File name:

CheatEvolution.zip

Full analysis: https://app.any.run/tasks/b5dfb05b-3bb2-4ae0-bdd0-8fea864b06a5
Verdict: Malicious activity
Analysis date: December 10, 2024, 19:13:43
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
lua
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

643F26FC4D70F7B4CB6CC69F81871E1B

SHA1:

68D93756FE0244373556424C1B05969D818C4967

SHA256:

0F0D91B9F5FFF3F9106753B914EC92ACEEFDCB223DDCD3CCACFFA9F7ADBFEF08

SSDEEP:

98304:DhfgZzbeMuYv4m0DUyZR4h9h6M9NkdKfZtVYiwSPmKsYS+7Yf7QjV/CQbbzUK+S3:oswaR4/7ky7eO1a+HSiOB0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • CheatEvolution.exe (PID: 1616)
      • Launcher.exe (PID: 1512)
      • WinRAR.exe (PID: 3688)
      • Launcher.exe (PID: 3208)
      • CheatEvolution.exe (PID: 4840)
      • Launcher.exe (PID: 4300)
      • CheatEvolution.exe (PID: 440)
    • Reads the date of Windows installation

      • CheatEvolution.exe (PID: 1616)
    • Reads Microsoft Outlook installation path

      • CheatEvolution.exe (PID: 4840)
    • Checks Windows Trust Settings

      • CheatEvolution.exe (PID: 4840)
      • CheatEvolution.exe (PID: 440)
    • Executable content was dropped or overwritten

      • CheatEvolution.exe (PID: 440)
    • Reads Internet Explorer settings

      • CheatEvolution.exe (PID: 440)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 3688)
      • CheatEvolution.exe (PID: 1616)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 3688)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3688)
    • Checks supported languages

      • CheatEvolution.exe (PID: 1616)
      • Launcher.exe (PID: 1512)
      • CheatEvolution.exe (PID: 3696)
      • Launcher.exe (PID: 3208)
      • CheatEvolution.exe (PID: 4840)
      • Launcher.exe (PID: 4300)
      • CheatEvolution.exe (PID: 440)
    • Sends debugging messages

      • CheatEvolution.exe (PID: 1616)
      • CheatEvolution.exe (PID: 4840)
      • CheatEvolution.exe (PID: 440)
    • Reads the computer name

      • CheatEvolution.exe (PID: 1616)
      • Launcher.exe (PID: 1512)
      • Launcher.exe (PID: 3208)
      • CheatEvolution.exe (PID: 4840)
      • Launcher.exe (PID: 4300)
    • Process checks computer location settings

      • CheatEvolution.exe (PID: 1616)
      • Launcher.exe (PID: 1512)
      • Launcher.exe (PID: 3208)
    • Checks proxy server information

      • CheatEvolution.exe (PID: 4840)
      • CheatEvolution.exe (PID: 440)
    • Create files in a temporary directory

      • CheatEvolution.exe (PID: 4840)
      • CheatEvolution.exe (PID: 440)
    • Reads the software policy settings

      • CheatEvolution.exe (PID: 4840)
    • Creates files or folders in the user directory

      • CheatEvolution.exe (PID: 4840)
    • The process uses Lua

      • CheatEvolution.exe (PID: 4840)
      • CheatEvolution.exe (PID: 440)
    • Reads the machine GUID from the registry

      • CheatEvolution.exe (PID: 4840)
      • CheatEvolution.exe (PID: 440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:02:10 04:31:22
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: CheatEvolution/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
128
Monitored processes
11
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe cheatevolution.exe no specs cheatevolution.exe launcher.exe no specs cheatevolution.exe no specs launcher.exe no specs launcher.exe cheatevolution.exe launcher.exe no specs launcher.exe cheatevolution.exe

Process information

PID
CMD
Path
Indicators
Parent process
440"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40440\CheatEvolution\CheatEvolution.exe" -startC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40440\CheatEvolution\CheatEvolution.exe
Launcher.exe
User:
admin
Company:
CheatEvolution
Integrity Level:
HIGH
Description:
CheatEvolution
Version:
2.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.40440\cheatevolution\cheatevolution.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1512"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\Launcher.exeCheatEvolution.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.37412\cheatevolution\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1616"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\CheatEvolution.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\CheatEvolution.exe
WinRAR.exe
User:
admin
Company:
CheatEvolution
Integrity Level:
HIGH
Description:
CheatEvolution
Exit code:
0
Version:
2.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.37412\cheatevolution\cheatevolution.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3188"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37741\CheatEvolution\Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37741\CheatEvolution\Launcher.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Launcher
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.37741\cheatevolution\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
3208"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37741\CheatEvolution\Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37741\CheatEvolution\Launcher.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.37741\cheatevolution\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3688"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\CheatEvolution.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3696"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\CheatEvolution.exe" -startC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\CheatEvolution.exeLauncher.exe
User:
admin
Company:
CheatEvolution
Integrity Level:
HIGH
Description:
CheatEvolution
Exit code:
0
Version:
2.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.37412\cheatevolution\cheatevolution.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4300"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40440\CheatEvolution\Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40440\CheatEvolution\Launcher.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.40440\cheatevolution\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4840"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37741\CheatEvolution\CheatEvolution.exe" -startC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37741\CheatEvolution\CheatEvolution.exe
Launcher.exe
User:
admin
Company:
CheatEvolution
Integrity Level:
HIGH
Description:
CheatEvolution
Exit code:
0
Version:
2.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.37741\cheatevolution\cheatevolution.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
5340"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40440\CheatEvolution\Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40440\CheatEvolution\Launcher.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Launcher
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.40440\cheatevolution\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
8 340
Read events
8 295
Write events
45
Delete events
0

Modification events

(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CheatEvolution.zip
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4840) CheatEvolution.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4840) CheatEvolution.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
45
Suspicious files
17
Text files
35
Unknown types
4

Dropped files

PID
Process
Filename
Type
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\lua\dlls\DotNetInterface.deps.jsonbinary
MD5:1AF5B8ECC43A1B62F78047514BB6F481
SHA256:E80618CC2EEA23D14764CE357D8E48C60CFAF9AAC548CD9A8907D21C7FAEEF44
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\DotNetDataCollector32.exeexecutable
MD5:F1C9C9A8B035DA9385D88CA34CD49305
SHA256:4168D6408994A297665AEEA68ABB6C062D58EA00851751959557E7F8A8BAC17D
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\speedhack-x86_64.dllexecutable
MD5:156249CE92B9A15D71C39160DC05B4A1
SHA256:3BD69D00774B40132BD621C09C11093F188F06D634DB64A19A78C46A27388C8F
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\DotNetDataCollector64.exeexecutable
MD5:A2C0B5D0D9E5C2A2C774E8B587850447
SHA256:F0F3D0FAD632D9DDAC8FF0B4EAEC20094FA0F9ABDDF784954DFBB0723A997F21
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\lua\DotNetInject.luatext
MD5:B5AE011C70C1D26CC31A5D818D60E53C
SHA256:31ED4209776DBFAD74EC811326439D26C02B6AB653056D5E171D952C12D3F25B
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\lua\dlls\MonoDataCollector32.dllexecutable
MD5:C5B870CE07DA5206D8A81E139920B7DC
SHA256:EB26B38A604CF98B95A39FD249C0771E351061A9894D22284CDFE984E8FC7A6C
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\lua\DotNetInterface.luatext
MD5:04CDE30D6AA9999A846B5FC3CFC1F56C
SHA256:EAE2A91808BB58B386F3BDDE75176C7208C22BF5515C5D6E467C583DF2E72E15
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\lua53-64.dllexecutable
MD5:B7C9F1E7E640F1A034BE84AF86970D45
SHA256:6D0A06B90213F082CB98950890518C0F08B9FC16DBFAB34D400267CB6CDADEFF
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\lua\dotnetinfo.luatext
MD5:F30091A31003345EAE2A915D1EE13E9D
SHA256:CC505DA9EA622E39783D6AC0A98370E1B58EBA6702B9A1796FDC869AEEBBA261
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\lua\dlls\MonoDataCollector64.dllexecutable
MD5:4237719534B21BB179480ED8BB23C0CC
SHA256:15EE5851FF1B33E369B43C66D44E3D1452A212C2A37F337B680FE8BD88DF8748
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
183
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
184.24.77.37:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6516
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6280
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6280
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4840
CheatEvolution.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
4840
CheatEvolution.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
184.24.77.37:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
104.126.37.131:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1176
svchost.exe
40.126.31.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.46
whitelisted
crl.microsoft.com
  • 184.24.77.37
  • 184.24.77.35
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
www.bing.com
  • 104.126.37.131
  • 104.126.37.186
  • 104.126.37.128
  • 104.126.37.171
  • 104.126.37.169
  • 104.126.37.154
  • 104.126.37.184
  • 104.126.37.170
  • 104.126.37.161
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.31.71
  • 40.126.31.69
  • 20.190.159.71
  • 20.190.159.68
  • 20.190.159.73
  • 40.126.31.67
  • 20.190.159.64
  • 20.190.159.2
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted

Threats

No threats detected
Process
Message
CheatEvolution.exe
arm disassembler
CheatEvolution.exe
DisassemblerThumb init
CheatEvolution.exe
MainUnit2
CheatEvolution.exe
Offset of LBR_Count=768
CheatEvolution.exe
sizeof fxstate = 512
CheatEvolution.exe
arm disassembler
CheatEvolution.exe
DisassemblerThumb init
CheatEvolution.exe
MainUnit2
CheatEvolution.exe
start
CheatEvolution.exe
sizeof fxstate = 512