File name: | CS-GO.exe |
Full analysis: | https://app.any.run/tasks/0b74ff05-1dfe-4134-af3b-3b60c2947be1 |
Verdict: | Malicious activity |
Analysis date: | May 03, 2024, 23:42:06 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 32FFCC78A1C7DB4F24F24694FB97B443 |
SHA1: | 8EF86F8125C52EEE7C30408CCEC68D6E6E6F8125 |
SHA256: | 6D19FFACB8D29C8CBDD8AE684A3F965036603D3DC27166A277D8E3D2AD25AE8B |
SSDEEP: | 6144:zY34UPUb/VltGERMgCskoAYfYrSMhLcfv6npVS4ESMTpP5nRb7tnjbPnXDZyjg1b:XUPZWkvY3t6pVSBSSojQ |
.exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
---|---|---|
.exe | | | Win64 Executable (generic) (37.3) |
.dll | | | Win32 Dynamic Link Library (generic) (8.8) |
.exe | | | Win32 Executable (generic) (6) |
.exe | | | Generic Win/DOS Executable (2.7) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2013:12:01 08:08:28+00:00 |
ImageFileCharacteristics: | No relocs, Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 9 |
CodeSize: | 100352 |
InitializedDataSize: | 87040 |
UninitializedDataSize: | - |
EntryPoint: | 0x108af |
OSVersion: | 5 |
ImageVersion: | - |
SubsystemVersion: | 5 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
524 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1344 --field-trial-handle=1316,i,12834824950350745611,12552987104487743788,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
600 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=3968 --field-trial-handle=1316,i,12834824950350745611,12552987104487743788,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
752 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5124 --field-trial-handle=1328,i,17880605505833655411,1556021900012458509,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
860 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2148 --field-trial-handle=1328,i,17880605505833655411,1556021900012458509,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
956 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=24 --mojo-platform-channel-handle=2720 --field-trial-handle=1328,i,17880605505833655411,1556021900012458509,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
960 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=20 --mojo-platform-channel-handle=4296 --field-trial-handle=1328,i,17880605505833655411,1556021900012458509,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
1036 | timeout /t 3 /nobreak | C:\Windows\System32\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1036 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.PageScreenshotProcessor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=5308 --field-trial-handle=1328,i,17880605505833655411,1556021900012458509,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
1044 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=3024 --field-trial-handle=1164,i,10125313409759304059,13968238816733774773,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
1056 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4880 --field-trial-handle=1328,i,17880605505833655411,1556021900012458509,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
|
(PID) Process: | (3972) CS-GO.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (3972) CS-GO.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (3972) CS-GO.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (3972) CS-GO.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (3972) CS-GO.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (3972) CS-GO.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (3972) CS-GO.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (2108) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
Operation: | write | Name: | failed_count |
Value: 0 | |||
(PID) Process: | (2108) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
Operation: | write | Name: | state |
Value: 2 | |||
(PID) Process: | (2108) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
Operation: | write | Name: | StatusCodes |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
2108 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State | — | |
MD5:— | SHA256:— | |||
2108 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF105e3f.TMP | — | |
MD5:— | SHA256:— | |||
2108 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
2108 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF105e5e.TMP | — | |
MD5:— | SHA256:— | |||
2108 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
2108 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF105ecb.TMP | — | |
MD5:— | SHA256:— | |||
2108 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old | — | |
MD5:— | SHA256:— | |||
3972 | CS-GO.exe | C:\Users\admin\AppData\Local\Temp\update-csgo.bat | text | |
MD5:C50F1BF77D83B5F7A6419882BAD3437D | SHA256:03B31A57DEDABE88AF849E5F4BB08BE1FA3AEBDAEF6052F18124D9449DE67D59 | |||
3972 | CS-GO.exe | C:\Users\admin\AppData\Local\Temp\nosTEAM.bmp | binary | |
MD5:7ACF8532AB417906B1758839EFB1B213 | SHA256:D29E033C40DC6383AB52823F559934279326596B62F9C44690D27DA843A39D18 | |||
3972 | CS-GO.exe | C:\Users\admin\AppData\Local\Temp\visit-www.nosteam.ro.html | html | |
MD5:F670D397EB4590975FF3C44D51339052 | SHA256:3278F3FF732EE4F95186D972BB51B17C1BE55431F50031DF6BE8EF3B30B683D4 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1368 | msedge.exe | GET | 301 | 89.40.214.121:80 | http://www.nosteam.ro/portall/ | unknown | — | — | — |
1368 | msedge.exe | GET | 200 | 89.40.214.121:80 | http://www.nosteam.ro/games/index.html | unknown | — | — | — |
1368 | msedge.exe | GET | 200 | 89.40.214.121:80 | http://www.nosteam.ro/info/games/ | unknown | — | — | — |
1368 | msedge.exe | GET | 200 | 89.40.214.121:80 | http://www.nosteam.ro/favicon.ico | unknown | — | — | — |
3008 | msedge.exe | GET | 200 | 89.40.214.121:80 | http://www.nosteam.ro/index.php?topic=5068.msg111982 | unknown | — | — | — |
2776 | msedge.exe | GET | 200 | 2.19.105.18:80 | http://r3.i.lencr.org/ | unknown | — | — | — |
3008 | msedge.exe | GET | 200 | 89.40.214.121:80 | http://www.nosteam.ro/info/adhelper.js | unknown | — | — | — |
3008 | msedge.exe | GET | 200 | 89.40.214.121:80 | http://www.nosteam.ro/Themes/default/scripts/jquery-1.11.0.min.js | unknown | — | — | — |
3008 | msedge.exe | GET | 200 | 89.40.214.121:80 | http://www.nosteam.ro/info/2pipo.js | unknown | — | — | — |
3008 | msedge.exe | GET | 200 | 89.40.214.121:80 | http://www.nosteam.ro/donate.png | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1368 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2108 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
1368 | msedge.exe | 89.40.214.121:80 | www.nosteam.ro | Chroot Network SRL | RO | unknown |
1368 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
1368 | msedge.exe | 188.114.97.3:443 | greatdexchange.com | — | — | unknown |
1368 | msedge.exe | 2.19.120.29:443 | www.bing.com | Akamai International B.V. | DE | unknown |
2776 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
Domain | IP | Reputation |
---|---|---|
config.edge.skype.com |
| unknown |
www.nosteam.ro |
| unknown |
edge.microsoft.com |
| unknown |
www.bing.com |
| unknown |
greatdexchange.com |
| unknown |
r3.i.lencr.org |
| unknown |
www.paypal.com |
| unknown |
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com |
| unknown |
ctldl.windowsupdate.com |
| unknown |
publisher.linkvertise.com |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Misc activity | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup |
— | — | Misc activity | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup |
— | — | Misc activity | ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI |
— | — | Misc activity | ET INFO Observed ZeroSSL SSL/TLS Certificate |
— | — | Misc activity | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup |
— | — | Misc activity | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup |
— | — | Misc activity | ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI |
— | — | Misc activity | ET INFO Observed ZeroSSL SSL/TLS Certificate |
— | — | Misc activity | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup |
— | — | Misc activity | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup |