| File name: | MIDDLE.EARTH.SOM.V1.0.1951.27.PLUS16TRN.MAXTRE.ZIP |
| Full analysis: | https://app.any.run/tasks/6a032be7-2f54-4465-9f80-8ebded1f1fcd |
| Verdict: | Malicious activity |
| Analysis date: | December 15, 2024, 13:17:33 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract, compression method=store |
| MD5: | 888815068CDBF9753AF0DB573984A733 |
| SHA1: | 58FCEEBAA508410DC2A17A7EB9EE4B985B370734 |
| SHA256: | 4A494A848B646F43368A85414AEAF59E330C7C93D1EC8ECE559371229D784AE9 |
| SSDEEP: | 98304:Kq5lmAS1FjgExgDH4P43aIVh+kcQA++qIVzTiQMm4qUtu3jzl3FNdku8tPaq03Nq:6mWViQg27v03HTc2 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | 0x0800 |
| ZipCompression: | None |
| ZipModifyDate: | 2024:12:15 05:16:54 |
| ZipCRC: | 0x1532d15f |
| ZipCompressedSize: | 8 |
| ZipUncompressedSize: | 8 |
| ZipFileName: | MIDDLE.EARTH.SOM.V1.0.1951.27.PLUS16TRN.MAXTRE.ZIP.txt |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2940 | "C:\Users\admin\Desktop\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE" | C:\Users\admin\Desktop\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3060 | "C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE" -ORIGIN:"C:\Users\admin\Desktop\" | C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 3544 | "C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\xmplayer.exe" CEAE187DD8F_A893_4DF3_96AD9706BF341093 | C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\xmplayer.exe | — | Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | |||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 6452 | "C:\Users\admin\Desktop\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE" | C:\Users\admin\Desktop\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 6692 | "C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE" "C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\CET_TRAINER.CETRAINER" "-ORIGIN:C:\Users\admin\Desktop\" | C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | ||||||||||||
User: admin Company: Cheat Engine Integrity Level: HIGH Description: Cheat Engine Version: 6.4.0.4107 Modules
| |||||||||||||||
| 6696 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\MIDDLE.EARTH.SOM.V1.0.1951.27.PLUS16TRN.MAXTRE.ZIP.zip | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 7008 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa6696.47360\MIDDLE.EARTH.SOM.V1.0.1951.27.PLUS16TRN.MAXTRE.ZIP | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (6696) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (6696) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (6696) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (6696) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\MIDDLE.EARTH.SOM.V1.0.1951.27.PLUS16TRN.MAXTRE.ZIP.zip | |||
| (PID) Process: | (6696) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6696) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6696) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6696) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (7008) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (7008) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6452 | Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\CET_Archive.dat | — | |
MD5:— | SHA256:— | |||
| 3060 | Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\CET_TRAINER.CETRAINER | — | |
MD5:— | SHA256:— | |||
| 7008 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa7008.47858\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | executable | |
MD5:8144BD0598A3F245B6FE09C9969C8250 | SHA256:F8710ADD7F4A4B06995678E7D2A2670BAB124CEB600A9D3101108DF9E3C6D239 | |||
| 6696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa6696.47360\MIDDLE.EARTH.SOM.V1.0.1951.27.PLUS16TRN.MAXTRE.ZIP | compressed | |
MD5:B85793D25FF9EDF781C01350B1ED9381 | SHA256:7A68AEBD4FACF23BD00754630028700909583BB330F8391C9D67A5499F916DD9 | |||
| 3060 | Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | executable | |
MD5:1748F63933E6202E82691341CAFB986B | SHA256:65730EDAB718F812ECC9C0EC41032DFFC961A163BF9CE0BA6CA61E99DA83C31D | |||
| 3060 | Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\speedhack-x86_64.dll | executable | |
MD5:0BAD639F7549E3AEC3C7043BA10037A4 | SHA256:5EC85A0F12E4AE2A7007BA5252F743C5476B6BA0C5A0870484E6C8407F428E04 | |||
| 3060 | Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\xmplayer.exe | executable | |
MD5:B1761FCB265515ADB02D3675C6E0D135 | SHA256:D66240856AD4A49CDCBAD9DCDD03422E46F269F245B5A74CB750875535A6DC5A | |||
| 6452 | Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | executable | |
MD5:808DE473370EF6B5D98AB752F245A3CA | SHA256:65CBED2E8DB313B8966638E40EB27F94156C294EB060B28A02C130D146518C39 | |||
| 3060 | Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\lua5.1-64.dll | executable | |
MD5:32718A4EC812B81FD70D4246A94C8731 | SHA256:1CB952CA2BCD5646164AE0D1415DE6B6BD1841DE4609481716FCC67BBB6D872E | |||
| 3060 | Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | C:\Users\admin\AppData\Local\Temp\cetrainers\CET8DDC.tmp\extracted\defines.lua | text | |
MD5:D8F9B4A10A48EBD8936255F6215C8A43 | SHA256:D4347332B232622283E7DD3781F64966BD1097D06CCA7052B467CF99E62898F2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.48.23.156:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6164 | SIHClient.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6576 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
6164 | SIHClient.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 23.48.23.156:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.52.120.96:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 2.16.110.123:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1176 | svchost.exe | 20.190.159.2:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1176 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | sizeof fxstate = 512 |
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | Offset of LBR_Count=760 |
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | Symbolhandler: sync: Calling finishedloadingsymbols |
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | symbolloader thread finished |
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | after finishedloadingsymbols |
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | exit finishedLoadingSymbols() |
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | Symbol loader thread has finished without errors |
Trainer+16 Middle-earth Shadow Of Mordor Ver 1.0.1951.27 (Update 8)by{MaxTre}.EXE | finishedLoadingSymbols called |