File name: | wt_launcher_1.0.1.729.exe |
Full analysis: | https://app.any.run/tasks/fce28093-620a-484b-90b5-7054dcf84faa |
Verdict: | Malicious activity |
Analysis date: | April 13, 2024, 00:05:12 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 5AC7EFFDD6A264993E20360A2EB35005 |
SHA1: | A372FD1EA28490E6837FD2A4FE238A044BCEA6A1 |
SHA256: | FC51D6DE9C769F2A68720D6442A6E683A504E7DD44A3342EE61E8593E2342D42 |
SSDEEP: | 98304:noeSD406+4pPu2N0bYVnNCGplWLAGsaFtoafSYZs8COUaeB16fxS5GiCKOjCF1E+:PO0wty/yoaJrXAiik/J6 |
.exe | | | Win32 Executable Delphi generic (57.2) |
---|---|---|
.exe | | | Win32 Executable (generic) (18.2) |
.exe | | | Win16/32 Executable Delphi generic (8.3) |
.exe | | | Generic Win/DOS Executable (8) |
.exe | | | DOS Executable Generic (8) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2013:01:30 14:21:56+00:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
PEType: | PE32 |
LinkerVersion: | 2.25 |
CodeSize: | 65024 |
InitializedDataSize: | 197120 |
UninitializedDataSize: | - |
EntryPoint: | 0x113bc |
OSVersion: | 5 |
ImageVersion: | 6 |
SubsystemVersion: | 5 |
Subsystem: | Windows GUI |
FileVersionNumber: | 0.0.0.0 |
ProductVersionNumber: | 0.0.0.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
Comments: | This installation was built with Inno Setup. |
CompanyName: | Gaijin Entertainment |
FileDescription: | War Thunder Launcher Setup |
FileVersion: | |
LegalCopyright: | Copyright © 2011-2016 Gaijin Entertainment |
ProductName: | War Thunder Launcher |
ProductVersion: |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
128 | "C:\Windows\System32\taskkill.exe" /IM bpreport.exe | C:\Windows\System32\taskkill.exe | — | launcher.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
240 | "C:\Windows\System32\taskkill.exe" /F /IM aces.exe | C:\Windows\System32\taskkill.exe | — | launcher.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
392 | "C:\Windows\system32\netsh" firewall add portopening protocol = TCP port = 33333 name = "War Thunder" | C:\Windows\System32\netsh.exe | — | wt_launcher_1.0.1.729.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
552 | "C:\Windows\System32\taskkill.exe" /IM aces.exe | C:\Windows\System32\taskkill.exe | — | launcher.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
764 | "C:\Windows\system32\netsh.exe" firewall add allowedprogram "C:\WarThunder\win64\AFR-FriendlyD3D.exe" "War Thunder Game Client for CrossFire\SLI" ENABLE ALL | C:\Windows\System32\netsh.exe | — | wt_launcher_1.0.1.729.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
920 | "C:\Windows\system32\netsh" firewall add portopening protocol = TCP port = 80 name = "War Thunder" | C:\Windows\System32\netsh.exe | — | wt_launcher_1.0.1.729.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
984 | "C:\Windows\system32\netsh.exe" firewall add allowedprogram "C:\WarThunder\win64\ForceSingleGPU.exe" "War Thunder Game Client for disabled CrossFire\SLI" ENABLE ALL | C:\Windows\System32\netsh.exe | — | wt_launcher_1.0.1.729.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1072 | "C:\Users\admin\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe" | C:\Users\admin\AppData\Local\Gaijin\Program Files (x86)\NetAgent\gjagent.exe | — | launcher.exe | |||||||||||
User: admin Company: Gaijin Integrity Level: MEDIUM Description: Gaijin.Net Updater Exit code: 1 Version: 1.0.51 Modules
| |||||||||||||||
1124 | "C:\Windows\System32\taskkill.exe" /F /IM aces64.exe | C:\Windows\System32\taskkill.exe | — | launcher.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1540 | "C:\Windows\System32\cmd.exe" /c md content | C:\Windows\System32\cmd.exe | — | launcher.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
|
(PID) Process: | (3180) wt_launcher_1.0.1.729.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Owner |
Value: 6C0C0000566C3347368DDA01 | |||
(PID) Process: | (3180) wt_launcher_1.0.1.729.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | SessionHash |
Value: C3B54743DA19B3F89460254838E70BF5AA9400878EA464EE00112CC2D5CE025B | |||
(PID) Process: | (3180) wt_launcher_1.0.1.729.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Sequence |
Value: 1 | |||
(PID) Process: | (3180) wt_launcher_1.0.1.729.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFiles0000 |
Value: C:\WarThunder\launcher.exe | |||
(PID) Process: | (3180) wt_launcher_1.0.1.729.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFilesHash |
Value: 9C743356A478EF0AFBB85385729C7576FDD8770E3911DB0AE4631CDB608D9AC0 | |||
(PID) Process: | (3180) wt_launcher_1.0.1.729.tmp | Key: | HKEY_CURRENT_USER\Software\Gaijin\WarThunder |
Operation: | write | Name: | StartupWithWindows |
Value: Yes | |||
(PID) Process: | (3180) wt_launcher_1.0.1.729.tmp | Key: | HKEY_CURRENT_USER\Software\Gaijin\WarThunder |
Operation: | write | Name: | Version |
Value: 1.0.0.0 | |||
(PID) Process: | (3180) wt_launcher_1.0.1.729.tmp | Key: | HKEY_CURRENT_USER\Software\Gaijin\WarThunder |
Operation: | write | Name: | InstallDir |
Value: C:\WarThunder | |||
(PID) Process: | (3180) wt_launcher_1.0.1.729.tmp | Key: | HKEY_CURRENT_USER\Software\Gaijin\WarThunder |
Operation: | write | Name: | InstallPath |
Value: C:\WarThunder | |||
(PID) Process: | (3180) wt_launcher_1.0.1.729.tmp | Key: | HKEY_CURRENT_USER\Software\Gaijin\WarThunder |
Operation: | write | Name: | Dir |
Value: C:\WarThunder |
PID | Process | Filename | Type | |
---|---|---|---|---|
4008 | wt_launcher_1.0.1.729.exe | C:\Users\admin\AppData\Local\Temp\is-HV3DH.tmp\wt_launcher_1.0.1.729.tmp | executable | |
MD5:— | SHA256:— | |||
3488 | wt_launcher_1.0.1.729.exe | C:\Users\admin\AppData\Local\Temp\is-1SJB8.tmp\wt_launcher_1.0.1.729.tmp | executable | |
MD5:— | SHA256:— | |||
3180 | wt_launcher_1.0.1.729.tmp | C:\Users\admin\AppData\Local\Temp\is-7R3N0.tmp\_isetup\_shfoldr.dll | executable | |
MD5:— | SHA256:— | |||
3180 | wt_launcher_1.0.1.729.tmp | C:\WarThunder\is-EU5Q8.tmp | executable | |
MD5:— | SHA256:— | |||
3180 | wt_launcher_1.0.1.729.tmp | C:\WarThunder\unins000.exe | executable | |
MD5:— | SHA256:— | |||
3180 | wt_launcher_1.0.1.729.tmp | C:\WarThunder\is-0N9FO.tmp | image | |
MD5:— | SHA256:— | |||
3180 | wt_launcher_1.0.1.729.tmp | C:\WarThunder\icon.ico | image | |
MD5:— | SHA256:— | |||
3180 | wt_launcher_1.0.1.729.tmp | C:\WarThunder\is-JJ1LE.tmp | executable | |
MD5:— | SHA256:— | |||
3180 | wt_launcher_1.0.1.729.tmp | C:\WarThunder\launcher.exe | executable | |
MD5:— | SHA256:— | |||
3180 | wt_launcher_1.0.1.729.tmp | C:\WarThunder\is-NMVL3.tmp | executable | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3736 | run.exe | POST | 200 | 52.214.193.195:80 | http://yupmaster.gaijinent.com/launcher/version.php | unknown | — | — | — |
3216 | launcher.exe | GET | 301 | 104.20.82.98:80 | http://warthunder.com/news3-en.html | unknown | — | — | — |
3736 | run.exe | POST | 302 | 52.214.193.195:80 | http://yupmaster.gaijinent.com/launcher/update.php | unknown | — | — | — |
1624 | launcher.exe | GET | 301 | 104.20.82.98:80 | http://warthunder.com/news3-en.html | unknown | — | — | — |
3216 | launcher.exe | POST | 200 | 52.214.193.195:80 | http://yupmaster.gaijinent.com/yuitem/get_yup.php | unknown | — | — | — |
1624 | launcher.exe | POST | 200 | 52.214.193.195:80 | http://yupmaster.gaijinent.com/launcher/cdn_conf.php | unknown | — | — | — |
1624 | launcher.exe | POST | 200 | 52.214.193.195:80 | http://yupmaster.gaijinent.com/yuitem/get_yup.php | unknown | — | — | — |
3988 | launcher.exe | GET | — | 185.40.154.13:80 | http://04-warthunder-cdnnow.cdn.gaijin.net/warthunder/2.35.1.47/750d7830aa75593c38c8bb1b584e30ac170da235/aces.vromfs.bin | unknown | — | — | — |
3988 | launcher.exe | GET | 206 | 185.40.154.13:80 | http://04-warthunder-cdnnow.cdn.gaijin.net/warthunder/2.35.1.47/750d7830aa75593c38c8bb1b584e30ac170da235/compiledShaders/game.compatibilitySpirV.ps50.shdump.bin | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3216 | launcher.exe | 173.193.77.103:20101 | — | — | — | unknown |
3216 | launcher.exe | 173.193.77.103:20100 | — | — | — | unknown |
3216 | launcher.exe | 173.193.77.103:20105 | — | — | — | unknown |
3216 | launcher.exe | 173.193.77.103:20103 | — | — | — | unknown |
3216 | launcher.exe | 173.193.77.103:20102 | — | — | — | unknown |
3216 | launcher.exe | 173.193.77.103:20104 | — | — | — | unknown |
Domain | IP | Reputation |
---|---|---|
client-stats.warthunder.com |
| unknown |
yupmaster.gaijinent.com |
| unknown |
aws-yup-distr-02.gaijinent.com |
| unknown |
seeder.gaijin.lan |
| unknown |
warthunder.com |
| unknown |
aws-yup-distr-01.gaijinent.com |
| unknown |
aws-yup-distr-03.gaijinent.com |
| unknown |
router.bittorrent.com |
| unknown |
client-stats.gaijin.net |
| unknown |
dht.libtorrent.org |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET P2P BitTorrent DHT ping request |
— | — | Misc Attack | ET CINS Active Threat Intelligence Poor Reputation IP group 8 |
— | — | Potential Corporate Privacy Violation | ET P2P Vuze BT UDP Connection (5) |
— | — | Potential Corporate Privacy Violation | ET P2P BitTorrent peer sync |
— | — | Potential Corporate Privacy Violation | ET P2P BitTorrent DHT announce_peers request |
Process | Message |
---|---|
launcher.exe | BUILD TIMESTAMP: Dec 12 2016 13:58:41
|
launcher.exe | TIMER freq: ticks/usec=3 ticks/msec=3579
|
launcher.exe | statsd::connect: statsd server: client-stats.warthunder.com:20010 |
launcher.exe | Thread "Watchdog thread" started (auto delete is 1) |
launcher.exe | Creating thread "Watchdog thread"... |
launcher.exe | No config.blk found
|
launcher.exe | |
launcher.exe | Current language is English
|
launcher.exe | Unable to load BLK from files "C:\WarThunder\config.blk", "C:\WarThunder\config.blk.blk", "C:\WarThunder\config.blk.bin", "C:\WarThunder\config.blk.blk.bin"
|
launcher.exe | |