| File name: | GameRanger_v1.0.exe |
| Full analysis: | https://app.any.run/tasks/db8785a5-d0d1-4440-afd9-dc39e20c8ffb |
| Verdict: | Malicious activity |
| Analysis date: | February 24, 2024, 21:17:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 7F4C3472EFCBE0D231DD5C5305FE6DB6 |
| SHA1: | EB6F1798792B4CEAF3AFF9468A7378EC7196676F |
| SHA256: | F4BE971E242923DEC1E22995EB1907FE45A90A617E738EFFF001085B1FFB27D6 |
| SSDEEP: | 1536:YgkNPnEO0brG38GI/cqTzcD6U2qBpjuBrq2qBXWXxXOE8L:DNFG8h/cmcBpjuBrq/BmBGL |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:07:08 01:52:54+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 45056 |
| InitializedDataSize: | 65536 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa3d2 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (Australian) |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | GameRanger Technologies |
| FileDescription: | GameRanger |
| FileVersion: | 1, 0, 0, 0 |
| InternalName: | GameRanger |
| LegalCopyright: | Copyright © 1997-2009 GameRanger Technologies. All Rights Reserved. |
| LegalTrademarks: | - |
| OriginalFileName: | - |
| PrivateBuild: | - |
| ProductName: | GameRanger |
| ProductVersion: | 1, 0, 0, 0 |
| SpecialBuild: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 796 | "C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe" --channel="3892.1.1191343593\513860528" --lang=en-US --locales-dir-path="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger Prefs\Components\c1\Resources\locales\\" --log-file="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\debug.log" --log-severity=disable --resources-dir-path="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger Prefs\Components\c1\Resources\\" --type=utility --ns=1 --ppid=3892 /prefetch:-645351001 | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe | — | GameRanger.exe | |||||||||||
User: admin Company: GameRanger Pty Ltd Integrity Level: MEDIUM Description: GameRanger Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| 3180 | "C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe" --lang=en-US --locales-dir-path="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger Prefs\Components\c1\Resources\locales\\" --log-file="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\debug.log" --log-severity=disable --resources-dir-path="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger Prefs\Components\c1\Resources\\" --type=renderer --ns=1 --ppid=3892 --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3892.0.1819503762\496713168" /prefetch:673131151 | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe | — | GameRanger.exe | |||||||||||
User: admin Company: GameRanger Pty Ltd Integrity Level: MEDIUM Description: GameRanger Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| 3304 | "C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe" | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe | — | explorer.exe | |||||||||||
User: admin Company: GameRanger Pty Ltd Integrity Level: MEDIUM Description: GameRanger Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| 3656 | "C:\Users\admin\AppData\Local\Temp\GameRanger_v1.0.exe" | C:\Users\admin\AppData\Local\Temp\GameRanger_v1.0.exe | explorer.exe | ||||||||||||
User: admin Company: GameRanger Technologies Integrity Level: MEDIUM Description: GameRanger Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| 3892 | "C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe" | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe | GameRanger_v1.0.exe | ||||||||||||
User: admin Company: GameRanger Pty Ltd Integrity Level: MEDIUM Description: GameRanger Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| (PID) Process: | (3656) GameRanger_v1.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | Comments |
Value: GameRanger - play your friends online | |||
| (PID) Process: | (3656) GameRanger_v1.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | DisplayName |
Value: GameRanger | |||
| (PID) Process: | (3656) GameRanger_v1.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe | |||
| (PID) Process: | (3656) GameRanger_v1.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | HelpLink |
Value: http://www.GameRanger.com/support/ | |||
| (PID) Process: | (3656) GameRanger_v1.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | InstallLocation |
Value: C:\Users\admin\AppData\Roaming\GameRanger\GameRanger | |||
| (PID) Process: | (3656) GameRanger_v1.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | Publisher |
Value: GameRanger Technologies | |||
| (PID) Process: | (3656) GameRanger_v1.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | URLInfoAbout |
Value: http://www.GameRanger.com/ | |||
| (PID) Process: | (3656) GameRanger_v1.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
| (PID) Process: | (3656) GameRanger_v1.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | NoRemove |
Value: 0 | |||
| (PID) Process: | (3656) GameRanger_v1.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger |
| Operation: | write | Name: | NoRepair |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3656 | GameRanger_v1.0.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\GameRanger.dll | executable | |
MD5:2BBCA1C6AAE4389BD65F352BD87E1093 | SHA256:957BFD423124EE703F9F496F47E2ED0019613E37598398FF512FDBF41C4FFAEB | |||
| 3656 | GameRanger_v1.0.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Quake 4 Demo | executable | |
MD5:5EB74D5DC67341770FA3005B5CB5EC10 | SHA256:7646694E05224954AF31F1191E79A190BCFDED272CF4F65D5250161CA615D74E | |||
| 3656 | GameRanger_v1.0.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Prey Demo | executable | |
MD5:7685D30EDBBB57471937904C3CEBE170 | SHA256:275D5524E85F21BAAB1A037497EAAE2B0E6B4923109F8D54D46558A0FAFC0D4E | |||
| 3656 | GameRanger_v1.0.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Quake II | executable | |
MD5:BB5092219FE90FEEC44055AF28B1B1E1 | SHA256:DB9D3BEF2656A1E42B4D988B19D8CB50956413C5364DBB22C3848021E6EEEE5B | |||
| 3656 | GameRanger_v1.0.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Quake | executable | |
MD5:DBD0F04BD251DC52C3605A41F8AE771F | SHA256:937B95632B0051813024692561E04634BC5BB9C47BD7A11DB9A815387FECF264 | |||
| 3656 | GameRanger_v1.0.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Quake III Arena | executable | |
MD5:51E02B8426D4C831DDF036CD4CA8A4E3 | SHA256:3D24071F506348C8E9C7D3D6E35C1271A55CC568E336220D4F522BDEC5262B08 | |||
| 3656 | GameRanger_v1.0.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Heretic II | executable | |
MD5:5FECF9358A719A8835453D5BEF04F041 | SHA256:3936D92275C331644F72F4B115829DE8F297F144C456A39201A90E100C98450E | |||
| 3656 | GameRanger_v1.0.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\GameRangerLaunch.dll | executable | |
MD5:2B60C8E873747BF0317DE7457E733283 | SHA256:0E035BE8B32F55A91FBE2DAD33F04C19A10C9FB411380FC2F3066ADFF0E1FE77 | |||
| 3656 | GameRanger_v1.0.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\SiN Demo | executable | |
MD5:E4AF25C3811609CEE32217223AAFBEBC | SHA256:EBB7F8E862EE0A6AD569CBB84112FD8789DF90A22CA860F1557557E4D2281521 | |||
| 3892 | GameRanger.exe | C:\Users\admin\AppData\Roaming\GameRanger\GameRanger Prefs\Components\c1\icudtl.dat | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3656 | GameRanger_v1.0.exe | GET | 200 | 173.193.187.84:80 | http://www.gameranger.com/download/Archive204X.gr_arc | unknown | binary | 1.79 Mb | unknown |
3892 | GameRanger.exe | GET | 302 | 173.193.187.84:80 | http://www.GameRanger.com/download/component/c1.gr_arc | unknown | — | — | unknown |
3892 | GameRanger.exe | GET | — | 167.114.116.70:80 | http://dl3.GameRanger.com/c1.gr_arc | unknown | — | — | unknown |
3892 | GameRanger.exe | GET | 302 | 173.193.187.84:80 | http://www.GameRanger.com/download/component/c1.gr_arc | unknown | — | — | unknown |
3892 | GameRanger.exe | GET | 200 | 173.193.187.84:80 | http://dl1.GameRanger.com/c1.gr_arc | unknown | binary | 22.0 Mb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3656 | GameRanger_v1.0.exe | 173.193.187.87:16000 | connect.gameranger.com | SOFTLAYER | US | unknown |
3656 | GameRanger_v1.0.exe | 173.193.187.84:80 | www.gameranger.com | SOFTLAYER | US | unknown |
3892 | GameRanger.exe | 173.193.187.84:80 | www.gameranger.com | SOFTLAYER | US | unknown |
3892 | GameRanger.exe | 167.114.116.70:80 | dl3.GameRanger.com | OVH SAS | CA | unknown |
3892 | GameRanger.exe | 173.193.187.87:16000 | connect.gameranger.com | SOFTLAYER | US | unknown |
Domain | IP | Reputation |
|---|---|---|
connect.gameranger.com |
| unknown |
www.gameranger.com |
| unknown |
www.GameRanger.com |
| unknown |
dl3.GameRanger.com |
| unknown |
dl1.GameRanger.com |
| unknown |