| File name: | The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen.zip |
| Full analysis: | https://app.any.run/tasks/ebc9a3b8-70c1-49f2-92c3-d0f5464af7ca |
| Verdict: | Malicious activity |
| Analysis date: | January 04, 2024, 14:12:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 1EBC401FF9D93297714A73CFACA0CF89 |
| SHA1: | D44C2965EF6ED5BA6A7BE4DE62390E91231933AB |
| SHA256: | 64DF02D099D4179983E04EBEB4469C7C4F9B223FB411EB682D740B4A70F92600 |
| SSDEEP: | 98304:btfmg8GYnfjsXgkka5+jTq/R+4NPXcqx6EkEXwOeNAUDwf4ldKpBTPWR8H3AybGr:MtcUajqk+4A57 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2024:01:04 15:07:12 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1044 | "C:\Users\admin\Desktop\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe" | C:\Users\admin\Desktop\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1576 | "C:\Users\admin\Desktop\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe" | C:\Users\admin\Desktop\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1900 | "C:\Users\admin\AppData\Local\Temp\cetrainers\CET5455.tmp\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe" -ORIGIN:"C:\Users\admin\Desktop\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\" | C:\Users\admin\AppData\Local\Temp\cetrainers\CET5455.tmp\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | — | The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2052 | C:\Windows\helppane.exe -Embedding | C:\Windows\HelpPane.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Help and Support Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2128 | "C:\Users\admin\AppData\Local\Temp\cetrainers\CET3573.tmp\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe" -ORIGIN:"C:\Users\admin\Desktop\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\" | C:\Users\admin\AppData\Local\Temp\cetrainers\CET3573.tmp\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | — | The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2296 | "C:\Users\admin\Desktop\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe" | C:\Users\admin\Desktop\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2316 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\options.txt | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2424 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\options.txt | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2620 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\options.txt | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (124) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1576 | The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CET3573.tmp\CET_Archive.dat | — | |
MD5:— | SHA256:— | |||
| 2296 | The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CET5455.tmp\CET_Archive.dat | — | |
MD5:— | SHA256:— | |||
| 1576 | The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CET3573.tmp\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | executable | |
MD5:A65C29111A4CF5A7FDD5A9D79F77BCAB | SHA256:DAB3003436B6861AE220CC5FDCB97970FC05AFDF114C2F91E46EED627CE3D6AF | |||
| 124 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa124.2476\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\options.txt | text | |
MD5:CE13563B4C5A6FBDE556BDC19D4D23B8 | SHA256:CB9B0711F6FD84280124219CB277BCFB39B5BBAD1C28F08C2AE3FEB60D4A5D36 | |||
| 124 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa124.2476\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | executable | |
MD5:481DE97B2EBD53D89B914A99128F3EEF | SHA256:C89F00B7E6579332C7295F3C7B943307F4584C9BB29AAE9B9AAA5EF2D4DD8199 | |||
| 2128 | The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CET3573.tmp\extracted\CET_TRAINER.CETRAINER | binary | |
MD5:923CA725E43B6AB3926C3AD4C3E5139A | SHA256:1AF096B34F7CF3119A1ECC4E54792899DB77B327E450E5B6C8B27B5E60718D07 | |||
| 2128 | The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CET3573.tmp\extracted\defines.lua | text | |
MD5:50DDB39ECE0AABD0E709ADFC15F93CE2 | SHA256:30B816A90ABBE520BCB6606D022F3C870A72AD05A94522FF64B8395BFC088E67 | |||
| 2128 | The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CET3573.tmp\extracted\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | executable | |
MD5:7D234D01DA96F53F0BFAECB3A8F3FCC4 | SHA256:46EFDD35E91D2A90AB76A6FCCDED973AFC80D7B4A83FDA4BBE305B9FE9B6851D | |||
| 124 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa124.2476\The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2-peizhaochen\More Trainers @ GameCopyWorld.url | text | |
MD5:B40C2287E8323510C1FDDB903E4F6D3C | SHA256:BC2C79EA0113B6B2B6A06A8AE448ADA10CB05026BD4F840582079F218CE50937 | |||
| 2128 | The.Callisto.Protocol.v1.0.Plus.17.Trainer.Update2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CET3573.tmp\extracted\lua53-64.dll | executable | |
MD5:B7C9F1E7E640F1A034BE84AF86970D45 | SHA256:6D0A06B90213F082CB98950890518C0F08B9FC16DBFAB34D400267CB6CDADEFF | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |