File name:

Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE

Full analysis: https://app.any.run/tasks/19f8be62-c35a-44f3-8e28-f1afc080d6f2
Verdict: Malicious activity
Analysis date: March 10, 2024, 11:19:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F39AB259177DA55DF1E05128D3170EEB

SHA1:

DE7D0651AB71C3108542D484F4E19E364255438A

SHA256:

828AD737E7FFFD5A3ABC8B7086EC32E5408E08CBE4E5DDDE794B548A6F7FBF7F

SSDEEP:

98304:ltDawkt4O2i0jUJ8fGeOXgoPrTKF3r+bAMVsB0s5GKfvAVrY/8le8ChViLZtUOBF:R2y6/J

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 3660)
      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 3772)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 2852)
    • Executable content was dropped or overwritten

      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 3660)
      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 3772)
    • Process drops legitimate windows executable

      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 3660)
    • Reads the Internet Settings

      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 2852)
  • INFO

    • Checks supported languages

      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 3772)
      • xmplayer.exe (PID: 3848)
      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 2852)
      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 3660)
    • Create files in a temporary directory

      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 3660)
      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 3772)
    • Reads the computer name

      • xmplayer.exe (PID: 3848)
      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 3772)
      • Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe (PID: 2852)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:04:29 02:56:00+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 36352
InitializedDataSize: 4170240
UninitializedDataSize: -
EntryPoint: 0x15ad
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start trainer+8 command and conquer red alert 3 ver.1.12 by {maxtre}.exe.exe trainer+8 command and conquer red alert 3 ver.1.12 by {maxtre}.exe.exe trainer+8 command and conquer red alert 3 ver.1.12 by {maxtre}.exe.exe xmplayer.exe no specs trainer+8 command and conquer red alert 3 ver.1.12 by {maxtre}.exe.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2852"C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe" "C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\CET_TRAINER.CETRAINER" "-ORIGIN:C:\Users\admin\AppData\Local\Temp\"C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe
Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe
User:
admin
Company:
Cheat Engine
Integrity Level:
HIGH
Description:
Cheat Engine
Exit code:
0
Version:
6.3.0.3328
Modules
Images
c:\users\admin\appdata\local\temp\cetrainers\cetf3c6.tmp\extracted\trainer+8 command and conquer red alert 3 ver.1.12 by {maxtre}.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3660"C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe" -ORIGIN:"C:\Users\admin\AppData\Local\Temp\"C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe
Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\cetrainers\cetf3c6.tmp\trainer+8 command and conquer red alert 3 ver.1.12 by {maxtre}.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3668"C:\Users\admin\AppData\Local\Temp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe" C:\Users\admin\AppData\Local\Temp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\trainer+8 command and conquer red alert 3 ver.1.12 by {maxtre}.exe.exe
c:\windows\system32\ntdll.dll
3772"C:\Users\admin\AppData\Local\Temp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe" C:\Users\admin\AppData\Local\Temp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\trainer+8 command and conquer red alert 3 ver.1.12 by {maxtre}.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3848"C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\xmplayer.exe" CEABD118244_6BC0_4279_A160CFD18B0CA92FC:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\xmplayer.exeTrainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\cetrainers\cetf3c6.tmp\extracted\xmplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
2 797
Read events
2 785
Write events
12
Delete events
0

Modification events

(PID) Process:(2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeKey:HKEY_CURRENT_USER\Software\Cheat Engine\Window Positions
Operation:writeName:AdvancedOptions Position
Value:
7E010000FF0100007402000029010000
(PID) Process:(2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeKey:HKEY_CURRENT_USER\Software\Cheat Engine\Window Positions
Operation:writeName:frmAutoInject Position
Value:
8701000000050000AF0100004B010000
(PID) Process:(2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeKey:HKEY_CURRENT_USER\Software\Cheat Engine\Window Positions
Operation:writeName:MemoryBrowser Position
Value:
F600000062030000CC0200004B020000500000008C000000C8000000640000002C010000D20000000100000001000000
(PID) Process:(2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeKey:HKEY_CURRENT_USER\Software\Cheat Engine\Window Positions
Operation:writeName:MainForm Position
Value:
CD00000005030000580200003A02000028000000A0000000550000003C00000010270000590100005D000000
Executable files
5
Suspicious files
1
Text files
1
Unknown types
1

Dropped files

PID
Process
Filename
Type
3772Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeexecutable
MD5:808DE473370EF6B5D98AB752F245A3CA
SHA256:65CBED2E8DB313B8966638E40EB27F94156C294EB060B28A02C130D146518C39
3772Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\CET_Archive.datbinary
MD5:366FACD2D3CCC80600C74E6E0ECFFDDC
SHA256:733AC62AEA6C8279D39C58A0035E20361DECE510D2C40DD3A606839683FD3D01
3660Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\xmplayer.exeexecutable
MD5:1C84FE15CD4649DFBD903AA883F139AE
SHA256:3F120F522E9A00975D0A9C1A724303E5A16A4D52C35091810F00F82482308E7D
3660Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\win32\dbghelp.dllexecutable
MD5:4003E34416EBD25E4C115D49DC15E1A7
SHA256:C06430B8CB025BE506BE50A756488E1BCC3827C4F45158D93E4E3EEB98CE1E4F
3660Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\lua5.1-32.dllexecutable
MD5:8ABE7DD2963502FE189F42FA7CBA4F74
SHA256:BB89ED00C1974E376E8FAADA62A2EEE7C3229FF3C2734771EA16D2D5DF97E74A
3660Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeexecutable
MD5:3900DC45F137AD53488492C8AF082B5D
SHA256:452AF4E8ED15DC524601645C231FE5732507F2248EBF8C813FEF29D4E86C61C3
3660Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\CET_TRAINER.CETRAINERbinary
MD5:B289074D651656C3D7F331A02FB37465
SHA256:2F453A94E4BF7E177B56D0AB05921B6DC9C67E3C0394282B3AECE1D544AA11FB
3660Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\defines.luatext
MD5:137698460F16DD9D7C5DCD95497FDE8C
SHA256:69CC27CC19C4F47586D4E65F5B22329F66D5D6DC9B86670CDC8E3C19D2E39829
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe
Offset of LBR_Count=760
Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe
sizeof fxstate = 512
Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe
Symbolhandler: sync: Calling finishedloadingsymbols
Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe
finishedLoadingSymbols called