| URL: | https://cheat-engine.soft32.es/descarga-gratuita/?nc |
| Full analysis: | https://app.any.run/tasks/f1ae5454-1d5c-49d3-b559-7134886b8ed3 |
| Verdict: | Malicious activity |
| Analysis date: | March 11, 2024, 12:19:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | B4E8DAB242A2B50982F8701FACB10F0C |
| SHA1: | 125BC50E51DE876EA70783EB9F52BA1B4DEE4886 |
| SHA256: | 43A8B5A78C04E51F35F7B0ABF576E7B42FCB87F98C5675EF2D1CB35C43C17B21 |
| SSDEEP: | 3:N8QoNMLApN1xTXfXdQ8Gn:2QoNM05c8G |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 292 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1416 --field-trial-handle=1280,i,14836155765645281725,15945124212229273986,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 664 | "C:\Program Files\Cheat Engine 6.8.1\cheatengine-i386.exe" | C:\Program Files\Cheat Engine 6.8.1\cheatengine-i386.exe | Cheat Engine.exe | ||||||||||||
User: admin Company: Cheat Engine Integrity Level: HIGH Description: Cheat Engine Exit code: 0 Version: 6.8.1.5602 Modules
| |||||||||||||||
| 764 | "icacls" "C:\Program Files\Cheat Engine 6.8.1" /grant *S-1-15-2-1:(OI)(CI)(RX) /T | C:\Windows\System32\icacls.exe | — | CheatEngine681.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 1332 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 952 | "C:\Program Files\Cheat Engine 6.8.1\Cheat Engine.exe" | C:\Program Files\Cheat Engine 6.8.1\Cheat Engine.exe | — | CheatEngine681.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 6.3.0.0 Modules
| |||||||||||||||
| 984 | "C:\Program Files\Cheat Engine 6.8.1\ceregreset.exe" -silent -dontdeletecustomtypes -dontdeleteversioncheck | C:\Program Files\Cheat Engine 6.8.1\ceregreset.exe | — | CheatEngine681.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 992 | "C:\Program Files\Cheat Engine 6.8.1\windowsrepair.exe" /s | C:\Program Files\Cheat Engine 6.8.1\windowsrepair.exe | — | CheatEngine681.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1432 | "C:\Program Files\Internet Explorer\iexplore.exe" "https://cheat-engine.soft32.es/descarga-gratuita/?nc" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2060 | "C:\Users\admin\AppData\Local\Temp\is-EB5C7.tmp\CheatEngine681.tmp" /SL5="$150190,14068795,56832,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\CheatEngine681.exe" /SPAWNWND=$1A0164 /NOTIFYWND=$A021E | C:\Users\admin\AppData\Local\Temp\is-EB5C7.tmp\CheatEngine681.tmp | CheatEngine681.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 2072 | "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\CheatEngine681.exe" | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\CheatEngine681.exe | iexplore.exe | ||||||||||||
User: admin Company: Cheat Engine Integrity Level: MEDIUM Description: Cheat Engine 6.8.1 Setup Exit code: 0 Version: 6.8.1.2 Modules
| |||||||||||||||
| 2156 | "C:\Users\admin\AppData\Local\Temp\is-I87L0.tmp\CheatEngine681.tmp" /SL5="$A021E,14068795,56832,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\CheatEngine681.exe" | C:\Users\admin\AppData\Local\Temp\is-I87L0.tmp\CheatEngine681.tmp | — | CheatEngine681.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1432) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (1432) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: | |||
| (PID) Process: | (1432) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31093678 | |||
| (PID) Process: | (1432) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: | |||
| (PID) Process: | (1432) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 31093678 | |||
| (PID) Process: | (1432) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (1432) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1432) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1432) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (1432) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3892 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894 | der | |
MD5:E683DE4B64CDB28EBA42AE704968F1E5 | SHA256:1A1FE0EDB5E43698A6A4BFBBCCF1AD778BBBD3C77D3B1748504DBF6DE8195682 | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62 | binary | |
MD5:1050A1409D767E71187DDD255C2B07A9 | SHA256:DD8F577698995E6B454D3403196A0046112C64B37180AE345A9E7533F592C106 | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517 | binary | |
MD5:CBDB82F538C5D7CA849F55C5ABFBCF41 | SHA256:791127B4509EA89BE6F775491168FC4C23A8455651D85C07F6583C6FD409BC37 | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894 | binary | |
MD5:D46387A37C3F21A61A1B467B97E1D77B | SHA256:58B8179411C32BA2FD688A2EFC11B23E86DD0C83FC63233556F06E0F3320127E | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517 | binary | |
MD5:447723AA115FD0C4C39B43DB122BC490 | SHA256:A47A0480DD2FCBE005B6C86C47C4166C48ED782CE12384C9F5A355D173EF30D0 | |||
| 1432 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118A | binary | |
MD5:5D8F7B1C393FF00DE21F682F78942993 | SHA256:FC8EF68E41508D55F9272B96BC7D075B05A35800A8781E1AF1D6D82171B103C1 | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\375RQGMT.txt | text | |
MD5:9BC63E23622A583F5BFB5140C21F20C6 | SHA256:1F9918D2DDE62DCE6D11B34FA8F57209E5A4940B7AE587B13F2ACEEE22CD2C0B | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\descarga-gratuita[1].htm | html | |
MD5:C9A88B6E7052C1BAB49E3A19D62F11A5 | SHA256:16C66199CE499024FAA186B348ED7FCBC24C17F024E080BB6A171C413A3155F7 | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8 | der | |
MD5:370FD030CD98AA54C29D99ABAFEFA213 | SHA256:91373A7988FD6D3AEA0E8B3712147D96414A0F657D45514B1DEC3CF8B88EE61B | |||
| 1432 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118A | binary | |
MD5:DC0D3EF27EC5AA74E5F130716247ACCB | SHA256:DF6134EF204A80CDDDC78B50E5C10FA726ADF6EE26A51F95B330592FC797C4FF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3892 | iexplore.exe | GET | 304 | 95.100.100.50:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?545e1839169dd0e6 | unknown | — | — | unknown |
3892 | iexplore.exe | GET | 304 | 95.100.100.50:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a08f35fbea17b647 | unknown | — | — | unknown |
3892 | iexplore.exe | GET | 200 | 108.138.34.92:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | unknown | binary | 2.02 Kb | unknown |
3892 | iexplore.exe | GET | 200 | 18.66.190.71:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | unknown | binary | 1.49 Kb | unknown |
3892 | iexplore.exe | GET | 200 | 18.66.190.71:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D | unknown | binary | 1.37 Kb | unknown |
1432 | iexplore.exe | GET | 304 | 95.100.100.50:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?70b4a85d87201c80 | unknown | — | — | unknown |
1432 | iexplore.exe | GET | 304 | 95.100.100.50:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?18014fff35250a83 | unknown | — | — | unknown |
1432 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D | unknown | binary | 314 b | unknown |
3892 | iexplore.exe | GET | 200 | 18.66.190.71:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D | unknown | binary | 1.37 Kb | unknown |
3892 | iexplore.exe | GET | 200 | 142.250.185.195:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | binary | 1.41 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3892 | iexplore.exe | 18.173.187.44:443 | cheat-engine.soft32.es | — | US | unknown |
3892 | iexplore.exe | 95.100.100.50:80 | ctldl.windowsupdate.com | Akamai International B.V. | PT | unknown |
3892 | iexplore.exe | 108.138.34.92:80 | o.ss2.us | AMAZON-02 | US | unknown |
1432 | iexplore.exe | 128.177.173.175:443 | www.bing.com | ZAYO-6461 | US | unknown |
3892 | iexplore.exe | 18.66.190.71:80 | ocsp.rootg2.amazontrust.com | AMAZON-02 | US | unknown |
1432 | iexplore.exe | 95.100.100.50:80 | ctldl.windowsupdate.com | Akamai International B.V. | PT | unknown |
1432 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3892 | iexplore.exe | 18.66.188.227:443 | d3gx3uz4yj2hnq.cloudfront.net | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
cheat-engine.soft32.es |
| unknown |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
ocsp.digicert.com |
| whitelisted |
d3gx3uz4yj2hnq.cloudfront.net |
| whitelisted |
pagead2.googlesyndication.com |
| whitelisted |
Process | Message |
|---|---|
Kernelmoduleunloader.exe | Kernelmodule unloader |
Kernelmoduleunloader.exe | Setup. So do not show messages |
Kernelmoduleunloader.exe | attempting to unload |
Kernelmoduleunloader.exe | SCManager opened |
Kernelmoduleunloader.exe | count=0 |
Kernelmoduleunloader.exe | setup=true |
cheatengine-i386.exe | Offset of LBR_Count=760 |
cheatengine-i386.exe | sizeof fxstate = 512 |
cheatengine-i386.exe | TSymbolListHandler.create 1 |
cheatengine-i386.exe | TSymbolListHandler.create 2 |