File name:

GameRanger_v1.0.exe

Full analysis: https://app.any.run/tasks/db8785a5-d0d1-4440-afd9-dc39e20c8ffb
Verdict: Malicious activity
Analysis date: February 24, 2024, 21:17:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7F4C3472EFCBE0D231DD5C5305FE6DB6

SHA1:

EB6F1798792B4CEAF3AFF9468A7378EC7196676F

SHA256:

F4BE971E242923DEC1E22995EB1907FE45A90A617E738EFFF001085B1FFB27D6

SSDEEP:

1536:YgkNPnEO0brG38GI/cqTzcD6U2qBpjuBrq2qBXWXxXOE8L:DNFG8h/cmcBpjuBrq/BmBGL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • GameRanger_v1.0.exe (PID: 3656)
      • GameRanger.exe (PID: 3892)
    • Create files in the Startup directory

      • GameRanger_v1.0.exe (PID: 3656)
  • SUSPICIOUS

    • Connects to unusual port

      • GameRanger_v1.0.exe (PID: 3656)
      • GameRanger.exe (PID: 3892)
    • Creates a software uninstall entry

      • GameRanger_v1.0.exe (PID: 3656)
      • GameRanger.exe (PID: 3892)
    • Executable content was dropped or overwritten

      • GameRanger_v1.0.exe (PID: 3656)
      • GameRanger.exe (PID: 3892)
    • Searches for installed software

      • GameRanger.exe (PID: 3892)
      • GameRanger.exe (PID: 3304)
    • Process drops legitimate windows executable

      • GameRanger.exe (PID: 3892)
    • Application launched itself

      • GameRanger.exe (PID: 3892)
  • INFO

    • Reads the computer name

      • GameRanger_v1.0.exe (PID: 3656)
      • GameRanger.exe (PID: 3892)
    • Creates files or folders in the user directory

      • GameRanger.exe (PID: 3892)
      • GameRanger.exe (PID: 796)
      • GameRanger_v1.0.exe (PID: 3656)
    • Checks supported languages

      • GameRanger.exe (PID: 3892)
      • GameRanger.exe (PID: 3304)
      • GameRanger.exe (PID: 3180)
      • GameRanger.exe (PID: 796)
      • GameRanger_v1.0.exe (PID: 3656)
    • Manual execution by a user

      • GameRanger.exe (PID: 3304)
    • Create files in a temporary directory

      • GameRanger.exe (PID: 3892)
    • Reads the machine GUID from the registry

      • GameRanger.exe (PID: 3892)
      • GameRanger_v1.0.exe (PID: 3656)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:07:08 01:52:54+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 45056
InitializedDataSize: 65536
UninitializedDataSize: -
EntryPoint: 0xa3d2
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (Australian)
CharacterSet: Unicode
Comments: -
CompanyName: GameRanger Technologies
FileDescription: GameRanger
FileVersion: 1, 0, 0, 0
InternalName: GameRanger
LegalCopyright: Copyright © 1997-2009 GameRanger Technologies. All Rights Reserved.
LegalTrademarks: -
OriginalFileName: -
PrivateBuild: -
ProductName: GameRanger
ProductVersion: 1, 0, 0, 0
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start gameranger_v1.0.exe gameranger.exe gameranger.exe no specs gameranger.exe no specs gameranger.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
796"C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe" --channel="3892.1.1191343593\513860528" --lang=en-US --locales-dir-path="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger Prefs\Components\c1\Resources\locales\\" --log-file="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\debug.log" --log-severity=disable --resources-dir-path="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger Prefs\Components\c1\Resources\\" --type=utility --ns=1 --ppid=3892 /prefetch:-645351001C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exeGameRanger.exe
User:
admin
Company:
GameRanger Pty Ltd
Integrity Level:
MEDIUM
Description:
GameRanger
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\appdata\roaming\gameranger\gameranger\gameranger.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3180"C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe" --lang=en-US --locales-dir-path="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger Prefs\Components\c1\Resources\locales\\" --log-file="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\debug.log" --log-severity=disable --resources-dir-path="C:\Users\admin\AppData\Roaming\GameRanger\GameRanger Prefs\Components\c1\Resources\\" --type=renderer --ns=1 --ppid=3892 --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3892.0.1819503762\496713168" /prefetch:673131151C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exeGameRanger.exe
User:
admin
Company:
GameRanger Pty Ltd
Integrity Level:
MEDIUM
Description:
GameRanger
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\appdata\roaming\gameranger\gameranger\gameranger.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3304"C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe" C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exeexplorer.exe
User:
admin
Company:
GameRanger Pty Ltd
Integrity Level:
MEDIUM
Description:
GameRanger
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\appdata\roaming\gameranger\gameranger\gameranger.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3656"C:\Users\admin\AppData\Local\Temp\GameRanger_v1.0.exe" C:\Users\admin\AppData\Local\Temp\GameRanger_v1.0.exe
explorer.exe
User:
admin
Company:
GameRanger Technologies
Integrity Level:
MEDIUM
Description:
GameRanger
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\appdata\local\temp\gameranger_v1.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3892"C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe"C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe
GameRanger_v1.0.exe
User:
admin
Company:
GameRanger Pty Ltd
Integrity Level:
MEDIUM
Description:
GameRanger
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\appdata\roaming\gameranger\gameranger\gameranger.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
3 940
Read events
3 911
Write events
29
Delete events
0

Modification events

(PID) Process:(3656) GameRanger_v1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger
Operation:writeName:Comments
Value:
GameRanger - play your friends online
(PID) Process:(3656) GameRanger_v1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger
Operation:writeName:DisplayName
Value:
GameRanger
(PID) Process:(3656) GameRanger_v1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe
(PID) Process:(3656) GameRanger_v1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger
Operation:writeName:HelpLink
Value:
http://www.GameRanger.com/support/
(PID) Process:(3656) GameRanger_v1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Roaming\GameRanger\GameRanger
(PID) Process:(3656) GameRanger_v1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger
Operation:writeName:Publisher
Value:
GameRanger Technologies
(PID) Process:(3656) GameRanger_v1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger
Operation:writeName:URLInfoAbout
Value:
http://www.GameRanger.com/
(PID) Process:(3656) GameRanger_v1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger
Operation:writeName:NoModify
Value:
1
(PID) Process:(3656) GameRanger_v1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger
Operation:writeName:NoRemove
Value:
0
(PID) Process:(3656) GameRanger_v1.0.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\GameRanger
Operation:writeName:NoRepair
Value:
1
Executable files
25
Suspicious files
28
Text files
0
Unknown types
37

Dropped files

PID
Process
Filename
Type
3656GameRanger_v1.0.exeC:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\GameRanger.dllexecutable
MD5:2BBCA1C6AAE4389BD65F352BD87E1093
SHA256:957BFD423124EE703F9F496F47E2ED0019613E37598398FF512FDBF41C4FFAEB
3656GameRanger_v1.0.exeC:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Quake 4 Demoexecutable
MD5:5EB74D5DC67341770FA3005B5CB5EC10
SHA256:7646694E05224954AF31F1191E79A190BCFDED272CF4F65D5250161CA615D74E
3656GameRanger_v1.0.exeC:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Prey Demoexecutable
MD5:7685D30EDBBB57471937904C3CEBE170
SHA256:275D5524E85F21BAAB1A037497EAAE2B0E6B4923109F8D54D46558A0FAFC0D4E
3656GameRanger_v1.0.exeC:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Quake IIexecutable
MD5:BB5092219FE90FEEC44055AF28B1B1E1
SHA256:DB9D3BEF2656A1E42B4D988B19D8CB50956413C5364DBB22C3848021E6EEEE5B
3656GameRanger_v1.0.exeC:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Quakeexecutable
MD5:DBD0F04BD251DC52C3605A41F8AE771F
SHA256:937B95632B0051813024692561E04634BC5BB9C47BD7A11DB9A815387FECF264
3656GameRanger_v1.0.exeC:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Quake III Arenaexecutable
MD5:51E02B8426D4C831DDF036CD4CA8A4E3
SHA256:3D24071F506348C8E9C7D3D6E35C1271A55CC568E336220D4F522BDEC5262B08
3656GameRanger_v1.0.exeC:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Heretic IIexecutable
MD5:5FECF9358A719A8835453D5BEF04F041
SHA256:3936D92275C331644F72F4B115829DE8F297F144C456A39201A90E100C98450E
3656GameRanger_v1.0.exeC:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\GameRangerLaunch.dllexecutable
MD5:2B60C8E873747BF0317DE7457E733283
SHA256:0E035BE8B32F55A91FBE2DAD33F04C19A10C9FB411380FC2F3066ADFF0E1FE77
3656GameRanger_v1.0.exeC:\Users\admin\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\SiN Demoexecutable
MD5:E4AF25C3811609CEE32217223AAFBEBC
SHA256:EBB7F8E862EE0A6AD569CBB84112FD8789DF90A22CA860F1557557E4D2281521
3892GameRanger.exeC:\Users\admin\AppData\Roaming\GameRanger\GameRanger Prefs\Components\c1\icudtl.dat
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
13
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3656
GameRanger_v1.0.exe
GET
200
173.193.187.84:80
http://www.gameranger.com/download/Archive204X.gr_arc
unknown
binary
1.79 Mb
unknown
3892
GameRanger.exe
GET
302
173.193.187.84:80
http://www.GameRanger.com/download/component/c1.gr_arc
unknown
unknown
3892
GameRanger.exe
GET
167.114.116.70:80
http://dl3.GameRanger.com/c1.gr_arc
unknown
unknown
3892
GameRanger.exe
GET
302
173.193.187.84:80
http://www.GameRanger.com/download/component/c1.gr_arc
unknown
unknown
3892
GameRanger.exe
GET
200
173.193.187.84:80
http://dl1.GameRanger.com/c1.gr_arc
unknown
binary
22.0 Mb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3656
GameRanger_v1.0.exe
173.193.187.87:16000
connect.gameranger.com
SOFTLAYER
US
unknown
3656
GameRanger_v1.0.exe
173.193.187.84:80
www.gameranger.com
SOFTLAYER
US
unknown
3892
GameRanger.exe
173.193.187.84:80
www.gameranger.com
SOFTLAYER
US
unknown
3892
GameRanger.exe
167.114.116.70:80
dl3.GameRanger.com
OVH SAS
CA
unknown
3892
GameRanger.exe
173.193.187.87:16000
connect.gameranger.com
SOFTLAYER
US
unknown

DNS requests

Domain
IP
Reputation
connect.gameranger.com
  • 173.193.187.87
unknown
www.gameranger.com
  • 173.193.187.84
unknown
www.GameRanger.com
  • 173.193.187.84
unknown
dl3.GameRanger.com
  • 167.114.116.70
unknown
dl1.GameRanger.com
  • 173.193.187.84
unknown

Threats

No threats detected
No debug info