File name:

CsGo Cheat.rar

Full analysis: https://app.any.run/tasks/53b9203b-d454-4886-ba12-00127023235f
Verdict: Malicious activity
Threats:

RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.

Analysis date: November 11, 2023, 19:35:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
redline
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

ACED090600BE92C91E70CCF1BBAEEB8D

SHA1:

B9BC1D8169A396723E5D3B9697F35DCCB58C3171

SHA256:

561DFE536FDE91B3E2CC745C89FAEFB9240F2148DE342CA47B1670C4FC737B25

SSDEEP:

3072:l3G8D68sxlcjjnyy369MfWmfh1rEfQaCntTz0ytw8C8cQJ39b1:NG8D6fQmrgfLyQnJz91C1QJ39b1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • REDLINE has been detected (YARA)

      • AppLaunch.exe (PID: 3528)
      • AppLaunch.exe (PID: 4004)
  • SUSPICIOUS

    • Connects to unusual port

      • AppLaunch.exe (PID: 3528)
      • AppLaunch.exe (PID: 4004)
  • INFO

    • Reads the computer name

      • AppLaunch.exe (PID: 3528)
      • wmpnscfg.exe (PID: 3756)
      • AppLaunch.exe (PID: 4004)
    • Manual execution by a user

      • Csgo SkinChanger.exe (PID: 3580)
      • wmpnscfg.exe (PID: 3756)
      • Csgo SkinChanger.exe (PID: 3992)
    • Checks supported languages

      • Csgo SkinChanger.exe (PID: 3580)
      • AppLaunch.exe (PID: 3528)
      • wmpnscfg.exe (PID: 3756)
      • Csgo SkinChanger.exe (PID: 3992)
      • AppLaunch.exe (PID: 4004)
    • Reads the machine GUID from the registry

      • AppLaunch.exe (PID: 3528)
      • wmpnscfg.exe (PID: 3756)
      • AppLaunch.exe (PID: 4004)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3140)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs csgo skinchanger.exe no specs #REDLINE applaunch.exe wmpnscfg.exe no specs csgo skinchanger.exe #REDLINE applaunch.exe

Process information

PID
CMD
Path
Indicators
Parent process
3140"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CsGo Cheat.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3528"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AppLaunch.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
Csgo SkinChanger.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET ClickOnce Launch Utility
Exit code:
0
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\applaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3580"C:\Users\admin\Desktop\CsGo Cheat\Csgo SkinChanger.exe" C:\Users\admin\Desktop\CsGo Cheat\Csgo SkinChanger.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\csgo cheat\csgo skinchanger.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3756"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3992"C:\Users\admin\Desktop\CsGo Cheat\Csgo SkinChanger.exe" C:\Users\admin\Desktop\CsGo Cheat\Csgo SkinChanger.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\csgo cheat\csgo skinchanger.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
4004"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AppLaunch.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
Csgo SkinChanger.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET ClickOnce Launch Utility
Exit code:
0
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\applaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
Total events
1 379
Read events
1 357
Write events
19
Delete events
3

Modification events

(PID) Process:(3140) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3140) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
1
Suspicious files
4
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3140WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3140.31383\CsGo Cheat\settings.3.local.cod22.csttext
MD5:62A96F74F6EA17ADC35332A2D1FCED9A
SHA256:373ABB182654910FFB9ADB31F9746DE7CB8ED02CDACBAC03DBD107E0BDF77478
3140WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3140.31383\CsGo Cheat\settings.BR.3.codhq.csbbinary
MD5:FEF2E09635215818BBB519DFC70843B9
SHA256:D5E0FE801BDB2C8E60ADB05DB1FF90D9960C7A63E99D97D2F27D7D4F894B1F69
3140WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3140.31383\CsGo Cheat\settings.3.cod22.csbbinary
MD5:73686DEE4420EAB2E547716886DB87E1
SHA256:808635066D278503BBEB4C5A938671AB66967EE693A07A06759788FB45788EA2
3140WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3140.31383\CsGo Cheat\settings.3.local.codhq.csttext
MD5:B1B1938717419333137787D1878EA0A9
SHA256:0C0FBABCA404E6D929D14F38B32EA32307F6FE008CB27505A80FADE2048A7AEC
3140WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3140.31383\CsGo Cheat\settings.BR.3.local.cod22.csttext
MD5:465981B2C7142B9FB660B39E2DE874C1
SHA256:74D01A0C051C963D9A9B8AB9DBEAB1723F0AD8534EA9FA6A942F358D7FA011B4
3140WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3140.31383\CsGo Cheat\Csgo SkinChanger.exeexecutable
MD5:F05CA70BBEFC2805E7DE7F7C959A213A
SHA256:01E5E34A50B9F25FC3E5EBBECC7D89A8CB67D1A5157D2BB9F900C84FF796BE2C
3140WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3140.31383\CsGo Cheat\settings.BR.3.cod22.csbbinary
MD5:FEF2E09635215818BBB519DFC70843B9
SHA256:D5E0FE801BDB2C8E60ADB05DB1FF90D9960C7A63E99D97D2F27D7D4F894B1F69
3140WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3140.31383\CsGo Cheat\settings.3.codhq.csbbinary
MD5:A70DEA2B8002A55D4722BEB5BB0628FF
SHA256:C509823C67A91A9B4F0DA5A7E3C2DCAFEA827B6BEC5A05F813AA31BDBF5E0D1D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
954
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
868
svchost.exe
95.101.148.135:80
Akamai International B.V.
NL
unknown
868
svchost.exe
23.35.228.137:80
armmf.adobe.com
AKAMAI-AS
DE
unknown
3528
AppLaunch.exe
37.220.87.8:42823
LLC Internet Tehnologii
UZ
malicious
4004
AppLaunch.exe
37.220.87.8:42823
LLC Internet Tehnologii
UZ
malicious

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 23.35.228.137
whitelisted

Threats

No threats detected
No debug info