File name:

Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe

Full analysis: https://app.any.run/tasks/213a61cd-7d04-4aee-b6d3-388c1738eefc
Verdict: Malicious activity
Analysis date: January 28, 2025, 19:47:24
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
python
pyinstaller
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 6 sections
MD5:

54F7D65C98A0245C53AF2D8918B2E2E7

SHA1:

D96C256DD53010E75366F7B7A4E836EFD6E65D95

SHA256:

4E5316A747104C1B94968A8C292A81B7458AB36BB370FF1ABDC6B111E65AAACC

SSDEEP:

98304:acdlNF5mWFk3Gm4jSm6QKUMUwgvGnRig5Tg2F8NuvEhiL7UJDZ2pli9TZIATPSkW:DmTyYw6Nz1LxgL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops python dynamic module

      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6692)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 1296)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 4840)
    • The process drops C-runtime libraries

      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6692)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 1296)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 4840)
    • Application launched itself

      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6788)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6692)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 1296)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6872)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 5576)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 4840)
    • Process drops legitimate windows executable

      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6692)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 1296)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 4840)
    • Executable content was dropped or overwritten

      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6692)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 1296)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 4840)
    • Loads Python modules

      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6788)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6816)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6808)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6832)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6824)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6872)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 5892)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6256)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6244)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 5004)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6172)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6180)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6164)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6188)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 5576)
    • Reads security settings of Internet Explorer

      • PCHealthCheck.exe (PID: 6424)
    • Reads Internet Explorer settings

      • PCHealthCheck.exe (PID: 6424)
    • Reads the date of Windows installation

      • PCHealthCheck.exe (PID: 6424)
  • INFO

    • Reads the computer name

      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6692)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 1296)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 4840)
    • Checks supported languages

      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6692)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6788)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6816)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6808)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6832)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6824)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 1296)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6872)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6244)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 5892)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 4840)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6256)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 5004)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6164)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6188)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6180)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 5576)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6172)
      • PCHealthCheck.exe (PID: 6424)
    • Create files in a temporary directory

      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6692)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6816)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 1296)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 5004)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6256)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 4840)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6172)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6180)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6164)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6188)
    • The sample compiled with english language support

      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6692)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 1296)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 4840)
    • Manual execution by a user

      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 1296)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 4840)
      • PCHealthCheck.exe (PID: 6424)
      • Taskmgr.exe (PID: 6544)
      • Taskmgr.exe (PID: 6552)
    • Reads security settings of Internet Explorer

      • Taskmgr.exe (PID: 6552)
    • Reads the software policy settings

      • PCHealthCheck.exe (PID: 6424)
    • Checks proxy server information

      • PCHealthCheck.exe (PID: 6424)
    • PyInstaller has been detected (YARA)

      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 4840)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 5576)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6172)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6164)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6180)
      • Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe (PID: 6188)
    • Reads Environment values

      • PCHealthCheck.exe (PID: 6424)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (57.6)
.exe | Win64 Executable (generic) (36.9)
.exe | Generic Win/DOS Executable (2.6)
.exe | DOS Executable Generic (2.6)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:01:28 19:42:50+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.41
CodeSize: 176640
InitializedDataSize: 152576
UninitializedDataSize: -
EntryPoint: 0xc380
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
172
Monitored processes
24
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe conhost.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe conhost.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe conhost.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe no specs taskmgr.exe no specs taskmgr.exe pchealthcheck.exe

Process information

PID
CMD
Path
Indicators
Parent process
1296"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe" C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2424\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSteam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4840"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe" C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5004"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe" "--multiprocessing-fork" "parent_pid=6872" "pipe_handle=576"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeSteam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5576"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe" C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeSteam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5892"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe" "--multiprocessing-fork" "parent_pid=6872" "pipe_handle=540"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeSteam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6164"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe" "--multiprocessing-fork" "parent_pid=5576" "pipe_handle=376"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeSteam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6172"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe" "--multiprocessing-fork" "parent_pid=5576" "pipe_handle=368"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeSteam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6180"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe" "--multiprocessing-fork" "parent_pid=5576" "pipe_handle=480"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeSteam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6188"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe" "--multiprocessing-fork" "parent_pid=5576" "pipe_handle=516"C:\Users\admin\Desktop\Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeSteam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\steam emulator + anti-denuvo & anti-enigma & anti-drm injector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
5 630
Read events
5 622
Write events
7
Delete events
1

Modification events

(PID) Process:(6552) Taskmgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager
Operation:delete valueName:Preferences
Value:
(PID) Process:(6552) Taskmgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager
Operation:writeName:Preferences
Value:
0D00000060000000600000006800000068000000E3010000DC010000000001000000008000000080D8010080DF010080000100016B00000034000000130300008C020000E80300000000000000000000000000000F000000010000000000000058AA6C15F77F00000000000000000000000000002E0100001E0000008990000000000000FF00000001015002000000000D0000000000000098AA6C15F77F00000000000000000000FFFFFFFF960000001E0000008B900000010000000000000000101001000000000300000000000000B0AA6C15F77F00000000000000000000FFFFFFFF780000001E0000008C900000020000000000000001021200000000000400000000000000C8AA6C15F77F00000000000000000000FFFFFFFF960000001E0000008D900000030000000000000000011001000000000200000000000000E8AA6C15F77F00000000000000000000FFFFFFFF320000001E0000008A90000004000000000000000008200100000000050000000000000000AB6C15F77F00000000000000000000FFFFFFFFC80000001E0000008E90000005000000000000000001100100000000060000000000000028AB6C15F77F00000000000000000000FFFFFFFF040100001E0000008F90000006000000000000000001100100000000070000000000000050AB6C15F77F00000000000000000000FFFFFFFF49000000490000009090000007000000000000000004250000000000080000000000000080AA6C15F77F00000000000000000000FFFFFFFF49000000490000009190000008000000000000000004250000000000090000000000000070AB6C15F77F00000000000000000000FFFFFFFF490000004900000092900000090000000000000000042508000000000A0000000000000088AB6C15F77F00000000000000000000FFFFFFFF4900000049000000939000000A0000000000000000042508000000000B00000000000000A8AB6C15F77F00000000000000000000FFFFFFFF490000004900000039A000000B0000000000000000042509000000001C00000000000000C8AB6C15F77F00000000000000000000FFFFFFFFC8000000490000003AA000000C0000000000000000011009000000001D00000000000000F0AB6C15F77F00000000000000000000FFFFFFFF64000000490000004CA000000D0000000000000000021508000000001E0000000000000010AC6C15F77F00000000000000000000FFFFFFFF64000000490000004DA000000E000000000000000002150800000000030000000A000000010000000000000058AA6C15F77F0000000000000000000000000000D70000001E0000008990000000000000FF00000001015002000000000400000000000000C8AA6C15F77F0000000000000000000001000000960000001E0000008D900000010000000000000001011000000000000300000000000000B0AA6C15F77F00000000000000000000FFFFFFFF640000001E0000008C900000020000000000000000021000000000000C0000000000000040AC6C15F77F0000000000000000000003000000640000001E00000094900000030000000000000001021000000000000D0000000000000068AC6C15F77F00000000000000000000FFFFFFFF640000001E00000095900000040000000000000000011001000000000E0000000000000090AC6C15F77F0000000000000000000005000000320000001E00000096900000050000000000000001042001000000000F00000000000000B8AC6C15F77F0000000000000000000006000000320000001E00000097900000060000000000000001042001000000001000000000000000D8AC6C15F77F0000000000000000000007000000460000001E00000098900000070000000000000001011001000000001100000000000000F8AC6C15F77F00000000000000000000FFFFFFFF640000001E0000009990000008000000000000000001100100000000060000000000000028AB6C15F77F0000000000000000000009000000040100001E0000008F9000000900000000000000010110010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000B000000010000000000000058AA6C15F77F0000000000000000000000000000D70000001E0000009E90000000000000FF0000000101500200000000120000000000000020AD6C15F77F00000000000000000000FFFFFFFF2D0000001E0000009B90000001000000000000000004200100000000140000000000000040AD6C15F77F00000000000000000000FFFFFFFF640000001E0000009D90000002000000000000000001100100000000130000000000000068AD6C15F77F00000000000000000000FFFFFFFF640000001E0000009C900000030000000000000000011001000000000300000000000000B0AA6C15F77F00000000000000000000FFFFFFFF640000001E0000008C90000004000000000000000102100000000000070000000000000050AB6C15F77F000000000000000000000500000049000000490000009090000005000000000000000104210000000000080000000000000080AA6C15F77F000000000000000000000600000049000000490000009190000006000000000000000104210000000000090000000000000070AB6C15F77F0000000000000000000007000000490000004900000092900000070000000000000001042108000000000A0000000000000088AB6C15F77F0000000000000000000008000000490000004900000093900000080000000000000001042108000000000B00000000000000A8AB6C15F77F0000000000000000000009000000490000004900000039A00000090000000000000001042109000000001C00000000000000C8AB6C15F77F000000000000000000000A00000064000000490000003AA000000A00000000000000000110090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000008000000010000000000000058AA6C15F77F0000000000000000000000000000C60000001E000000B090000000000000FF0000000101500200000000150000000000000088AD6C15F77F00000000000000000000FFFFFFFF6B0000001E000000B1900000010000000000000000042500000000001600000000000000B8AD6C15F77F00000000000000000000FFFFFFFF6B0000001E000000B2900000020000000000000000042500000000001800000000000000E0AD6C15F77F00000000000000000000FFFFFFFF6B0000001E000000B490000003000000000000000004250000000000170000000000000008AE6C15F77F00000000000000000000FFFFFFFF6B0000001E000000B390000004000000000000000004250000000000190000000000000040AE6C15F77F00000000000000000000FFFFFFFFA00000001E000000B5900000050000000000000000042001000000001A0000000000000070AE6C15F77F00000000000000000000FFFFFFFF7D0000001E000000B6900000060000000000000000042001000000001B00000000000000A0AE6C15F77F00000000000000000000FFFFFFFF7D0000001E000000B790000007000000000000000004200100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA00000000000000000000000000000000000000000000009D200000200000009100000064000000320000006400000050000000320000003200000028000000500000003C0000005000000050000000320000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C00000050000000500000009700000032000000780000003200000050000000500000005000000050000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA000000000000000000000000000000000000009D200000200000009100000064000000320000009700000050000000320000003200000028000000500000003C000000500000005000000032000000500000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C0000005000000064000000780000003200000078000000780000003200000050000000500000005000000050000000C8000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C0000002D0000002E0000002F00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000002000000030000000400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000000000000000000000000000000
(PID) Process:(6552) Taskmgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager
Operation:writeName:Preferences
Value:
0D00000060000000600000006800000068000000E3010000DC010000000001000000008000000080D8010080DF010080000100016B00000034000000130300008C020000E80300000000000000000000000000000F000000010000000000000058AA6C15F77F00000000000000000000000000002E0100001E0000008990000000000000FF00000001015002000000000D0000000000000098AA6C15F77F00000000000000000000FFFFFFFF960000001E0000008B900000010000000000000000101001000000000300000000000000B0AA6C15F77F00000000000000000000FFFFFFFF780000001E0000008C900000020000000000000001021200000000000400000000000000C8AA6C15F77F00000000000000000000FFFFFFFF960000001E0000008D900000030000000000000000011001000000000200000000000000E8AA6C15F77F00000000000000000000FFFFFFFF320000001E0000008A90000004000000000000000008200100000000050000000000000000AB6C15F77F00000000000000000000FFFFFFFFC80000001E0000008E90000005000000000000000001100100000000060000000000000028AB6C15F77F00000000000000000000FFFFFFFF040100001E0000008F90000006000000000000000001100100000000070000000000000050AB6C15F77F00000000000000000000FFFFFFFF49000000490000009090000007000000000000000004250000000000080000000000000080AA6C15F77F00000000000000000000FFFFFFFF49000000490000009190000008000000000000000004250000000000090000000000000070AB6C15F77F00000000000000000000FFFFFFFF490000004900000092900000090000000000000000042508000000000A0000000000000088AB6C15F77F00000000000000000000FFFFFFFF4900000049000000939000000A0000000000000000042508000000000B00000000000000A8AB6C15F77F00000000000000000000FFFFFFFF490000004900000039A000000B0000000000000000042509000000001C00000000000000C8AB6C15F77F00000000000000000000FFFFFFFFC8000000490000003AA000000C0000000000000000011009000000001D00000000000000F0AB6C15F77F00000000000000000000FFFFFFFF64000000490000004CA000000D0000000000000000021508000000001E0000000000000010AC6C15F77F00000000000000000000FFFFFFFF64000000490000004DA000000E000000000000000002150800000000030000000A000000010000000000000058AA6C15F77F0000000000000000000000000000D70000001E0000008990000000000000FF00000001015002000000000400000000000000C8AA6C15F77F0000000000000000000001000000960000001E0000008D900000010000000000000001011000000000000300000000000000B0AA6C15F77F00000000000000000000FFFFFFFF640000001E0000008C900000020000000000000000021000000000000C0000000000000040AC6C15F77F0000000000000000000003000000640000001E00000094900000030000000000000001021000000000000D0000000000000068AC6C15F77F00000000000000000000FFFFFFFF640000001E00000095900000040000000000000000011001000000000E0000000000000090AC6C15F77F0000000000000000000005000000320000001E00000096900000050000000000000001042001000000000F00000000000000B8AC6C15F77F0000000000000000000006000000320000001E00000097900000060000000000000001042001000000001000000000000000D8AC6C15F77F0000000000000000000007000000460000001E00000098900000070000000000000001011001000000001100000000000000F8AC6C15F77F00000000000000000000FFFFFFFF640000001E0000009990000008000000000000000001100100000000060000000000000028AB6C15F77F0000000000000000000009000000040100001E0000008F9000000900000000000000010110010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000B000000010000000000000058AA6C15F77F0000000000000000000000000000D70000001E0000009E90000000000000FF0000000101500200000000120000000000000020AD6C15F77F00000000000000000000FFFFFFFF2D0000001E0000009B90000001000000000000000004200100000000140000000000000040AD6C15F77F00000000000000000000FFFFFFFF640000001E0000009D90000002000000000000000001100100000000130000000000000068AD6C15F77F00000000000000000000FFFFFFFF640000001E0000009C900000030000000000000000011001000000000300000000000000B0AA6C15F77F00000000000000000000FFFFFFFF640000001E0000008C90000004000000000000000102100000000000070000000000000050AB6C15F77F000000000000000000000500000049000000490000009090000005000000000000000104210000000000080000000000000080AA6C15F77F000000000000000000000600000049000000490000009190000006000000000000000104210000000000090000000000000070AB6C15F77F0000000000000000000007000000490000004900000092900000070000000000000001042108000000000A0000000000000088AB6C15F77F0000000000000000000008000000490000004900000093900000080000000000000001042108000000000B00000000000000A8AB6C15F77F0000000000000000000009000000490000004900000039A00000090000000000000001042109000000001C00000000000000C8AB6C15F77F000000000000000000000A00000064000000490000003AA000000A00000000000000000110090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000008000000010000000000000058AA6C15F77F0000000000000000000000000000C60000001E000000B090000000000000FF0000000101500200000000150000000000000088AD6C15F77F00000000000000000000FFFFFFFF6B0000001E000000B1900000010000000000000000042500000000001600000000000000B8AD6C15F77F00000000000000000000FFFFFFFF6B0000001E000000B2900000020000000000000000042500000000001800000000000000E0AD6C15F77F00000000000000000000FFFFFFFF6B0000001E000000B490000003000000000000000004250000000000170000000000000008AE6C15F77F00000000000000000000FFFFFFFF6B0000001E000000B390000004000000000000000004250000000000190000000000000040AE6C15F77F00000000000000000000FFFFFFFFA00000001E000000B5900000050000000000000000042001000000001A0000000000000070AE6C15F77F00000000000000000000FFFFFFFF7D0000001E000000B6900000060000000000000000042001000000001B00000000000000A0AE6C15F77F00000000000000000000FFFFFFFF7D0000001E000000B790000007000000000000000004200100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA00000000000000000000000000000000000000000000009D200000200000009100000064000000320000006400000050000000320000003200000028000000500000003C0000005000000050000000320000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C00000050000000500000009700000032000000780000003200000050000000500000005000000050000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA000000000000000000000000000000000000009D200000200000009100000064000000320000009700000050000000320000003200000028000000500000003C000000500000005000000032000000500000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C0000005000000064000000780000003200000078000000780000003200000050000000500000005000000050000000C8000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C0000002D0000002E0000002F00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000002000000030000000400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000000000000000000000000000000
(PID) Process:(6424) PCHealthCheck.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHealthCheck
Operation:writeName:LastUpdateCheckTime
Value:
3C49B607BE71DB01
(PID) Process:(6424) PCHealthCheck.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6424) PCHealthCheck.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6424) PCHealthCheck.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6424) PCHealthCheck.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\PCHC
Operation:writeName:UpgradeEligibility
Value:
0
Executable files
64
Suspicious files
3 677
Text files
1
Unknown types
1

Dropped files

PID
Process
Filename
Type
6692Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeC:\Users\admin\AppData\Local\Temp\_MEI66922\_hashlib.pydexecutable
MD5:5B08C2DCBE1B1DEA46ABBD6C9425878E
SHA256:823717926ADCE6B36F9C13B6555EAEAF5714C4756828F11CFFC1CE0BEF970A7E
6692Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeC:\Users\admin\AppData\Local\Temp\_MEI66922\VCRUNTIME140.dllexecutable
MD5:862F820C3251E4CA6FC0AC00E4092239
SHA256:36585912E5EAF83BA9FEA0631534F690CCDC2D7BA91537166FE53E56C221E153
6692Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeC:\Users\admin\AppData\Local\Temp\_MEI66922\_ctypes.pydexecutable
MD5:F8D2950D5496D3940AEF6758C9E9E576
SHA256:9FFDEDD0F1F09F21870BD75C08D05C32994A1193BE3955E367F260690A36CBD0
6692Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeC:\Users\admin\AppData\Local\Temp\_MEI66922\_queue.pydexecutable
MD5:6F8624F0746FA31CF72EF568D6A121F1
SHA256:37622CA591FB8E45A894DB9C0DA99BFCB18A820A48F028E4949D9256B69247E3
6692Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeC:\Users\admin\AppData\Local\Temp\_MEI66922\_multiprocessing.pydexecutable
MD5:3966D8FD4D83FA54DB28338FF6087E08
SHA256:B66A5A1A4AA1F187CC349E7548C3CF6D815552937A6A1D33ECC87B76794A1939
6692Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeC:\Users\admin\AppData\Local\Temp\_MEI66922\_socket.pydexecutable
MD5:DC5A5AB89E6E2B48CB50B463B214FD89
SHA256:0E2C1089974A2757426DAC3295201A33C990C36F3C09593F8A2B6E07FD36B99C
6692Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeC:\Users\admin\AppData\Local\Temp\_MEI66922\_decimal.pydexecutable
MD5:C68FC0D5C1878D02069503280234E969
SHA256:847E2B2C69CA623E0F96BBDA0F421CA978FBB5925BEEC4CC5E4C5D9C966C4BBC
6692Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeC:\Users\admin\AppData\Local\Temp\_MEI66922\_ssl.pydexecutable
MD5:25D4B1C6CA053C573A55D68AE3DB5CE2
SHA256:81344E3E16CF6F2D5B24CC0CF92E95C5FD0592E4A3859BB00C3F5891E2482128
6692Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeC:\Users\admin\AppData\Local\Temp\_MEI66922\libffi-8.dllexecutable
MD5:0F8E4992CA92BAAF54CC0B43AACCCE21
SHA256:EFF52743773EB550FCC6CE3EFC37C85724502233B6B002A35496D828BD7B280A
6692Steam Emulator + Anti-Denuvo & Anti-Enigma & Anti-DRM Injector.exeC:\Users\admin\AppData\Local\Temp\_MEI66922\_bz2.pydexecutable
MD5:03BAD8289D9AA18E859ED7270A719E92
SHA256:178C6EEB30843E656CC407AAF53AE6D0F170966E4E0BDD2EE1BEDE73962275CD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
40
DNS requests
28
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5488
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5488
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6408
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6100
SystemSettings.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6100
SystemSettings.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
40.126.31.69:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1076
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
4428
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
SIHClient.exe
20.12.23.50:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 40.126.31.69
  • 20.190.159.4
  • 20.190.159.23
  • 20.190.159.75
  • 20.190.159.73
  • 20.190.159.0
  • 40.126.31.73
  • 40.126.31.67
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 184.30.131.245
whitelisted
go.microsoft.com
  • 184.28.89.167
  • 23.213.166.81
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.48
whitelisted

Threats

No threats detected
No debug info