File name:

Ender Magnolia Bloom in the mist - Trainer +13.zip

Full analysis: https://app.any.run/tasks/2b2ebf4c-cf1f-46b8-a7f5-546da4ae90c2
Verdict: Malicious activity
Analysis date: January 25, 2025, 22:04:01
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

2AC9A4130F4C8C98D66D8167871FAD79

SHA1:

1B38067F901587364800DD919CA415124D7D8F2F

SHA256:

679E7B11B808CE0AAE850B5F537489B1C0F95EF62829630C83456D6FEB65C173

SSDEEP:

6144:cXK5UzOCU5JOlnFMGlREXnDwC2akRzenYGXUec:Gh86FMG3oDwCZ7nYGXUj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6404)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • EMBitm.exe (PID: 7004)
    • Reads security settings of Internet Explorer

      • EMBitm.exe (PID: 7004)
      • Aurora.exe (PID: 5532)
      • Aurora.exe (PID: 1460)
      • Aurora.exe (PID: 3984)
      • Aurora.exe (PID: 4952)
    • Reads the date of Windows installation

      • EMBitm.exe (PID: 7004)
      • Aurora.exe (PID: 5532)
      • Aurora.exe (PID: 1460)
      • Aurora.exe (PID: 3984)
      • Aurora.exe (PID: 4952)
    • Executable content was dropped or overwritten

      • EMBitm.exe (PID: 7004)
    • The process drops C-runtime libraries

      • EMBitm.exe (PID: 7004)
    • The process creates files with name similar to system file names

      • EMBitm.exe (PID: 7004)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6404)
    • Reads the computer name

      • EMBitm.exe (PID: 7004)
      • Aurora.exe (PID: 5532)
      • Aurora.exe (PID: 3984)
      • Aurora.exe (PID: 1460)
      • Aurora.exe (PID: 4952)
    • Manual execution by a user

      • EMBitm.exe (PID: 6944)
      • EMBitm.exe (PID: 7004)
      • Aurora.exe (PID: 3984)
      • Aurora.exe (PID: 6180)
      • Aurora.exe (PID: 6924)
      • Aurora.exe (PID: 1460)
      • Aurora.exe (PID: 4952)
      • Aurora.exe (PID: 3288)
    • Create files in a temporary directory

      • EMBitm.exe (PID: 7004)
    • Reads the machine GUID from the registry

      • EMBitm.exe (PID: 7004)
    • Checks supported languages

      • EMBitm.exe (PID: 7004)
      • Aurora.exe (PID: 5532)
      • Aurora.exe (PID: 1460)
      • Aurora.exe (PID: 3984)
      • Aurora.exe (PID: 4952)
    • Reads Environment values

      • EMBitm.exe (PID: 7004)
    • Process checks computer location settings

      • EMBitm.exe (PID: 7004)
      • Aurora.exe (PID: 5532)
      • Aurora.exe (PID: 1460)
      • Aurora.exe (PID: 4952)
      • Aurora.exe (PID: 3984)
    • Creates files in the program directory

      • Aurora.exe (PID: 5532)
      • EMBitm.exe (PID: 7004)
    • Creates files or folders in the user directory

      • Aurora.exe (PID: 5532)
    • Checks proxy server information

      • Aurora.exe (PID: 5532)
      • Aurora.exe (PID: 1460)
      • Aurora.exe (PID: 3984)
      • Aurora.exe (PID: 4952)
      • EMBitm.exe (PID: 7004)
    • Reads the software policy settings

      • Aurora.exe (PID: 5532)
      • Aurora.exe (PID: 1460)
      • Aurora.exe (PID: 3984)
      • Aurora.exe (PID: 4952)
      • EMBitm.exe (PID: 7004)
    • Disables trace logs

      • EMBitm.exe (PID: 7004)
    • The sample compiled with english language support

      • EMBitm.exe (PID: 7004)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:04:01 19:47:44
ZipCRC: 0x50d88b10
ZipCompressedSize: 5
ZipUncompressedSize: 5
ZipFileName: EMBitm.config
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
10
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe embitm.exe no specs embitm.exe aurora.exe aurora.exe no specs aurora.exe aurora.exe no specs aurora.exe aurora.exe no specs aurora.exe

Process information

PID
CMD
Path
Indicators
Parent process
1460"C:\Program Files\CH Aurora\Aurora.exe" C:\Program Files\CH Aurora\Aurora.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
4294967295
Version:
1.10.1.0
Modules
Images
c:\program files\ch aurora\aurora.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3288"C:\Program Files\CH Aurora\Aurora.exe" C:\Program Files\CH Aurora\Aurora.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
1.10.1.0
3984"C:\Program Files\CH Aurora\Aurora.exe" C:\Program Files\CH Aurora\Aurora.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
4294967295
Version:
1.10.1.0
4952"C:\Program Files\CH Aurora\Aurora.exe" C:\Program Files\CH Aurora\Aurora.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
4294967295
Version:
1.10.1.0
5532"C:\Program Files\CH Aurora\Aurora.exe" chaurora://promotrainer=73781C:\Program Files\CH Aurora\Aurora.exe
EMBitm.exe
User:
admin
Integrity Level:
HIGH
Exit code:
4294967295
Version:
1.10.1.0
Modules
Images
c:\program files\ch aurora\aurora.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6180"C:\Program Files\CH Aurora\Aurora.exe" C:\Program Files\CH Aurora\Aurora.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
1.10.1.0
Modules
Images
c:\program files\ch aurora\aurora.exe
c:\windows\system32\ntdll.dll
6404"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Ender Magnolia Bloom in the mist - Trainer +13.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6924"C:\Program Files\CH Aurora\Aurora.exe" C:\Program Files\CH Aurora\Aurora.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
1.10.1.0
Modules
Images
c:\program files\ch aurora\aurora.exe
c:\windows\system32\ntdll.dll
6944"C:\Users\admin\Desktop\EMBitm.exe" C:\Users\admin\Desktop\EMBitm.exeexplorer.exe
User:
admin
Company:
Cheat Happens
Integrity Level:
MEDIUM
Description:
CH Trainer
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\embitm.exe
c:\windows\system32\ntdll.dll
7004"C:\Users\admin\Desktop\EMBitm.exe" C:\Users\admin\Desktop\EMBitm.exe
explorer.exe
User:
admin
Company:
Cheat Happens
Integrity Level:
HIGH
Description:
CH Trainer
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\embitm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
10 613
Read events
10 561
Write events
52
Delete events
0

Modification events

(PID) Process:(6404) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6404) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6404) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6404) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Ender Magnolia Bloom in the mist - Trainer +13.zip
(PID) Process:(6404) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6404) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6404) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6404) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6404) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(6404) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
284
Suspicious files
70
Text files
15
Unknown types
0

Dropped files

PID
Process
Filename
Type
7004EMBitm.exeC:\Users\admin\AppData\Local\Temp\tmp7A92.tmp
MD5:
SHA256:
7004EMBitm.exeC:\Program Files\CH Aurora\audio\activated.mp3binary
MD5:926EC3F662C8D1E7290BB44EE3CF967F
SHA256:D2B3306E7FB5821B490CE21766D8AFA7F84A1F8E0D249F547E98B2AE1AD0A681
6404WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6404.46169\EMBitm.exeexecutable
MD5:03BB1E34D4B42568AFFD7A4EBDDEB3EE
SHA256:7E850D16CF44D92226901C73773D4B04E414FFA70E22D47C6A6B486AF2F2E8C6
7004EMBitm.exeC:\Program Files\CH Aurora\audio\female\deactivated.mp3binary
MD5:5D7D888BC994C02A3ADB98A33A4BBFBD
SHA256:57C9614960463019910FB45538CB0986E6D1F88242F5E20B04336C0FDCAC4332
7004EMBitm.exeC:\Program Files\CH Aurora\audio\female\hotkeys muted.mp3binary
MD5:BB3F965E332FB2CC459ED44F4A8A2CAA
SHA256:DE2EF38996928FE0D900ADBC0D7FF024B4717262D74B3D3F350B688A007D8DC4
7004EMBitm.exeC:\Program Files\CH Aurora\audio\deactivated.mp3binary
MD5:9CF92DAAEF5ACA26E110350D28E291AD
SHA256:79471932B6A9623EA05C392A0FCE817607E6C4CC713690F91EDB2EC35751605A
7004EMBitm.exeC:\Program Files\CH Aurora\audio\a new trainer update is available.mp3binary
MD5:B694CAFE2380784861D147E46B3F1651
SHA256:A604DAA41820EDEA760C16B46A229290840D57015DAA706AE4D4AE5A74863478
7004EMBitm.exeC:\Program Files\CH Aurora\audio\female\failed.mp3binary
MD5:2D366B82D8E0083C68B8C38B3C60C309
SHA256:ED31AFFA1B2A2D7C7A09F85516DCCD4BE605FDE61B64724A6E07E7901111331A
7004EMBitm.exeC:\Program Files\CH Aurora\audio\female\trainer not found.mp3binary
MD5:2EB800BB4D489ACF6A1EB0FDDE1B9770
SHA256:D8446EB2A6B5388DEF51B399F78EE76E75D507EF0DC31FAC29E17C59C6D41172
7004EMBitm.exeC:\Program Files\CH Aurora\audio\hotkeys muted.mp3binary
MD5:AF1A608C581897D2C8C2A619FEF1176B
SHA256:6AA26B5BBF5B6EF57DC3BDAE479B5F227213683E8F94E0778A1ABCB4E8965BA5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
77
DNS requests
25
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
23.48.23.191:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2088
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2088
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6284
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3040
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
2.16.204.148:443
www.bing.com
Akamai International B.V.
DE
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
23.48.23.191:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.16.253.202:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
184.30.18.9:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.16.204.148
  • 2.16.204.159
  • 2.16.204.143
  • 2.16.204.144
  • 2.16.204.138
  • 2.16.204.147
  • 2.16.204.136
  • 2.16.204.135
  • 2.16.204.139
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
crl.microsoft.com
  • 23.48.23.191
  • 23.48.23.167
  • 23.48.23.181
  • 23.48.23.179
  • 23.48.23.176
  • 23.48.23.173
  • 23.48.23.169
  • 23.48.23.174
  • 23.48.23.190
whitelisted
www.microsoft.com
  • 2.16.253.202
whitelisted
google.com
  • 142.250.74.206
whitelisted
go.microsoft.com
  • 184.30.18.9
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.140
  • 20.190.160.17
  • 40.126.32.133
  • 40.126.32.138
  • 40.126.32.74
  • 20.190.160.20
  • 40.126.32.68
whitelisted
www.ch-downloads.com
  • 104.26.2.55
  • 104.26.3.55
  • 172.67.70.189
unknown
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info