| File name: | Modern Warefare 2 Aimbot Steam Edition.exe |
| Full analysis: | https://app.any.run/tasks/e82b0c7e-f849-42ff-a982-c9cb60fc971b |
| Verdict: | Malicious activity |
| Analysis date: | May 23, 2024, 21:57:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive |
| MD5: | 3D4ADDF8A84693F878D22187867A14D7 |
| SHA1: | F7D86103E85F6B6823227CADB36D5E3A3DE2AD4E |
| SHA256: | 873E78F1513F4F9A9B3D87D23B5F7BA08FB82B021EE8AB0AB49CDF821FF6EE0A |
| SSDEEP: | 98304:K/RaBdMOEhG1G3tIz9PuxGM3Trrq2EHq6OiDraZK4T1aPjqh7V8qjlnxmA75MO6l:lmR0nVPLFp9b |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:03:15 06:27:50+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 67584 |
| InitializedDataSize: | 174592 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa7b1 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 660 | "C:\Users\admin\Desktop\Modern Warefare 2 Aimbot Steam Edition.exe" | C:\Users\admin\Desktop\Modern Warefare 2 Aimbot Steam Edition.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1120 | "C:\Users\admin\Desktop\Modern Warefare 2 Aimbot Steam Edition.exe" | C:\Users\admin\Desktop\Modern Warefare 2 Aimbot Steam Edition.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2012 | "C:\Users\admin\Desktop\Modern Warefare 2 Aimbot Steam Edition.exe" | C:\Users\admin\Desktop\Modern Warefare 2 Aimbot Steam Edition.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3984 | "C:\Users\admin\Desktop\Modern Warefare 2 Aimbot Steam Edition.exe" | C:\Users\admin\Desktop\Modern Warefare 2 Aimbot Steam Edition.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| (PID) Process: | (1120) Modern Warefare 2 Aimbot Steam Edition.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (1120) Modern Warefare 2 Aimbot Steam Edition.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (1120) Modern Warefare 2 Aimbot Steam Edition.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
| (PID) Process: | (1120) Modern Warefare 2 Aimbot Steam Edition.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoConfigURL |
Value: | |||
| (PID) Process: | (1120) Modern Warefare 2 Aimbot Steam Edition.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoDetect |
Value: | |||
| (PID) Process: | (1120) Modern Warefare 2 Aimbot Steam Edition.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1120) Modern Warefare 2 Aimbot Steam Edition.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1120) Modern Warefare 2 Aimbot Steam Edition.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1120) Modern Warefare 2 Aimbot Steam Edition.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1120) Modern Warefare 2 Aimbot Steam Edition.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1120 | Modern Warefare 2 Aimbot Steam Edition.exe | C:\Program Files\MW2 Aimbot\Modern Warefare 2 Aimbot(Steam Edition)\avutil-50.dll | executable | |
MD5:EA1F42949B42D9B0A17CC98829B5D641 | SHA256:547FD4286ADE3DAA74E0A04A3BE26776D3F3BD7E52ADEE82CF4B29946E094D1E | |||
| 1120 | Modern Warefare 2 Aimbot Steam Edition.exe | C:\Program Files\MW2 Aimbot\Modern Warefare 2 Aimbot(Steam Edition)\CSERHelper.dll | executable | |
MD5:173C217E677C4B0C4F8A6D54BA13BF9B | SHA256:1DF7F26931AC31569AB0F5A0F4F687776501891276884377426CAEB9C04ADD8C | |||
| 1120 | Modern Warefare 2 Aimbot Steam Edition.exe | C:\Program Files\MW2 Aimbot\Modern Warefare 2 Aimbot(Steam Edition)\Aimbot Injector.exe | executable | |
MD5:44B5A256D414DB633C3B73E39A165489 | SHA256:816C74E4560B9D09E14459E105BE4EA3F980C289DD7BF5A5C49B4484FFDD93CB | |||
| 1120 | Modern Warefare 2 Aimbot Steam Edition.exe | C:\Program Files\MW2 Aimbot\Modern Warefare 2 Aimbot(Steam Edition)\GameOverlayRenderer.dll | executable | |
MD5:1C2797F421C6569B31CF85E182F4F730 | SHA256:67952FA750B1B55C48D1FC77D6EC2C350FF9F2D7D966F49E44E6A91C58F26817 | |||
| 1120 | Modern Warefare 2 Aimbot Steam Edition.exe | C:\Program Files\MW2 Aimbot\Modern Warefare 2 Aimbot(Steam Edition)\mss32_s.dll | executable | |
MD5:1B461C2917663D325FBD51E6C3687963 | SHA256:9BCC83AAD942DB4956362C9C536B8CA761EFBD852EACE4D3225F8E8611576AB0 | |||
| 1120 | Modern Warefare 2 Aimbot Steam Edition.exe | C:\Program Files\MW2 Aimbot\Modern Warefare 2 Aimbot(Steam Edition)\dbghelp.dll | executable | |
MD5:A7532E66EA2F168A0970E829D8986423 | SHA256:908B92E80C41D2782C6806C2B05F2FBB4C34A9F95D603C16C188384A9E4EF989 | |||
| 1120 | Modern Warefare 2 Aimbot Steam Edition.exe | C:\Program Files\MW2 Aimbot\Modern Warefare 2 Aimbot(Steam Edition)\GameOverlayUI.exe.log | text | |
MD5:B11B697EE4FF5B743ADD91F4E48C8A93 | SHA256:CCD28A236FC1952F31B9203465AB10F93DF6BA4B3806EE2A672B7EAAB1C3F514 | |||
| 1120 | Modern Warefare 2 Aimbot Steam Edition.exe | C:\Program Files\MW2 Aimbot\Modern Warefare 2 Aimbot(Steam Edition)\GameOverlayUI.exe | executable | |
MD5:CA5239BA97E13AB68D0D088435F64C44 | SHA256:C3CE7803B1DEEDE777E16F3F02853688ACFE1CD64AA5491B94F443138DF33786 | |||
| 1120 | Modern Warefare 2 Aimbot Steam Edition.exe | C:\Program Files\MW2 Aimbot\Modern Warefare 2 Aimbot(Steam Edition)\GameOverlayRenderer64.dll | executable | |
MD5:842DB1956330932ED701E0664AE785AE | SHA256:BA764E8E67817CCCB3FC386A71960AAA29C4D8F98E8E14ED1497EB967C226DE2 | |||
| 1120 | Modern Warefare 2 Aimbot Steam Edition.exe | C:\Program Files\MW2 Aimbot\Modern Warefare 2 Aimbot(Steam Edition)\vstdlib_s64.dll | executable | |
MD5:8BB9E293559FD1AC7E103747B70B1E3C | SHA256:E960473212A46A2DEC2E465F32F383117FEF8953C489789DC2BC9A2E0BC9ED5F | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |