| File name: | NoClippingBro_[unknowncheats.me]_.exe |
| Full analysis: | https://app.any.run/tasks/a60fde04-1473-4797-a0e8-d3247bf7a657 |
| Verdict: | Malicious activity |
| Analysis date: | October 04, 2024, 18:52:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 1BF97464516EBA32632E4978EF2F7E4F |
| SHA1: | ECBADE5BED7C0E5077A780AE40F9989C35F2C0DF |
| SHA256: | 3E636D37906E3D578472E3FC0E32FC627D5D459C65F8436EAAECDDB5440B29FF |
| SSDEEP: | 98304:PirUeUkFkHKzsCEx41M9fg1rlFsb4KAUoVF+f6eY/b/WlmPBUFihKRkEeSD2mTRO:dXkeG8b/s7QV |
| .exe | | | Win32 EXE PECompact compressed (generic) (47.3) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (35.5) |
| .dll | | | Win32 Dynamic Link Library (generic) (7.4) |
| .exe | | | Win32 Executable (generic) (5.1) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2013:06:28 14:45:44+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 36352 |
| InitializedDataSize: | 5585920 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x15eb |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 524 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 748 | "C:\Users\admin\Desktop\NoClippingBro_[unknowncheats.me]_.exe" | C:\Users\admin\Desktop\NoClippingBro_[unknowncheats.me]_.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 1476 | "C:\Program Files\FileZilla FTP Client\filezilla.exe" | C:\Program Files\FileZilla FTP Client\filezilla.exe | — | explorer.exe | |||||||||||
User: admin Company: FileZilla Project Integrity Level: MEDIUM Description: FileZilla FTP Client Version: 3, 65, 0, 0 Modules
| |||||||||||||||
| 1916 | "C:\Program Files\FileZilla FTP Client\fzsftp.exe" -v | C:\Program Files\FileZilla FTP Client\fzsftp.exe | filezilla.exe | ||||||||||||
User: admin Company: FileZilla Project Integrity Level: MEDIUM Description: SFTP module for FileZilla based on PuTTY's psftp component Version: Unidentified build Modules
| |||||||||||||||
| 2296 | "C:\Users\admin\AppData\Local\Temp\cetrainers\CETCC05.tmp\extracted\xmplayer.exe" CEAFCA1A660_30A4_40BE_AF24D4FF39135AAE | C:\Users\admin\AppData\Local\Temp\cetrainers\CETCC05.tmp\extracted\xmplayer.exe | — | NoClippingBro_[unknowncheats.me]_.exe | |||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 2920 | "C:\Program Files\Windows Sidebar\sidebar.exe" /showGadgets | C:\Program Files\Windows Sidebar\sidebar.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Desktop Gadgets Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3060 | C:\Users\admin\AppData\Local\Temp\cetrainers\CETCC05.tmp\extracted\NoClippingBro_[unknowncheats.me]_.exe "C:\Users\admin\AppData\Local\Temp\cetrainers\CETCC05.tmp\extracted\CET_TRAINER.CETRAINER" "-ORIGIN:C:\Users\admin\Desktop\" | C:\Users\admin\AppData\Local\Temp\cetrainers\CETCC05.tmp\extracted\NoClippingBro_[unknowncheats.me]_.exe | NoClippingBro_[unknowncheats.me]_.exe | ||||||||||||
User: admin Company: Cheat Engine Integrity Level: HIGH Description: Cheat Engine Version: 6.4.0.4106 Modules
| |||||||||||||||
| 3256 | "C:\Users\admin\Desktop\NoClippingBro_[unknowncheats.me]_.exe" | C:\Users\admin\Desktop\NoClippingBro_[unknowncheats.me]_.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3592 | "C:\Users\admin\AppData\Local\Temp\cetrainers\CETCC05.tmp\NoClippingBro_[unknowncheats.me]_.exe" -ORIGIN:"C:\Users\admin\Desktop\" | C:\Users\admin\AppData\Local\Temp\cetrainers\CETCC05.tmp\NoClippingBro_[unknowncheats.me]_.exe | NoClippingBro_[unknowncheats.me]_.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| (PID) Process: | (3060) NoClippingBro_[unknowncheats.me]_.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3060) NoClippingBro_[unknowncheats.me]_.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3060) NoClippingBro_[unknowncheats.me]_.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3060) NoClippingBro_[unknowncheats.me]_.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3060) NoClippingBro_[unknowncheats.me]_.exe | Key: | HKEY_CURRENT_USER\Software\Cheat Engine\Window Positions |
| Operation: | write | Name: | AdvancedOptions Position |
Value: 7E010000FF0100007402000029010000 | |||
| (PID) Process: | (3060) NoClippingBro_[unknowncheats.me]_.exe | Key: | HKEY_CURRENT_USER\Software\Cheat Engine\Window Positions |
| Operation: | write | Name: | frmAutoInject Position |
Value: 8701000000050000AF0100004B010000 | |||
| (PID) Process: | (2920) sidebar.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Sidebar\Settings |
| Operation: | write | Name: | ShowGadgets |
Value: 1 | |||
| (PID) Process: | (2920) sidebar.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | Sidebar |
Value: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun | |||
| (PID) Process: | (2920) sidebar.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2920) sidebar.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 748 | NoClippingBro_[unknowncheats.me]_.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETCC05.tmp\CET_Archive.dat | — | |
MD5:— | SHA256:— | |||
| 2920 | sidebar.exe | C:\Users\admin\AppData\Local\Microsoft\Windows Sidebar\Settings.ini | text | |
MD5:30D295030F52A72ECDA3994602164E4C | SHA256:E441993B15AF83500BE37304EADBE48CBC127CAB7D8FB531F770753FA56C4902 | |||
| 3592 | NoClippingBro_[unknowncheats.me]_.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETCC05.tmp\extracted\CET_TRAINER.CETRAINER | binary | |
MD5:11AB537E0F59EB5B06A8CA42259FDAEF | SHA256:D9A81673A749B2C27B1665B9B1513F517235122CDC46E4AEA31FA39BA654352F | |||
| 3592 | NoClippingBro_[unknowncheats.me]_.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETCC05.tmp\extracted\lua5.1-32.dll | executable | |
MD5:2730FF589AE86EF10D94952769F9404F | SHA256:FAF0850051BA175347E40481DA9E2CC3A122A09D428925042932BE555DB06E6B | |||
| 3592 | NoClippingBro_[unknowncheats.me]_.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETCC05.tmp\extracted\defines.lua | text | |
MD5:D8F9B4A10A48EBD8936255F6215C8A43 | SHA256:D4347332B232622283E7DD3781F64966BD1097D06CCA7052B467CF99E62898F2 | |||
| 748 | NoClippingBro_[unknowncheats.me]_.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETCC05.tmp\NoClippingBro_[unknowncheats.me]_.exe | executable | |
MD5:808DE473370EF6B5D98AB752F245A3CA | SHA256:65CBED2E8DB313B8966638E40EB27F94156C294EB060B28A02C130D146518C39 | |||
| 1476 | filezilla.exe | C:\Users\admin\AppData\Roaming\FileZilla\layout.xml | xml | |
MD5:2C67357412FE5428D2EB67E2178925FA | SHA256:6E8BEE236C7BB6E2CD249AF7449B0F08AFCEBEBE4140CF818750E4489D570B69 | |||
| 1476 | filezilla.exe | C:\Users\admin\AppData\Roaming\FileZilla\layout.xml~ | xml | |
MD5:2C67357412FE5428D2EB67E2178925FA | SHA256:6E8BEE236C7BB6E2CD249AF7449B0F08AFCEBEBE4140CF818750E4489D570B69 | |||
| 2920 | sidebar.exe | C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\8f96978fc46d9f00d8780351026924d7_90059c37-1320-41a4-b58d-2b75a9850d2f | binary | |
MD5:DB733E033C397FEC5917611957620271 | SHA256:1F3FFADD3B80C7F95BE06E245410768E8302A24E573868DA3C6FD91230025BDC | |||
| 1476 | filezilla.exe | C:\Users\admin\AppData\Local\FileZilla\default_localtreeview20x20.png | image | |
MD5:6F1521A05994C29F5DB6711A2A56E25A | SHA256:C0B2F0998B11BFBC0D5EE0FBCA3320CC79A5AF5DF16800F7EDAAB99C7AF0949F | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2564 | svchost.exe | 239.255.255.250:3702 | — | — | — | whitelisted |
1060 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
1916 | fzsftp.exe | 144.76.58.217:2022 | gold.magmanode.com | Hetzner Online GmbH | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
gold.magmanode.com |
| unknown |
Process | Message |
|---|---|
NoClippingBro_[unknowncheats.me]_.exe | Offset of LBR_Count=760 |
NoClippingBro_[unknowncheats.me]_.exe | sizeof fxstate = 512 |
NoClippingBro_[unknowncheats.me]_.exe | symbolloader thread finished |
NoClippingBro_[unknowncheats.me]_.exe | Symbolhandler: sync: Calling finishedloadingsymbols |
NoClippingBro_[unknowncheats.me]_.exe | finishedLoadingSymbols called |
NoClippingBro_[unknowncheats.me]_.exe | exit finishedLoadingSymbols() |
NoClippingBro_[unknowncheats.me]_.exe | after finishedloadingsymbols |
NoClippingBro_[unknowncheats.me]_.exe | Symbol loader thread has finished without errors |