File name:

Gmod Glua Loader + Money Exploit.zip

Full analysis: https://app.any.run/tasks/b4299ad6-08ef-4627-83ba-1f2c05d4c11b
Verdict: Malicious activity
Analysis date: February 11, 2021, 19:15:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

77055B7D27BADE3F3B3ADE675A22DA70

SHA1:

2BFB903B287CA440AAD6F09E99857438253F6EF7

SHA256:

49E2BE34C44453A1A5DDD29EAE40EF8C5D7231EF9D43149CE8AA0655E67E2E11

SSDEEP:

98304:bpxnN9zMQ/Z0zgJ+uqQyED/e5uw2AhIAHey:bpxnNywZ0eYZEDW5uwzmYey

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • JJGMOD.exe (PID: 2480)
      • WerFault.exe (PID: 1704)
      • JJGMOD.exe (PID: 3904)
      • WerFault.exe (PID: 1904)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • JJGMOD.exe (PID: 2480)
    • Application launched itself

      • Extreme Injector v3.exe (PID: 3620)
    • Changes default file association

      • JJGMOD.exe (PID: 2480)
      • JJGMOD.exe (PID: 3904)
    • Reads Environment values

      • Extreme Injector v3.exe (PID: 3800)
  • INFO

    • Manual execution by user

      • Extreme Injector v3.exe (PID: 3620)
      • JJGMOD_Updater.exe (PID: 544)
      • JJGMOD.exe (PID: 3904)
      • JJGMOD.exe (PID: 2480)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:07:29 16:59:12
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Gmod Hacks Glua Loader & Money Exploit/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
8
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe no specs jjgmod.exe jjgmod_updater.exe werfault.exe no specs extreme injector v3.exe no specs extreme injector v3.exe jjgmod.exe werfault.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
544"C:\Users\admin\Desktop\Gmod Hacks Glua Loader & Money Exploit\JJGmod\JJGMOD_Updater.exe" C:\Users\admin\Desktop\Gmod Hacks Glua Loader & Money Exploit\JJGmod\JJGMOD_Updater.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Stalin Updater
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\gmod hacks glua loader & money exploit\jjgmod\jjgmod_updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1704C:\Windows\system32\WerFault.exe -u -p 2480 -s 1452C:\Windows\system32\WerFault.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\werfault.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1904C:\Windows\system32\WerFault.exe -u -p 3904 -s 1452C:\Windows\system32\WerFault.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\werfault.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2272"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Gmod Glua Loader + Money Exploit.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2480"C:\Users\admin\Desktop\Gmod Hacks Glua Loader & Money Exploit\JJGmod\JJGMOD.exe" C:\Users\admin\Desktop\Gmod Hacks Glua Loader & Money Exploit\JJGmod\JJGMOD.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WindowsFormsApp1
Exit code:
3
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\gmod hacks glua loader & money exploit\jjgmod\jjgmod.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3620"C:\Users\admin\Desktop\Gmod Hacks Glua Loader & Money Exploit\Injector\Extreme Injector v3.exe" C:\Users\admin\Desktop\Gmod Hacks Glua Loader & Money Exploit\Injector\Extreme Injector v3.exeexplorer.exe
User:
admin
Company:
master131
Integrity Level:
MEDIUM
Description:
Extreme Injector
Exit code:
0
Version:
3.7.2.0
Modules
Images
c:\users\admin\desktop\gmod hacks glua loader & money exploit\injector\extreme injector v3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3800"C:\Users\admin\Desktop\Gmod Hacks Glua Loader & Money Exploit\Injector\Extreme Injector v3.exe" C:\Users\admin\Desktop\Gmod Hacks Glua Loader & Money Exploit\Injector\Extreme Injector v3.exe
Extreme Injector v3.exe
User:
admin
Company:
master131
Integrity Level:
HIGH
Description:
Extreme Injector
Exit code:
0
Version:
3.7.2.0
Modules
Images
c:\users\admin\desktop\gmod hacks glua loader & money exploit\injector\extreme injector v3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3904"C:\Users\admin\Desktop\Gmod Hacks Glua Loader & Money Exploit\JJGmod\JJGMOD.exe" C:\Users\admin\Desktop\Gmod Hacks Glua Loader & Money Exploit\JJGmod\JJGMOD.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WindowsFormsApp1
Exit code:
3
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\gmod hacks glua loader & money exploit\jjgmod\jjgmod.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
738
Read events
652
Write events
86
Delete events
0

Modification events

(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2272) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Gmod Glua Loader + Money Exploit.zip
(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2272) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2480) JJGMOD.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\JJGMOD_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2480) JJGMOD.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\JJGMOD_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
1
Suspicious files
3
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2272.30709\Gmod Hacks Glua Loader & Money Exploit\Glua Loader + Lua\Gmod Glua Loader.dll
MD5:
SHA256:
2272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2272.30709\Gmod Hacks Glua Loader & Money Exploit\Glua Loader + Lua\IdiotBox.lua
MD5:
SHA256:
2272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2272.30709\Gmod Hacks Glua Loader & Money Exploit\Injector\Extreme Injector v3.exe
MD5:
SHA256:
2272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2272.30709\Gmod Hacks Glua Loader & Money Exploit\Injector\settings.xml
MD5:
SHA256:
2272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2272.30709\Gmod Hacks Glua Loader & Money Exploit\JJGmod\AutoHotkey.Interop.dll
MD5:
SHA256:
2272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2272.30709\Gmod Hacks Glua Loader & Money Exploit\JJGmod\discord-rpc-w32.dll
MD5:
SHA256:
2272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2272.30709\Gmod Hacks Glua Loader & Money Exploit\JJGmod\JJGMOD.exe
MD5:
SHA256:
2272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2272.30709\Gmod Hacks Glua Loader & Money Exploit\JJGmod\JJGMOD_Updater.exe
MD5:
SHA256:
2272WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2272.30709\Gmod Hacks Glua Loader & Money Exploit\JJGmod\Test_Dev_money.ahk
MD5:
SHA256:
1704WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\JJGMOD.exe.2480.dmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
6
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2480
JJGMOD.exe
104.23.98.190:443
pastebin.com
Cloudflare Inc
US
malicious
544
JJGMOD_Updater.exe
140.82.121.3:443
github.com
US
suspicious
544
JJGMOD_Updater.exe
185.199.108.133:443
raw.githubusercontent.com
GitHub, Inc.
NL
malicious
2480
JJGMOD.exe
162.159.130.233:443
cdn.discordapp.com
Cloudflare Inc
shared
185.199.110.133:443
raw.githubusercontent.com
GitHub, Inc.
NL
malicious
3904
JJGMOD.exe
162.159.130.233:443
cdn.discordapp.com
Cloudflare Inc
shared
3904
JJGMOD.exe
104.23.99.190:443
pastebin.com
Cloudflare Inc
US
malicious

DNS requests

Domain
IP
Reputation
pastebin.com
  • 104.23.98.190
  • 104.23.99.190
malicious
github.com
  • 140.82.121.3
malicious
raw.githubusercontent.com
  • 185.199.108.133
  • 185.199.111.133
  • 185.199.109.133
  • 185.199.110.133
shared
cdn.discordapp.com
  • 162.159.130.233
  • 162.159.133.233
  • 162.159.135.233
  • 162.159.134.233
  • 162.159.129.233
shared

Threats

No threats detected
No debug info