File name:

until-dawn-trainer-24-original-cheat-happens.rar

Full analysis: https://app.any.run/tasks/01bf6c72-e33c-44ed-bc42-069dd818e5bc
Verdict: Malicious activity
Analysis date: October 31, 2024, 19:12:00
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

D6BAFF14DF383B2884DC1AF19B62D9FB

SHA1:

DC9CD2F463B03D6D9A19DA80425917D6CE9D0545

SHA256:

8166B5A0475F9FB117C02AFF353820A2FBC834953482367FA23D52CF4082738D

SSDEEP:

6144:6JGhBSjXwlw4Pcno40OU6RS5PdcEKzq8+p:YMUj4kno7JdcEKc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6472)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6472)
    • Executable content was dropped or overwritten

      • UD.exe (PID: 1788)
    • The process drops C-runtime libraries

      • UD.exe (PID: 1788)
    • Process drops legitimate windows executable

      • UD.exe (PID: 1788)
    • Application launched itself

      • WinRAR.exe (PID: 6472)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 6472)
    • Manual execution by a user

      • UD.exe (PID: 1788)
      • UD.exe (PID: 3744)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 120674
UncompressedSize: 120674
OperatingSystem: Win32
ArchivedFileName: Until Dawn Trainer +24 ORIGINAL (Cheat Happens)/UD.rar
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe ud.exe no specs ud.exe aurora.exe

Process information

PID
CMD
Path
Indicators
Parent process
1788"C:\Users\admin\Desktop\UD.exe" C:\Users\admin\Desktop\UD.exe
explorer.exe
User:
admin
Company:
Cheat Happens
Integrity Level:
HIGH
Description:
CH Trainer
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\ud.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3744"C:\Users\admin\Desktop\UD.exe" C:\Users\admin\Desktop\UD.exeexplorer.exe
User:
admin
Company:
Cheat Happens
Integrity Level:
MEDIUM
Description:
CH Trainer
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\ud.exe
c:\windows\system32\ntdll.dll
5508"C:\Program Files\CH Aurora\Aurora.exe" chaurora://promotrainer=75979C:\Program Files\CH Aurora\Aurora.exe
UD.exe
User:
admin
Integrity Level:
HIGH
Exit code:
4294967295
Version:
1.10.1.0
Modules
Images
c:\program files\ch aurora\aurora.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6472"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\until-dawn-trainer-24-original-cheat-happens.rarC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6548"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIa6472.24412\UD.rarC:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
8 273
Read events
8 202
Write events
70
Delete events
1

Modification events

(PID) Process:(6472) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6472) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\until-dawn-trainer-24-original-cheat-happens.rar
(PID) Process:(6472) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6472) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6472) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6472) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\AppData\Local\Temp\until-dawn-trainer-24-original-cheat-happens.rar
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Rar$DIa6472.24412\UD.rar
(PID) Process:(6548) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
Executable files
284
Suspicious files
49
Text files
11
Unknown types
11

Dropped files

PID
Process
Filename
Type
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6548.25007\UD.config
MD5:
SHA256:
1788UD.exeC:\Users\admin\AppData\Local\Temp\tmp81.tmp
MD5:
SHA256:
6548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6548.25007\UD.exeexecutable
MD5:03BB1E34D4B42568AFFD7A4EBDDEB3EE
SHA256:7E850D16CF44D92226901C73773D4B04E414FFA70E22D47C6A6B486AF2F2E8C6
6472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa6472.24412\UD.rarcompressed
MD5:C8406F07684955B1B92C5E00496F7B82
SHA256:FF39F106BEB638D8B39D1D8057BBBE916F42BB3BF9A94E5FBC2EE56D045F5955
1788UD.exeC:\Program Files\CH Aurora\audio\failed.mp3mp3
MD5:2C0D142262BEE0FA849DA0EF912AE6FE
SHA256:4C2C444BC8AFF4766B35F9D50015365716BEBD8EFE4F838FE51844046C6FCAE3
1788UD.exeC:\Program Files\CH Aurora\audio\female\a new trainer update is available.mp3binary
MD5:3794F1B3A6B7E7BF29E3AC8CFA6F4441
SHA256:AAF0A3125B9B581B5D182AD699ACAA0181248767CD4E10F979C95E88B314AFBB
1788UD.exeC:\Program Files\CH Aurora\audio\female\activated.mp3binary
MD5:359966B574E77BEF79F801D6D552DB39
SHA256:86B7E5A957793C629F48FD80308CBDC932B3C55CEB27E9D959AD091B304FB499
1788UD.exeC:\Program Files\CH Aurora\audio\female\hotkeys muted.mp3binary
MD5:BB3F965E332FB2CC459ED44F4A8A2CAA
SHA256:DE2EF38996928FE0D900ADBC0D7FF024B4717262D74B3D3F350B688A007D8DC4
1788UD.exeC:\Program Files\CH Aurora\audio\activated.mp3binary
MD5:926EC3F662C8D1E7290BB44EE3CF967F
SHA256:D2B3306E7FB5821B490CE21766D8AFA7F84A1F8E0D249F547E98B2AE1AD0A681
1788UD.exeC:\Program Files\CH Aurora\audio\hotkeys muted.mp3binary
MD5:AF1A608C581897D2C8C2A619FEF1176B
SHA256:6AA26B5BBF5B6EF57DC3BDAE479B5F227213683E8F94E0778A1ABCB4E8965BA5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
57
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5832
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5832
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
632
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4340
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
3524
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1788
UD.exe
104.26.2.55:443
www.ch-downloads.com
CLOUDFLARENET
US
unknown
4360
SearchApp.exe
2.16.206.221:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.181.238
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.145
  • 23.48.23.167
  • 23.48.23.147
  • 23.48.23.166
  • 23.48.23.177
  • 23.48.23.164
  • 23.48.23.176
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
www.ch-downloads.com
  • 104.26.2.55
  • 104.26.3.55
  • 172.67.70.189
unknown
www.bing.com
  • 2.16.206.221
  • 2.16.206.212
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.31.73
  • 20.190.159.68
  • 20.190.159.75
  • 20.190.159.73
  • 20.190.159.2
  • 20.190.159.4
  • 40.126.31.67
  • 20.190.159.71
whitelisted
th.bing.com
  • 2.16.206.212
  • 2.16.206.221
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted

Threats

No threats detected
No debug info