File name:

CheatEvolution.zip

Full analysis: https://app.any.run/tasks/b5dfb05b-3bb2-4ae0-bdd0-8fea864b06a5
Verdict: Malicious activity
Analysis date: December 10, 2024, 19:13:43
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
lua
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

643F26FC4D70F7B4CB6CC69F81871E1B

SHA1:

68D93756FE0244373556424C1B05969D818C4967

SHA256:

0F0D91B9F5FFF3F9106753B914EC92ACEEFDCB223DDCD3CCACFFA9F7ADBFEF08

SSDEEP:

98304:DhfgZzbeMuYv4m0DUyZR4h9h6M9NkdKfZtVYiwSPmKsYS+7Yf7QjV/CQbbzUK+S3:oswaR4/7ky7eO1a+HSiOB0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the date of Windows installation

      • CheatEvolution.exe (PID: 1616)
    • Reads security settings of Internet Explorer

      • Launcher.exe (PID: 1512)
      • CheatEvolution.exe (PID: 1616)
      • WinRAR.exe (PID: 3688)
      • Launcher.exe (PID: 3208)
      • CheatEvolution.exe (PID: 4840)
      • Launcher.exe (PID: 4300)
      • CheatEvolution.exe (PID: 440)
    • Reads Microsoft Outlook installation path

      • CheatEvolution.exe (PID: 4840)
    • Checks Windows Trust Settings

      • CheatEvolution.exe (PID: 4840)
      • CheatEvolution.exe (PID: 440)
    • Reads Internet Explorer settings

      • CheatEvolution.exe (PID: 440)
    • Executable content was dropped or overwritten

      • CheatEvolution.exe (PID: 440)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 3688)
    • Reads the computer name

      • CheatEvolution.exe (PID: 1616)
      • Launcher.exe (PID: 1512)
      • Launcher.exe (PID: 3208)
      • CheatEvolution.exe (PID: 4840)
      • Launcher.exe (PID: 4300)
    • Process checks computer location settings

      • CheatEvolution.exe (PID: 1616)
      • Launcher.exe (PID: 1512)
      • Launcher.exe (PID: 3208)
    • Checks supported languages

      • Launcher.exe (PID: 1512)
      • CheatEvolution.exe (PID: 3696)
      • Launcher.exe (PID: 3208)
      • Launcher.exe (PID: 4300)
      • CheatEvolution.exe (PID: 440)
      • CheatEvolution.exe (PID: 4840)
      • CheatEvolution.exe (PID: 1616)
    • The process uses the downloaded file

      • CheatEvolution.exe (PID: 1616)
      • WinRAR.exe (PID: 3688)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3688)
    • Sends debugging messages

      • CheatEvolution.exe (PID: 1616)
      • CheatEvolution.exe (PID: 4840)
      • CheatEvolution.exe (PID: 440)
    • Checks proxy server information

      • CheatEvolution.exe (PID: 4840)
      • CheatEvolution.exe (PID: 440)
    • Reads the machine GUID from the registry

      • CheatEvolution.exe (PID: 4840)
      • CheatEvolution.exe (PID: 440)
    • Creates files or folders in the user directory

      • CheatEvolution.exe (PID: 4840)
    • Reads the software policy settings

      • CheatEvolution.exe (PID: 4840)
    • The process uses Lua

      • CheatEvolution.exe (PID: 4840)
      • CheatEvolution.exe (PID: 440)
    • Create files in a temporary directory

      • CheatEvolution.exe (PID: 4840)
      • CheatEvolution.exe (PID: 440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:02:10 04:31:22
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: CheatEvolution/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
128
Monitored processes
11
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe cheatevolution.exe no specs cheatevolution.exe launcher.exe no specs cheatevolution.exe no specs launcher.exe no specs launcher.exe cheatevolution.exe launcher.exe no specs launcher.exe cheatevolution.exe

Process information

PID
CMD
Path
Indicators
Parent process
440"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40440\CheatEvolution\CheatEvolution.exe" -startC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40440\CheatEvolution\CheatEvolution.exe
Launcher.exe
User:
admin
Company:
CheatEvolution
Integrity Level:
HIGH
Description:
CheatEvolution
Version:
2.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.40440\cheatevolution\cheatevolution.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1512"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\Launcher.exeCheatEvolution.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.37412\cheatevolution\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1616"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\CheatEvolution.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\CheatEvolution.exe
WinRAR.exe
User:
admin
Company:
CheatEvolution
Integrity Level:
HIGH
Description:
CheatEvolution
Exit code:
0
Version:
2.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.37412\cheatevolution\cheatevolution.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3188"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37741\CheatEvolution\Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37741\CheatEvolution\Launcher.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Launcher
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.37741\cheatevolution\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
3208"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37741\CheatEvolution\Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37741\CheatEvolution\Launcher.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.37741\cheatevolution\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3688"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\CheatEvolution.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3696"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\CheatEvolution.exe" -startC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\CheatEvolution.exeLauncher.exe
User:
admin
Company:
CheatEvolution
Integrity Level:
HIGH
Description:
CheatEvolution
Exit code:
0
Version:
2.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.37412\cheatevolution\cheatevolution.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4300"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40440\CheatEvolution\Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40440\CheatEvolution\Launcher.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.40440\cheatevolution\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4840"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37741\CheatEvolution\CheatEvolution.exe" -startC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37741\CheatEvolution\CheatEvolution.exe
Launcher.exe
User:
admin
Company:
CheatEvolution
Integrity Level:
HIGH
Description:
CheatEvolution
Exit code:
0
Version:
2.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.37741\cheatevolution\cheatevolution.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
5340"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40440\CheatEvolution\Launcher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40440\CheatEvolution\Launcher.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Launcher
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.40440\cheatevolution\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
8 340
Read events
8 295
Write events
45
Delete events
0

Modification events

(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CheatEvolution.zip
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4840) CheatEvolution.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4840) CheatEvolution.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
45
Suspicious files
17
Text files
35
Unknown types
4

Dropped files

PID
Process
Filename
Type
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\lua\additional_settings.luabinary
MD5:1F73E4D6E1A5C6EB97B31813EC21D0DB
SHA256:A0343D322F042622040D129C7B5D9F9B4CD10E0EE3B249F280B9DA7C1F7C0222
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\DotNetDataCollector64.exeexecutable
MD5:A2C0B5D0D9E5C2A2C774E8B587850447
SHA256:F0F3D0FAD632D9DDAC8FF0B4EAEC20094FA0F9ABDDF784954DFBB0723A997F21
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\CheatEvolution.exeexecutable
MD5:E385BF6ABE0DDFADFB7E098DA559A882
SHA256:5D5162DB542340F73B7451C2D9138EC714DA25483B05344392111C8B0316DBFC
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\DotNetDataCollector32.exeexecutable
MD5:F1C9C9A8B035DA9385D88CA34CD49305
SHA256:4168D6408994A297665AEEA68ABB6C062D58EA00851751959557E7F8A8BAC17D
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\lua\dlls\DotNetInterface.deps.jsonbinary
MD5:1AF5B8ECC43A1B62F78047514BB6F481
SHA256:E80618CC2EEA23D14764CE357D8E48C60CFAF9AAC548CD9A8907D21C7FAEEF44
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\lua\dlls\MonoDataCollector32.dllexecutable
MD5:C5B870CE07DA5206D8A81E139920B7DC
SHA256:EB26B38A604CF98B95A39FD249C0771E351061A9894D22284CDFE984E8FC7A6C
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\lua\DotNetInject.luatext
MD5:B5AE011C70C1D26CC31A5D818D60E53C
SHA256:31ED4209776DBFAD74EC811326439D26C02B6AB653056D5E171D952C12D3F25B
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\lua53-64.dllexecutable
MD5:B7C9F1E7E640F1A034BE84AF86970D45
SHA256:6D0A06B90213F082CB98950890518C0F08B9FC16DBFAB34D400267CB6CDADEFF
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\speedhack-i386.dllexecutable
MD5:4ACC9D3311FFF9D1AC7697010B43F90B
SHA256:2F77A5E845EE6838BFDC73005E748084A79E18AE0E2DE4702224041CDE78E0BA
3688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3688.37412\CheatEvolution\lua\dlls\MonoDataCollector64.dllexecutable
MD5:4237719534B21BB179480ED8BB23C0CC
SHA256:15EE5851FF1B33E369B43C66D44E3D1452A212C2A37F337B680FE8BD88DF8748
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
183
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
184.24.77.37:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6516
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6280
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6280
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4840
CheatEvolution.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
4840
CheatEvolution.exe
GET
200
142.250.184.195:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
184.24.77.37:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
104.126.37.131:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1176
svchost.exe
40.126.31.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.46
whitelisted
crl.microsoft.com
  • 184.24.77.37
  • 184.24.77.35
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
www.bing.com
  • 104.126.37.131
  • 104.126.37.186
  • 104.126.37.128
  • 104.126.37.171
  • 104.126.37.169
  • 104.126.37.154
  • 104.126.37.184
  • 104.126.37.170
  • 104.126.37.161
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.31.71
  • 40.126.31.69
  • 20.190.159.71
  • 20.190.159.68
  • 20.190.159.73
  • 40.126.31.67
  • 20.190.159.64
  • 20.190.159.2
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted

Threats

No threats detected
Process
Message
CheatEvolution.exe
arm disassembler
CheatEvolution.exe
DisassemblerThumb init
CheatEvolution.exe
MainUnit2
CheatEvolution.exe
Offset of LBR_Count=768
CheatEvolution.exe
sizeof fxstate = 512
CheatEvolution.exe
arm disassembler
CheatEvolution.exe
DisassemblerThumb init
CheatEvolution.exe
MainUnit2
CheatEvolution.exe
start
CheatEvolution.exe
sizeof fxstate = 512