | SHA256:0E7265D4A8C16223538EDD8CD620B8820611C74538E420A88E333BE7F62AC787 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
860 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/dl6iudcrkm7tlleep5b7sio2si_2937/jflookgnkcckhobaglndicnbbgbonegd_2937_all_n6dma56ie7wmbezc4aw6zyp2jq.crx3 | US | binary | 9.30 Kb | whitelisted |
860 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/dl6iudcrkm7tlleep5b7sio2si_2937/jflookgnkcckhobaglndicnbbgbonegd_2937_all_n6dma56ie7wmbezc4aw6zyp2jq.crx3 | US | binary | 9.69 Kb | whitelisted |
860 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/dl6iudcrkm7tlleep5b7sio2si_2937/jflookgnkcckhobaglndicnbbgbonegd_2937_all_n6dma56ie7wmbezc4aw6zyp2jq.crx3 | US | binary | 13.8 Kb | whitelisted |
860 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/YGkwa4MXjfWSuERyWQYP_A_4/aapLKTSZ439A-0g3nqJr3Q | US | binary | 13.8 Kb | whitelisted |
860 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3 | US | binary | 90.2 Kb | whitelisted |
860 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/dl6iudcrkm7tlleep5b7sio2si_2937/jflookgnkcckhobaglndicnbbgbonegd_2937_all_n6dma56ie7wmbezc4aw6zyp2jq.crx3 | US | binary | 15.9 Kb | whitelisted |
860 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3 | US | binary | 179 Kb | whitelisted |
860 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3 | US | binary | 358 Kb | whitelisted |
860 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3 | US | crx | 3.72 Kb | whitelisted |
860 | svchost.exe | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/YGkwa4MXjfWSuERyWQYP_A_4/aapLKTSZ439A-0g3nqJr3Q | US | crx | 3.72 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3228 | chrome.exe | 43.135.190.24:443 | gtarcade.com | Tencent Building, Kejizhongyi Avenue | SG | unknown |
3228 | chrome.exe | 142.250.185.109:443 | accounts.google.com | GOOGLE | US | suspicious |
3228 | chrome.exe | 142.250.185.67:443 | ssl.gstatic.com | GOOGLE | US | whitelisted |
3228 | chrome.exe | 23.206.209.61:443 | static.gtarcade.com | AKAMAI-AS | DE | unknown |
3228 | chrome.exe | 142.250.185.226:443 | www.googleadservices.com | GOOGLE | US | suspicious |
— | — | 142.250.185.78:443 | www.google-analytics.com | GOOGLE | US | whitelisted |
— | — | 2.18.234.204:443 | upload.gtarcade.com | AKAMAI-AS | DE | whitelisted |
— | — | 23.206.209.61:443 | static.gtarcade.com | AKAMAI-AS | DE | unknown |
— | — | 142.250.185.226:443 | www.googleadservices.com | GOOGLE | US | suspicious |
— | — | 106.15.124.111:443 | ucms-api.youzu.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
Domain | IP | Reputation |
|---|---|---|
clients2.google.com |
| whitelisted |
gtarcade.com |
| whitelisted |
accounts.google.com |
| shared |
ssl.gstatic.com |
| whitelisted |
static.gtarcade.com |
| unknown |
www.googleadservices.com |
| whitelisted |
upload.gtarcade.com |
| unknown |
www.google-analytics.com |
| whitelisted |
connect.facebook.net |
| whitelisted |
collect.gtarcade.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
848 | GTarExternal.exe | Unknown Traffic | ET JA3 Hash - [Abuse.ch] Possible Adware |
848 | GTarExternal.exe | Unknown Traffic | ET JA3 Hash - [Abuse.ch] Possible Adware |
848 | GTarExternal.exe | Unknown Traffic | ET JA3 Hash - [Abuse.ch] Possible Adware |
848 | GTarExternal.exe | Unknown Traffic | ET JA3 Hash - [Abuse.ch] Possible Adware |
848 | GTarExternal.exe | Unknown Traffic | ET JA3 Hash - [Abuse.ch] Possible Adware |
848 | GTarExternal.exe | Unknown Traffic | ET JA3 Hash - [Abuse.ch] Possible Adware |
848 | GTarExternal.exe | Unknown Traffic | ET JA3 Hash - [Abuse.ch] Possible Adware |
Process | Message |
|---|---|
setup-gtarcade-64284f6ed5cfd.exe | https://micro-api.gtarcade.com/package.info?code=setup-gtarcade-64284f6ed5cfd&lang=en-us&type=1&os=Win7_64&client_id=6e3aab7cb29bc9495dfde01272c66f39&j_version= |
setup-gtarcade-64284f6ed5cfd.exe | https://micro-api.gtarcade.com/package.info?code=setup-gtarcade-64284f6ed5cfd&lang=en-us&type=1&os=Win7_64&client_id=6e3aab7cb29bc9495dfde01272c66f39&j_version= |
setup-gtarcade-64284f6ed5cfd.exe | {"code":0,"data":{"business_type":"1","ver":"13290","version":"3.1.11.3290","url":"https://static-cdn.gtarcade.com/gtarcade/gamerepository/micro/install/13290/gtarcade.zip?v=202005285666","game":{"ver":1,"game_id":0,"game_name":"","url":"https://static-cdn.gtarcade.com/","resources_path":"https://static-cdn.gtarcade.com/","desc":""},"game_vers":{"id":"","game_id":"","server_id":"","ver_code":"","ver":"","download_url":"","desc":"","status":"","g_type":"","md5":"","is_popup":"","system":"","create_time":"","public_time":"","download_size":"","space_size":"","increment_download_url":"","increment_md5":""},"user_from":"1","source_type_new":0,"source_value":"","status":0,"ad_id":""},"msg":"success","time":1680363383} |
setup-gtarcade-64284f6ed5cfd.exe | {"code":0,"data":{"business_type":"1","ver":"13290","version":"3.1.11.3290","url":"https://static-cdn.gtarcade.com/gtarcade/gamerepository/micro/install/13290/gtarcade.zip?v=202005285666","game":{"ver":1,"game_id":0,"game_name":"","url":"https://static-cdn.gtarcade.com/","resources_path":"https://static-cdn.gtarcade.com/","desc":""},"game_vers":{"id":"","game_id":"","server_id":"","ver_code":"","ver":"","download_url":"","desc":"","status":"","g_type":"","md5":"","is_popup":"","system":"","create_time":"","public_time":"","download_size":"","space_size":"","increment_download_url":"","increment_md5":""},"user_from":"1","source_type_new":0,"source_value":"","status":0,"ad_id":""},"msg":"success","time":1680363383} |
setup-gtarcade-64284f6ed5cfd.exe | install downloaded success |
setup-gtarcade-64284f6ed5cfd.exe | install downloaded success |
setup-gtarcade-64284f6ed5cfd.exe | C:\Users\admin\AppData\Local\Temp\gtarinstall_2557390.tmp |
setup-gtarcade-64284f6ed5cfd.exe | C:\Users\admin\AppData\Local\Temp\gtarinstall_2557390.tmp |
GTarExternal.exe | [2023-04-01 16:37:25.526] Start Creating CompletionPort and start Threads
|
GTarExternal.exe | [2023-04-01 16:37:25.526] Create CompletionPort
|