File name:

MegaCheat v8.2.3.exe

Full analysis: https://app.any.run/tasks/72dcc572-8a43-4520-adf3-6563db44d8b3
Verdict: Malicious activity
Threats:

Metamorfo is a trojan malware family that has been active since 2018. It remains a top threat, focusing on stealing victims’ financial information, including banking credentials and other data. The malware is known for targeting users in Brazil.

Analysis date: September 21, 2023, 13:21:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
metamorfo
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

194FA0549C1952B06B05FDF1F09B2BD1

SHA1:

04F215251D5182A06397FC56381487351F80CF75

SHA256:

0D8D44A2814BE4F0F6A41A3173A081A62126ACDD89D29D052D8BF38412003B62

SSDEEP:

98304:iHISzZ2QDhvLnT0oiwWdoNVyHZh5n/OacQVTsEROt:cI0hAoNVyHxn/OacDEM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • METAMORFO detected by memory dumps

      • MegaCheat v8.2.3.exe (PID: 3484)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • MegaCheat v8.2.3.exe (PID: 3484)
    • Reads the computer name

      • MegaCheat v8.2.3.exe (PID: 3484)
    • Creates files or folders in the user directory

      • MegaCheat v8.2.3.exe (PID: 3484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

ProgramID: com.embarcadero.Cheat
Comments: www.mega-cheats.ru
ProductVersion: 8.2.3
ProductName: MegaCheat
OriginalFileName: MegaCheat v8.2.3
LegalTrademarks: www.mega-cheats.ru
LegalCopyright: www.mega-cheats.ru
InternalName: MegaCheat
FileVersion: 8.2.3.0
FileDescription: www.mega-cheats.ru
CompanyName: www.mega-cheats.ru
CharacterSet: Windows, Cyrillic
LanguageCode: Russian
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 8.2.3.0
FileVersionNumber: 8.2.3.0
Subsystem: Windows GUI
SubsystemVersion: 5
ImageVersion: -
OSVersion: 5
EntryPoint: 0x46d804
UninitializedDataSize: -
InitializedDataSize: 2184192
CodeSize: 4637696
LinkerVersion: 2.25
PEType: PE32
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
TimeStamp: 2020:06:04 05:22:13+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #METAMORFO megacheat v8.2.3.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3484"C:\Users\admin\AppData\Local\Temp\MegaCheat v8.2.3.exe" C:\Users\admin\AppData\Local\Temp\MegaCheat v8.2.3.exe
explorer.exe
User:
admin
Company:
www.mega-cheats.ru
Integrity Level:
MEDIUM
Description:
www.mega-cheats.ru
Exit code:
0
Version:
8.2.3.0
Modules
Images
c:\users\admin\appdata\local\temp\megacheat v8.2.3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
Total events
209
Read events
209
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3484MegaCheat v8.2.3.exeC:\Users\admin\AppData\Local\MegaCheat\Tools\app.configtext
MD5:3A6C9E6AF54BCCEB22DAF1B898E8597B
SHA256:41F99C4B8EA08DBD193B2EC0FF5D26D418B72CEDD6220E28619A5CA9AE7F8402
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
4
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
f1-hack.ru
unknown

Threats

No threats detected
No debug info