File name:

until-dawn-trainer-24-original-cheat-happens.rar

Full analysis: https://app.any.run/tasks/01bf6c72-e33c-44ed-bc42-069dd818e5bc
Verdict: Malicious activity
Analysis date: October 31, 2024, 19:12:00
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

D6BAFF14DF383B2884DC1AF19B62D9FB

SHA1:

DC9CD2F463B03D6D9A19DA80425917D6CE9D0545

SHA256:

8166B5A0475F9FB117C02AFF353820A2FBC834953482367FA23D52CF4082738D

SSDEEP:

6144:6JGhBSjXwlw4Pcno40OU6RS5PdcEKzq8+p:YMUj4kno7JdcEKc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6472)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6472)
    • Application launched itself

      • WinRAR.exe (PID: 6472)
    • Process drops legitimate windows executable

      • UD.exe (PID: 1788)
    • Executable content was dropped or overwritten

      • UD.exe (PID: 1788)
    • The process drops C-runtime libraries

      • UD.exe (PID: 1788)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 6472)
    • Manual execution by a user

      • UD.exe (PID: 1788)
      • UD.exe (PID: 3744)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 120674
UncompressedSize: 120674
OperatingSystem: Win32
ArchivedFileName: Until Dawn Trainer +24 ORIGINAL (Cheat Happens)/UD.rar
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe ud.exe no specs ud.exe aurora.exe

Process information

PID
CMD
Path
Indicators
Parent process
1788"C:\Users\admin\Desktop\UD.exe" C:\Users\admin\Desktop\UD.exe
explorer.exe
User:
admin
Company:
Cheat Happens
Integrity Level:
HIGH
Description:
CH Trainer
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\ud.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3744"C:\Users\admin\Desktop\UD.exe" C:\Users\admin\Desktop\UD.exeexplorer.exe
User:
admin
Company:
Cheat Happens
Integrity Level:
MEDIUM
Description:
CH Trainer
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\ud.exe
c:\windows\system32\ntdll.dll
5508"C:\Program Files\CH Aurora\Aurora.exe" chaurora://promotrainer=75979C:\Program Files\CH Aurora\Aurora.exe
UD.exe
User:
admin
Integrity Level:
HIGH
Exit code:
4294967295
Version:
1.10.1.0
Modules
Images
c:\program files\ch aurora\aurora.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6472"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\until-dawn-trainer-24-original-cheat-happens.rarC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6548"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa6472.24412\UD.rarC:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
8 273
Read events
8 202
Write events
70
Delete events
1

Modification events

(PID) Process:(6472) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6472) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\until-dawn-trainer-24-original-cheat-happens.rar
(PID) Process:(6472) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6472) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6472) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6472) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\AppData\Local\Temp\until-dawn-trainer-24-original-cheat-happens.rar
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Rar$DIa6472.24412\UD.rar
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
Executable files
284
Suspicious files
49
Text files
11
Unknown types
11

Dropped files

PID
Process
Filename
Type
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6548.25007\UD.config
MD5:
SHA256:
1788UD.exeC:\Users\admin\AppData\Local\Temp\tmp81.tmp
MD5:
SHA256:
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6548.25007\UD.exeexecutable
MD5:03BB1E34D4B42568AFFD7A4EBDDEB3EE
SHA256:7E850D16CF44D92226901C73773D4B04E414FFA70E22D47C6A6B486AF2F2E8C6
1788UD.exeC:\Program Files\CH Aurora\audio\please wait.mp3binary
MD5:DE40712B34492EBA152848BB395C3A7D
SHA256:807E5A10308B26164860A2C87603A42C3A413A4C0E4493CBFF9F7095623449BC
1788UD.exeC:\Program Files\CH Aurora\audio\female\trainer activated.mp3mp3
MD5:E98DAF9449760110C0962670E343BB32
SHA256:57539CE3E147A6E6682F84BF86168E44A6752E0DDBBF8B044A35E87F394C0328
1788UD.exeC:\Program Files\CH Aurora\audio\female\savegame protection enabled.mp3binary
MD5:E0D6568A620CD960C38466242DC944F1
SHA256:F06234945C519019834328810356B34591614BC1937D2CE4E681FF584189DDF5
1788UD.exeC:\Program Files\CH Aurora\audio\female\please wait.mp3binary
MD5:0FBCD96E1BDAA256EE8D8C080EBF571B
SHA256:6C30177C1BA14CF0417D975B08A748C6ECDDD4104D57881817435F62E11E3144
1788UD.exeC:\Program Files\CH Aurora\audio\female\hotkeys unmuted.mp3mp3
MD5:754EC024C4E28F133623FD7E7ECCD2D4
SHA256:3815BEEB92FF012F14280EDAF71265FF570549DF7B73EFB112AA72116CEFE3F9
1788UD.exeC:\Program Files\CH Aurora\audio\activated.mp3binary
MD5:926EC3F662C8D1E7290BB44EE3CF967F
SHA256:D2B3306E7FB5821B490CE21766D8AFA7F84A1F8E0D249F547E98B2AE1AD0A681
1788UD.exeC:\Program Files\CH Aurora\audio\hotkeys muted.mp3binary
MD5:AF1A608C581897D2C8C2A619FEF1176B
SHA256:6AA26B5BBF5B6EF57DC3BDAE479B5F227213683E8F94E0778A1ABCB4E8965BA5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
57
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6944
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
632
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5832
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5832
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4340
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
3524
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1788
UD.exe
104.26.2.55:443
www.ch-downloads.com
CLOUDFLARENET
US
unknown
4360
SearchApp.exe
2.16.206.221:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.181.238
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.145
  • 23.48.23.167
  • 23.48.23.147
  • 23.48.23.166
  • 23.48.23.177
  • 23.48.23.164
  • 23.48.23.176
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
www.ch-downloads.com
  • 104.26.2.55
  • 104.26.3.55
  • 172.67.70.189
unknown
www.bing.com
  • 2.16.206.221
  • 2.16.206.212
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.31.73
  • 20.190.159.68
  • 20.190.159.75
  • 20.190.159.73
  • 20.190.159.2
  • 20.190.159.4
  • 40.126.31.67
  • 20.190.159.71
whitelisted
th.bing.com
  • 2.16.206.212
  • 2.16.206.221
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted

Threats

No threats detected
No debug info