| File name: | Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE |
| Full analysis: | https://app.any.run/tasks/19f8be62-c35a-44f3-8e28-f1afc080d6f2 |
| Verdict: | Malicious activity |
| Analysis date: | March 10, 2024, 11:19:42 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F39AB259177DA55DF1E05128D3170EEB |
| SHA1: | DE7D0651AB71C3108542D484F4E19E364255438A |
| SHA256: | 828AD737E7FFFD5A3ABC8B7086EC32E5408E08CBE4E5DDDE794B548A6F7FBF7F |
| SSDEEP: | 98304:ltDawkt4O2i0jUJ8fGeOXgoPrTKF3r+bAMVsB0s5GKfvAVrY/8le8ChViLZtUOBF:R2y6/J |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:04:29 02:56:00+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 36352 |
| InitializedDataSize: | 4170240 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x15ad |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2852 | "C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe" "C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\CET_TRAINER.CETRAINER" "-ORIGIN:C:\Users\admin\AppData\Local\Temp\" | C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | ||||||||||||
User: admin Company: Cheat Engine Integrity Level: HIGH Description: Cheat Engine Exit code: 0 Version: 6.3.0.3328 Modules
| |||||||||||||||
| 3660 | "C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe" -ORIGIN:"C:\Users\admin\AppData\Local\Temp\" | C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3668 | "C:\Users\admin\AppData\Local\Temp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe" | C:\Users\admin\AppData\Local\Temp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3772 | "C:\Users\admin\AppData\Local\Temp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe" | C:\Users\admin\AppData\Local\Temp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3848 | "C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\xmplayer.exe" CEABD118244_6BC0_4279_A160CFD18B0CA92F | C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\xmplayer.exe | — | Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | Key: | HKEY_CURRENT_USER\Software\Cheat Engine\Window Positions |
| Operation: | write | Name: | AdvancedOptions Position |
Value: 7E010000FF0100007402000029010000 | |||
| (PID) Process: | (2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | Key: | HKEY_CURRENT_USER\Software\Cheat Engine\Window Positions |
| Operation: | write | Name: | frmAutoInject Position |
Value: 8701000000050000AF0100004B010000 | |||
| (PID) Process: | (2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | Key: | HKEY_CURRENT_USER\Software\Cheat Engine\Window Positions |
| Operation: | write | Name: | MemoryBrowser Position |
Value: F600000062030000CC0200004B020000500000008C000000C8000000640000002C010000D20000000100000001000000 | |||
| (PID) Process: | (2852) Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | Key: | HKEY_CURRENT_USER\Software\Cheat Engine\Window Positions |
| Operation: | write | Name: | MainForm Position |
Value: CD00000005030000580200003A02000028000000A0000000550000003C00000010270000590100005D000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3772 | Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | executable | |
MD5:808DE473370EF6B5D98AB752F245A3CA | SHA256:65CBED2E8DB313B8966638E40EB27F94156C294EB060B28A02C130D146518C39 | |||
| 3772 | Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\CET_Archive.dat | binary | |
MD5:366FACD2D3CCC80600C74E6E0ECFFDDC | SHA256:733AC62AEA6C8279D39C58A0035E20361DECE510D2C40DD3A606839683FD3D01 | |||
| 3660 | Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\xmplayer.exe | executable | |
MD5:1C84FE15CD4649DFBD903AA883F139AE | SHA256:3F120F522E9A00975D0A9C1A724303E5A16A4D52C35091810F00F82482308E7D | |||
| 3660 | Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\win32\dbghelp.dll | executable | |
MD5:4003E34416EBD25E4C115D49DC15E1A7 | SHA256:C06430B8CB025BE506BE50A756488E1BCC3827C4F45158D93E4E3EEB98CE1E4F | |||
| 3660 | Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\lua5.1-32.dll | executable | |
MD5:8ABE7DD2963502FE189F42FA7CBA4F74 | SHA256:BB89ED00C1974E376E8FAADA62A2EEE7C3229FF3C2734771EA16D2D5DF97E74A | |||
| 3660 | Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | executable | |
MD5:3900DC45F137AD53488492C8AF082B5D | SHA256:452AF4E8ED15DC524601645C231FE5732507F2248EBF8C813FEF29D4E86C61C3 | |||
| 3660 | Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\CET_TRAINER.CETRAINER | binary | |
MD5:B289074D651656C3D7F331A02FB37465 | SHA256:2F453A94E4BF7E177B56D0AB05921B6DC9C67E3C0394282B3AECE1D544AA11FB | |||
| 3660 | Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETF3C6.tmp\extracted\defines.lua | text | |
MD5:137698460F16DD9D7C5DCD95497FDE8C | SHA256:69CC27CC19C4F47586D4E65F5B22329F66D5D6DC9B86670CDC8E3C19D2E39829 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
Process | Message |
|---|---|
Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | Offset of LBR_Count=760 |
Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | sizeof fxstate = 512 |
Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | Symbolhandler: sync: Calling finishedloadingsymbols |
Trainer+8 Command And Conquer Red Alert 3 Ver.1.12 by {MaxTre}.EXE.exe | finishedLoadingSymbols called |