File name:

A8 Trainer v7.7.0i.Exe

Full analysis: https://app.any.run/tasks/0aff61ae-f358-41b9-898a-dbe00ac17b89
Verdict: Malicious activity
Analysis date: April 28, 2024, 14:12:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

079F675754D76CC1F951757A8C82E9D2

SHA1:

5AF3F37B4B9DBFAD4EDCB25D2E0EDD41BC82F5EB

SHA256:

85B52E58A3CDD281AA669468D1FEC66DD2B4386E5AB554A541688B2130CD2C25

SSDEEP:

98304:uiIvwrGTj6vdhyRKnVQyd9oekWHulLeHaU9cbOcIeWRnYzQlZE4k0xkWRgaE/a3h:/orhDXdeeOcrpxEYBg6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • A8 Trainer v7.7.0i.Exe.exe (PID: 4080)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 1024)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2344)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2468)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2504)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2688)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2424)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2392)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • A8 Trainer v7.7.0i.Exe.exe (PID: 4080)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 1024)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2344)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2468)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2504)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2688)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2424)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2392)
  • INFO

    • Checks supported languages

      • A8 Trainer v7.7.0i.Exe.exe (PID: 4080)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 1024)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2344)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2468)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2504)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2688)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2424)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2392)
    • Reads the computer name

      • A8 Trainer v7.7.0i.Exe.exe (PID: 4080)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2344)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2504)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2392)
    • Create files in a temporary directory

      • A8 Trainer v7.7.0i.Exe.exe (PID: 1024)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 4080)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2344)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2468)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2504)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2688)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2392)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2424)
    • Manual execution by a user

      • explorer.exe (PID: 1116)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2532)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2344)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 856)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2504)
      • A8 Trainer v7.7.0i.Exe.exe (PID: 2392)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:06:28 14:45:44+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 36352
InitializedDataSize: 13667328
UninitializedDataSize: -
EntryPoint: 0x15eb
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
12
Malicious processes
0
Suspicious processes
8

Behavior graph

Click at the process to see the details
start a8 trainer v7.7.0i.exe.exe a8 trainer v7.7.0i.exe.exe explorer.exe no specs a8 trainer v7.7.0i.exe.exe no specs a8 trainer v7.7.0i.exe.exe a8 trainer v7.7.0i.exe.exe a8 trainer v7.7.0i.exe.exe no specs a8 trainer v7.7.0i.exe.exe a8 trainer v7.7.0i.exe.exe a8 trainer v7.7.0i.exe.exe a8 trainer v7.7.0i.exe.exe a8 trainer v7.7.0i.exe.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
856"C:\Users\admin\AppData\Local\Temp\A8 Trainer v7.7.0i.Exe.exe" C:\Users\admin\AppData\Local\Temp\A8 Trainer v7.7.0i.Exe.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\a8 trainer v7.7.0i.exe.exe
c:\windows\system32\ntdll.dll
1024"C:\Users\admin\AppData\Local\Temp\cetrainers\CET42F6.tmp\A8 Trainer v7.7.0i.Exe.exe" -ORIGIN:"C:\Users\admin\AppData\Local\Temp\"C:\Users\admin\AppData\Local\Temp\cetrainers\CET42F6.tmp\A8 Trainer v7.7.0i.Exe.exe
A8 Trainer v7.7.0i.Exe.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\cetrainers\cet42f6.tmp\a8 trainer v7.7.0i.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1116"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2344"C:\Users\admin\AppData\Local\Temp\A8 Trainer v7.7.0i.Exe.exe" C:\Users\admin\AppData\Local\Temp\A8 Trainer v7.7.0i.Exe.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\a8 trainer v7.7.0i.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2392"C:\Users\admin\AppData\Local\Temp\A8 Trainer v7.7.0i.Exe.exe" C:\Users\admin\AppData\Local\Temp\A8 Trainer v7.7.0i.Exe.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\a8 trainer v7.7.0i.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2424"C:\Users\admin\AppData\Local\Temp\cetrainers\CET31CB.tmp\A8 Trainer v7.7.0i.Exe.exe" -ORIGIN:"C:\Users\admin\AppData\Local\Temp\"C:\Users\admin\AppData\Local\Temp\cetrainers\CET31CB.tmp\A8 Trainer v7.7.0i.Exe.exe
A8 Trainer v7.7.0i.Exe.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\cetrainers\cet31cb.tmp\a8 trainer v7.7.0i.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2468"C:\Users\admin\AppData\Local\Temp\cetrainers\CETF31C.tmp\A8 Trainer v7.7.0i.Exe.exe" -ORIGIN:"C:\Users\admin\AppData\Local\Temp\"C:\Users\admin\AppData\Local\Temp\cetrainers\CETF31C.tmp\A8 Trainer v7.7.0i.Exe.exe
A8 Trainer v7.7.0i.Exe.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\cetrainers\cetf31c.tmp\a8 trainer v7.7.0i.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2504"C:\Users\admin\AppData\Local\Temp\A8 Trainer v7.7.0i.Exe.exe" C:\Users\admin\AppData\Local\Temp\A8 Trainer v7.7.0i.Exe.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\a8 trainer v7.7.0i.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2532"C:\Users\admin\AppData\Local\Temp\A8 Trainer v7.7.0i.Exe.exe" C:\Users\admin\AppData\Local\Temp\A8 Trainer v7.7.0i.Exe.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\a8 trainer v7.7.0i.exe.exe
c:\windows\system32\ntdll.dll
2688"C:\Users\admin\AppData\Local\Temp\cetrainers\CET1CAD.tmp\A8 Trainer v7.7.0i.Exe.exe" -ORIGIN:"C:\Users\admin\AppData\Local\Temp\"C:\Users\admin\AppData\Local\Temp\cetrainers\CET1CAD.tmp\A8 Trainer v7.7.0i.Exe.exe
A8 Trainer v7.7.0i.Exe.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\cetrainers\cet1cad.tmp\a8 trainer v7.7.0i.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
291
Read events
291
Write events
0
Delete events
0

Modification events

No data
Executable files
12
Suspicious files
0
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
4080A8 Trainer v7.7.0i.Exe.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CET42F6.tmp\CET_Archive.dat
MD5:
SHA256:
1024A8 Trainer v7.7.0i.Exe.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CET42F6.tmp\extracted\CET_TRAINER.CETRAINER
MD5:
SHA256:
2344A8 Trainer v7.7.0i.Exe.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CETF31C.tmp\CET_Archive.dat
MD5:
SHA256:
2468A8 Trainer v7.7.0i.Exe.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CETF31C.tmp\extracted\CET_TRAINER.CETRAINER
MD5:
SHA256:
2504A8 Trainer v7.7.0i.Exe.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CET1CAD.tmp\CET_Archive.dat
MD5:
SHA256:
2688A8 Trainer v7.7.0i.Exe.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CET1CAD.tmp\extracted\CET_TRAINER.CETRAINER
MD5:
SHA256:
2392A8 Trainer v7.7.0i.Exe.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CET31CB.tmp\CET_Archive.dat
MD5:
SHA256:
2424A8 Trainer v7.7.0i.Exe.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CET31CB.tmp\extracted\CET_TRAINER.CETRAINER
MD5:
SHA256:
4080A8 Trainer v7.7.0i.Exe.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CET42F6.tmp\A8 Trainer v7.7.0i.Exe.exeexecutable
MD5:A65C29111A4CF5A7FDD5A9D79F77BCAB
SHA256:DAB3003436B6861AE220CC5FDCB97970FC05AFDF114C2F91E46EED627CE3D6AF
2344A8 Trainer v7.7.0i.Exe.exeC:\Users\admin\AppData\Local\Temp\cetrainers\CETF31C.tmp\A8 Trainer v7.7.0i.Exe.exeexecutable
MD5:A65C29111A4CF5A7FDD5A9D79F77BCAB
SHA256:DAB3003436B6861AE220CC5FDCB97970FC05AFDF114C2F91E46EED627CE3D6AF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown

DNS requests

No data

Threats

No threats detected
No debug info