2048 Puzzle Game

Traduzir Para:

Cartão de pontuação de ameaças

Popularity Rank: 5,688
Nível da Ameaça: 80 % (Alto)
Computadores infectados: 136
Visto pela Primeira Vez: April 21, 2021
Visto pela Última Vez: July 15, 2026
SO (s) Afetados: Windows

A extensão de navegador do 2048 Puzzle Game não deve ser associada ao portal legítimo do h[tt]p://2048game[.]com/, que oferece aos usuários um jogo semelhante ao sudoku, que pode ser usado gratuitamente. A extensão de navegador do 2048 Puzzle Game é publicada pelo h[tt]p://2048-game[.]review que se aproveita a popularidade acumulada pelo h[tt]p://2048game[.]com/ em outubro de 2017. A extensão do 2048 Puzzle Game do h[tt]p://2048-game[.]review parece ter sido instalada por 86 607 usuários (no momento da pesquisa), mas tem apenas duas avaliações que lhe deram uma classificação de cinco estrelas:

h[tt]ps://chrome.google[.]com/webstore/detail/2048-puzzle-game/bjjkmbkbhggaclclhhkahddjkfpbabcm

A extensão do 2048 Puzzle Game do h[tt]p://2048-game[.] é considerada um Programa Potencialmente Indesejado (PPI) que pode levar os usuários a acreditar que estão gostando do conteúdo do h[tt]p://2048game[.]com/. Os analistas de segurança do computador observaram que a extensão do 2048 Puzzle Game é um programa patrocinado por anúncios, projetado para alterar o seu provedor padrão de pesquisa para o h[tt]p://2048-game[.]review/?type=comoima&q=[KEYWORD] e carregar ofertas promocionais em todas as páginas que você navega na Internet. Você pode descobrir mais sobre a sua funcionalidade de marketing ao ler os Termos de Uso e o Contrato de Privacidade publicados no 2048-game.review/ext/2048/terms.html, 2048-game.review/ext/2048/eula.html, e 2048-game.review/ext/2048/privacy.html. Quando você tem a extensão do 2048 Puzzle Game em segundo plano, os seus pedidos de pesquisa através do Omnibox e da barra de pesquisa são redirecionados via h[tt]p://2048-game[.]review/?type=comoima&q=[KEYWORD] para:

h[tt]ps://search.yahoo[.]com/yhs/search?hspart=skylikes&hsimp=yhs-newtab&p=[KEYWORD]&type=comoima

A página acima mencionada oferece acesso a um mecanismo de pesquisa personalizado do Yahoo que carrega conteúdo promocional de uma lista definida de afiliados. Dessa forma, os operadores do h[tt]p://2048-game[.]review podem redirecionar os usuários para um conteúdo pago e reivindicar a receita afiliada do Yahoo. Os anúncios gerados pelo 2048 Puzzle Game podem não ser verificados e incluir links para páginas de phishing. Os usuários que instalam a extensão do 2048 Puzzle Game concordam que não podem procurar por responsáveis pelos danos resultantes dos links fornecidos pela extensão do 2048 Puzzle Game. Portanto, você deve considerar a remoção do aplicativo do 2048 Puzzle Game.

Relatório de análise

Informação geral

Family Name: Trojan.Downloader.Agent.NA
Signature status: Hash Mismatch

Known Samples

MD5: 9f3504ab95f1aed7dc3a8bfa970ecd4e
SHA1: 5cc473c3aa002b23d35298deef9f32ce04ec5276
SHA256: BF391A850A4C5E56570D2033CEF6CF81D713DC072E6371F159243306E75D1C12
Tamanho do Arquivo: 2.72 MB, 2716832 bytes
MD5: c57cbde6a0f0771fae3c2370d261b866
SHA1: 904ee0c270ad81ec40990b31d13eb5ee954f96da
SHA256: 1A8AD57027AB4E103919D6575D79A7F9E03E30E153C368E32936C5F4DBE97CF8
Tamanho do Arquivo: 1.21 MB, 1205624 bytes
MD5: 35a50cf3b454390d5a08754f621c0a65
SHA1: 2064f1ed7e83be3410325a64f34b22a614661a30
SHA256: CE2DB8910AD76A43A38D35A60C73FEB92DBDE77DAB4D7C13E5B8B88C071989AD
Tamanho do Arquivo: 1.26 MB, 1263512 bytes
MD5: 82328c291b95a81aaf244898bf95ff94
SHA1: 865d8590fec1d51773fa2a020b05aa4cd078a47b
SHA256: 7544B971F09023707D5E50A271045E8A79D77D6BD765341DACDA917BA1E00209
Tamanho do Arquivo: 1.26 MB, 1263512 bytes
MD5: d3196874428d4e457eebfc4357252c3f
SHA1: fd249ad14ad334745e81a468c99ae2a2204840c9
SHA256: 47760A4360F218FB71D6D5AF58B847A4E3CFB28319ABC38A6E2C0C867C62270A
Tamanho do Arquivo: 1.70 MB, 1700104 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Nome Valor
Company Name
  • Better Cloud Solutions
  • Google LLC
  • Lavasoft Inc.
Company Short Name
  • Better Cloud Solutions
  • BetterCloudSolutions
  • Google
  • Lavasoft
File Description
  • Google Chrome
  • Lavasoft quicklaunch browser
  • WebNavigatorBrowser
  • WebNavigatorBrowser Installer
File Version
  • 85.0.4183.121
  • 2.3.0.14
  • 2.3.0.13
  • 2.1.2.1
Internal Name
  • chrome_pwa_launcher
  • setup
  • webnavigatorbrowser_pwa_launcher
Last Change
  • 0
  • 0f89ef11042a546cf684de326b6b33ea23869b1b
  • 204fb33ef566736440f8445032aef3e4b85a9bf2
  • a81aa729a8e1fd413943a339393c82e7b8055ddc-refs/branch-heads/4183@{#1864}
Legal Copyright
  • Copyright 2020 Better Cloud Solutions. All rights reserved.
  • Copyright 2020 Google LLC. All rights reserved.
  • Copyright 2020 Lavasoft. All rights reserved.
Official Build 1
Original Filename
  • chrome_pwa_launcher.exe
  • setup.exe
  • webnavigatorbrowser_pwa_launcher.exe
Product Name
  • Google Chrome
  • Lavasoft quicklaunch browser
  • WebNavigatorBrowser
  • WebNavigatorBrowser Installer
Product Short Name
  • Chrome
  • quicklaunch browser
  • WebNavigatorBrowser
  • WebNavigatorBrowser Installer
Product Version
  • 85.0.4183.121
  • 2.3.0.14
  • 2.3.0.13
  • 2.1.2.1

Digital Signatures

Signer Root Status
Better Cloud Solutions LTD COMODO RSA Extended Validation Code Signing CA Self Signed
Google LLC DigiCert SHA2 Assured ID Code Signing CA Hash Mismatch
Lavasoft Software Canada Inc. Entrust Root Certification Authority - G2 Root Not Trusted

File Traits

  • big overlay
  • HighEntropy
  • Installer Version
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 2,323
Potentially Malicious Blocks: 386
Whitelisted Blocks: 1,902
Unknown Blocks: 35

Visual Map

? 0 ? 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 x 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x 0 0 0 x 0 x x x x x x x x x x 0 x x x x 0 0 x 0 0 x x x x x x x x x 0 0 0 x x 0 x x x x x 0 0 0 x x 0 0 0 0 0 0 0 x x x 0 x x 0 x x 0 x x x 0 x x x 0 x x x x x x x x 0 x 0 0 x 0 x x 0 x x 0 0 0 0 x 0 0 x x 0 0 x x x x x x 0 0 x x x 0 0 x 0 0 x 0 0 x x 0 x 0 x x x x x x 0 x x 0 x x 0 x x x 0 x 0 0 0 0 0 x 0 x x x 0 0 0 x ? ? ? ? ? 0 x x 0 0 0 x x x x x x x x x x 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 x x 0 0 x x 0 0 x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 x x ? 0 0 x x x x x 0 x x x x x x x 0 x 0 x x x 0 0 0 x 0 0 0 0 x x x 0 0 0 0 x x x 0 0 x 0 0 0 x 0 0 x 0 0 0 x x 0 0 0 0 0 0 x x 0 x x 0 0 0 x x x x x x x x x x 0 x x 0 x 0 x x x x x x x x 0 x x x 0 0 x 0 x 0 x 0 0 x x x x 0 x 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 x 0 0 x x 0 0 x 0 0 x x 0 0 0 x 0 x x 0 x 0 x 0 x 0 x x x 0 0 0 0 0 x x 0 0 x 0 0 x x 0 x ? 0 ? 0 ? 0 ? x x ? ? x 0 x x x x x 0 x 0 x x x x x x x 0 x 0 x 0 x x 0 0 x 0 x 0 x x 0 x x x 0 x 0 0 0 0 0 x x x x 0 0 x x 0 0 x x 0 x x x 0 0 x x x x 0 x x 0 x 0 x x 0 0 x x 0 x 0 0 0 x x 0 0 0 x x 0 x x x 0 x x 0 0 x x x x x x x x 0 0 0 x x x 0 x x x 0 ? 1 x x 0 0 0 x x x x x 0 x x x 0 0 0 x x x 0 0 0 0 x x 0 0 x 0 0 x x x 0 x 0 x x 0 x x x 0 x 0 x x 0 x x 0 x 0 0 x x x 0 0 x x x x 0 x x 0 x x 0 x 0 x 0 0 0 x x 0 0 0 x x x 0 0 x 0 0 0 0 x 0 0 0 0 0 x x x x x x x x 0 x 0 0 x 0 x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Downloader.Agent.NA

Files Modified

File Attributes
\device\namedpipe\crashpad_5064_uuobzvprpskkvdux Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\crashpad_5064_uuobzvprpskkvdux Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\appdata\local\temp\webnavigatorbrowser_installer.log Read Attributes,Synchronize,Append data
c:\users\user\appdata\local\webnavigatorbrowser\user data\crashpad\settings.dat Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtLockFile
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnlockFile
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent

Shell Command Execution

c:\users\user\downloads\5cc473c3aa002b23d35298deef9f32ce04ec5276_0002716832 c:\users\user\downloads\5cc473c3aa002b23d35298deef9f32ce04ec5276_0002716832 --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Vggtqzls\AppData\Local\WebNavigatorBrowser\User Data\Crashpad" --annotation=plat=Win64 --annotation=prod=WebNavigatorBrowser --annotation=ver=2.1.2.1 --initial-client-data=0x2c0,0x2c4,0x2c8,0x2bc,0x2cc,0x7ff6697d58f0,0x7ff6697d5900,0x7ff6697d5910

Mais visto

Carregando...