Gridinsoft Logo
File Icon

The GLP_installer_900223150_market.exe (Tencent Game Downloader) File Analysis

Technical Analysis

File Name GLP_installer_900223150_market.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
49152:608OhxtUg9OUi82w6aQp9dgS1GUL38XhCOYc3iJXe9emEPGKOPkQThMYRMnm7LB6:608vdsGaQNgS1C6e6ngKpq+
Scanner Version 1.0.142.174
Database Version 2023-10-08 15:01:52 UTC

Suspicious File Detected

Detected by 14 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
19%
Detection Rate
3,809,488
File Size (bytes)
14/72
Engines Detected
2023-10-08
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
e7f4d560e7520eb427eddb72cb645344
SHA1
8b9c624f90f150ea10fe5eac0d219be2d719280d
SHA256
8700e903754a00c6cf444f1c437e2944d72887310c11199ccda97b0e9517a876
SHA512
cfe7dfae8333d9d8320b0915abdd6d7da921c60a9d4b702568df39fc2fcac7fa1f3efe0c258d2e163a1f2b8e12426c333029eb7bbefc8e147f2c472466ed7532
ImpHash
0e2b0c48d5c7e0af756a1d45ad1efe66

Security Engines with Detections (14 of 72)

Bkav
W32.AIDetectMalware Malicious
CAT-QuickHeal
Trojan.Tencent Malicious
Cylance
unsafe Malicious
K7AntiVirus
Adware ( 005a0db31 ) Malicious
K7GW
Adware ( 005a0db31 ) Malicious
ESET-NOD32
a variant of Win32/Tencent.X potentially unwanted Malicious
McAfee-GW-Edition
Artemis Malicious
Antiy-AVL
GrayWare/Win32.Tencent Malicious
McAfee
Artemis!E7F4D560E752 Malicious
VBA32
Riskware.Tencent Malicious
Ikarus
PUA.Tencent Malicious
MaxSecure
Trojan.Malware.300983.susgen Malicious
Fortinet
Riskware/Tencent Malicious
DeepInstinct
MALICIOUS Malicious
58 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: c2fc8ab993ffbdb912225455b9583345
Fuzzy: 483971c513317e3de8fc35081d213929
dHash: c8ce9a0b07a6f831
Image Base 0x00400000
Entry Point 0x00620be4
Compilation Time 2021-09-17 02:57:05
Checksum 0x003a35e4 (Actual: 0x003a35e4)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path D:\Devops\agent\workspace\p-111758179e0043a5b011650a32a71ea0\src\TGBDownloader\Output\TGBDownloader\Release\TGBDownloader.pdb
Digital Signature Unknown certificate revision 7070
Imports 16 libraries
Exports 0 functions
Resources 9 Resources
Sections 8 Sections

Digital Signatures

DigiCert Assured ID Code Signing CA-1 Tencent Technology(Shenzhen) Company Limited (CN)
DigiCert Assured ID Root CA DigiCert Inc (US)

Version Information

CompanyName Tencent
FileDescription Tencent Game Downloader
FileVersion 1, 0, 0, 1
InternalName TGBDownloader.exe
LegalCopyright Copyright ? 2020 Tencent. All Rights Reserved.
OriginalFilename TGBDownloader.exe
ProductName Tencent Game Downloader
ProductVersion 1, 0, 0, 1
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,604,106 bytes 2,604,544 bytes 6.71 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 2BD24D366544B5191C8D3852EA95A081
.rdata 0x0027d000 541,830 bytes 542,208 bytes 5.44 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D927738A1ADB744E5A2944B0B2EA4B18
.data 0x00302000 84,436 bytes 66,048 bytes 5.14 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0330018292C674234C21B81A173AA699
.gfids 0x00317000 4,360 bytes 4,608 bytes 3.99 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ A0ED665C78BF78565665339DBADFF427
.tls 0x00319000 9 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1F354D76203061BFDD5A53DAE48D5435
.QMGuid 0x0031a000 20 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x0031b000 458,696 bytes 458,752 bytes 7.79 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 491E51D60F59C3A97D4821955C4F2E50
.reloc 0x0038b000 119,936 bytes 120,320 bytes 6.59 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 6B73CEC0E79CF9DC9F83D95989159A57
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 9 (458,005 bytes)
Resource Type Count Total Size Percentage
CUSTOM 2 85,830 bytes
18.7%
ZIPRES 1 360,872 bytes
78.8%
RT_ICON 1 9,640 bytes
2.1%
RT_MENU 1 80 bytes
0%
RT_STRING 1 84 bytes
0%
RT_GROUP_ICON 1 20 bytes
0%
RT_VERSION 1 828 bytes
0.2%
RT_MANIFEST 1 651 bytes
0.1%

Certificate Chain Analysis

Certificate #1
Subject Tencent Technology(Shenzhen) Company Limited
Tencent Technology(Shenzhen) Company Limited
CN
Issuer DigiCert Assured ID Code Signing CA-1
Serial Number 18874367992585516799620967379699280448
Certificate #2
Subject DigiCert Assured ID Code Signing CA-1
DigiCert Inc
US
Issuer DigiCert Assured ID Root CA
Serial Number 20812206907036738015322008881189383613
Certificate Verification Status

Unknown certificate revision 7070

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
14 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware