| File name: | GameRangerSetup.exe |
| Full analysis: | https://app.any.run/tasks/1e7b4720-4421-455e-a8ef-22e1cfc59c77 |
| Verdict: | Malicious activity |
| Analysis date: | March 14, 2024, 22:07:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 7F4C3472EFCBE0D231DD5C5305FE6DB6 |
| SHA1: | EB6F1798792B4CEAF3AFF9468A7378EC7196676F |
| SHA256: | F4BE971E242923DEC1E22995EB1907FE45A90A617E738EFFF001085B1FFB27D6 |
| SSDEEP: | 1536:YgkNPnEO0brG38GI/cqTzcD6U2qBpjuBrq2qBXWXxXOE8L:DNFG8h/cmcBpjuBrq/BmBGL |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:07:08 01:52:54+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 45056 |
| InitializedDataSize: | 65536 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa3d2 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (Australian) |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | GameRanger Technologies |
| FileDescription: | GameRanger |
| FileVersion: | 1, 0, 0, 0 |
| InternalName: | GameRanger |
| LegalCopyright: | Copyright © 1997-2009 GameRanger Technologies. All Rights Reserved. |
| LegalTrademarks: | - |
| OriginalFileName: | - |
| PrivateBuild: | - |
| ProductName: | GameRanger |
| ProductVersion: | 1, 0, 0, 0 |
| SpecialBuild: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2044 | "C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe" | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe | GameRangerSetup.exe | ||||||||||||
User: admin Company: GameRanger Pty Ltd Integrity Level: MEDIUM Description: GameRanger Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| 3228 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3672 | "C:\Users\admin\AppData\Local\Temp\GameRangerSetup.exe" | C:\Users\admin\AppData\Local\Temp\GameRangerSetup.exe | explorer.exe | ||||||||||||
User: admin Company: GameRanger Technologies Integrity Level: MEDIUM Description: GameRanger Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| 3936 | "C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe" --lang=en-US --locales-dir-path="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger Prefs\Components\c1\Resources\locales\\" --log-file="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\debug.log" --log-severity=disable --resources-dir-path="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger Prefs\Components\c1\Resources\\" --type=renderer --ns=1 --ppid=2044 --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="2044.0.1921185038\124908774" /prefetch:673131151 | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe | — | GameRanger.exe | |||||||||||
User: admin Company: GameRanger Pty Ltd Integrity Level: MEDIUM Description: GameRanger Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| (PID) Process: | (3672) GameRangerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | Comments |
Value: GameRanger - play your friends online | |||
| (PID) Process: | (3672) GameRangerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | DisplayName |
Value: GameRanger | |||
| (PID) Process: | (3672) GameRangerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe | |||
| (PID) Process: | (3672) GameRangerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | HelpLink |
Value: http://www.GameRanger.com/support/ | |||
| (PID) Process: | (3672) GameRangerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | InstallLocation |
Value: C:\Users\admin\AppData\Roaming\GameRanger\GameRanger | |||
| (PID) Process: | (3672) GameRangerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | Publisher |
Value: GameRanger Technologies | |||
| (PID) Process: | (3672) GameRangerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | URLInfoAbout |
Value: http://www.GameRanger.com/ | |||
| (PID) Process: | (3672) GameRangerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
| (PID) Process: | (3672) GameRangerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | NoRemove |
Value: 0 | |||
| (PID) Process: | (3672) GameRangerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | NoRepair |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3672 | GameRangerSetup.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\GameRanger.dll | executable | |
MD5:2BBCA1C6AAE4389BD65F352BD87E1093 | SHA256:957BFD423124EE703F9F496F47E2ED0019613E37598398FF512FDBF41C4FFAEB | |||
| 3672 | GameRangerSetup.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\GameRangerLaunch.dll | executable | |
MD5:2B60C8E873747BF0317DE7457E733283 | SHA256:0E035BE8B32F55A91FBE2DAD33F04C19A10C9FB411380FC2F3066ADFF0E1FE77 | |||
| 3672 | GameRangerSetup.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Quake III - Team Arena Demo | executable | |
MD5:7C19D82A0A73598AF25FC56864B819B8 | SHA256:A3C2BFBE8382556E8E925435C51E6A65B8962978278BD0FB38FB0757158AEF9C | |||
| 3672 | GameRangerSetup.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Quake | executable | |
MD5:DBD0F04BD251DC52C3605A41F8AE771F | SHA256:937B95632B0051813024692561E04634BC5BB9C47BD7A11DB9A815387FECF264 | |||
| 3672 | GameRangerSetup.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Prey Demo | executable | |
MD5:7685D30EDBBB57471937904C3CEBE170 | SHA256:275D5524E85F21BAAB1A037497EAAE2B0E6B4923109F8D54D46558A0FAFC0D4E | |||
| 3672 | GameRangerSetup.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Heretic II Demo | executable | |
MD5:6905221F237FA67B05D36CA60ED79699 | SHA256:77BEFAE8B14EC2FFC2CDC0A1E3A1194684BEB9F95193CEB83F531CF12CE9F18D | |||
| 3672 | GameRangerSetup.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Doom 3 | executable | |
MD5:B6B18083D824585CD1E5587E73D9CA05 | SHA256:E464D5197880488A0CFA8EB8576DD07C34A8B3A51B6F5B505E89E885AEA1AAED | |||
| 3672 | GameRangerSetup.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Prey | executable | |
MD5:ECC2A852D47389EF7A14F51EA9161585 | SHA256:2EA21B48CA5FDC857448C9A5F340340681DD760109CFD535DF045300F9857765 | |||
| 3672 | GameRangerSetup.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Heretic II | executable | |
MD5:5FECF9358A719A8835453D5BEF04F041 | SHA256:3936D92275C331644F72F4B115829DE8F297F144C456A39201A90E100C98450E | |||
| 2044 | GameRanger.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger Prefs\Components\c1\icudtl.dat | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3672 | GameRangerSetup.exe | GET | 200 | 173.193.187.84:80 | http://www.gameranger.com/download/Archive204X.gr_arc | unknown | binary | 1.79 Mb | unknown |
2044 | GameRanger.exe | GET | 302 | 173.193.187.84:80 | http://www.GameRanger.com/download/component/c1.gr_arc | unknown | — | — | unknown |
2044 | GameRanger.exe | GET | 200 | 173.193.187.84:80 | http://dl1.GameRanger.com/c1.gr_arc | unknown | binary | 22.0 Mb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3672 | GameRangerSetup.exe | 173.193.187.87:16000 | connect.gameranger.com | SOFTLAYER | US | unknown |
3672 | GameRangerSetup.exe | 173.193.187.84:80 | www.gameranger.com | SOFTLAYER | US | unknown |
2044 | GameRanger.exe | 173.193.187.84:80 | www.gameranger.com | SOFTLAYER | US | unknown |
Domain | IP | Reputation |
|---|---|---|
connect.gameranger.com |
| unknown |
www.gameranger.com |
| unknown |
www.GameRanger.com |
| unknown |
dl1.GameRanger.com |
| unknown |