URL: | https://www.lastwar.com/en/home.html?1741697083619 |
Full analysis: | https://app.any.run/tasks/af132516-0447-4842-bc9c-d9956a21d69c |
Verdict: | Malicious activity |
Analysis date: | April 10, 2025, 15:34:03 |
OS: | Windows 10 Professional (build: 19044, 64 bit) |
Indicators: | |
MD5: | CD4A518306499ABC0CA7B541E1E50C9E |
SHA1: | D2E74E45F6B67DC2C76B535CE85DA141DE1DB30F |
SHA256: | 950E30094763D2256CB21B4A4CF9FE2BCF72D5449E5EA03669A873921A6766EF |
SSDEEP: | 3:N8DSLNBGK1NKt0aLRKcmUTFn:2OLN/1NclKpkn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
7452 | "C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\Launch.exe" --squirrel-install 1.0.98 | C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\Launch.exe | — | Update.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Launch Exit code: 0 Version: 1.0.1 Modules
| |||||||||||||||
7480 | "C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\UnityCrashHandler64.exe" --attach 7808 37687296 | C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\UnityCrashHandler64.exe | — | LastWar.exe | |||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
7660 | "C:\Users\admin\AppData\Local\TheLastWar\Launch.exe" | C:\Users\admin\AppData\Local\TheLastWar\Launch.exe | — | Update.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Launch Exit code: 0 Version: 1.0.1 Modules
| |||||||||||||||
7672 | "C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\Launch.exe" | C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\Launch.exe | — | Launch.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Launch Exit code: 0 Version: 1.0.1 Modules
| |||||||||||||||
7800 | "C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\Launch.exe" --squirrel-firstrun | C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\Launch.exe | — | Update.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Launch Exit code: 0 Version: 1.0.1 Modules
| |||||||||||||||
7808 | "C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\LastWar.exe" | C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\LastWar.exe | — | Launch.exe | |||||||||||
User: admin Integrity Level: MEDIUM Version: 2019.4.40.16762411 Modules
| |||||||||||||||
7892 | "C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe" --install . --exename Setup.exe | C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe | Setup.exe | ||||||||||||
User: admin Company: GitHub Integrity Level: MEDIUM Description: Update Exit code: 0 Version: 2.0.1.64 Modules
| |||||||||||||||
8072 | "C:\Users\admin\Downloads\Setup.exe" | C:\Users\admin\Downloads\Setup.exe | explorer.exe | ||||||||||||
User: admin Company: FirstFun Integrity Level: MEDIUM Description: Last War:Survival Game for PC Exit code: 0 Version: 1.0.98 Modules
|
(PID) Process: | (7452) Launch.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
Operation: | write | Name: | GlobalAssocChangedCounter |
Value: 114 | |||
(PID) Process: | (7892) Update.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TheLastWar |
Operation: | write | Name: | QuietUninstallString |
Value: "C:\Users\admin\AppData\Local\TheLastWar\Update.exe" --uninstall -s | |||
(PID) Process: | (7892) Update.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TheLastWar |
Operation: | write | Name: | UninstallString |
Value: "C:\Users\admin\AppData\Local\TheLastWar\Update.exe" --uninstall | |||
(PID) Process: | (7892) Update.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TheLastWar |
Operation: | write | Name: | URLUpdateInfo |
Value: | |||
(PID) Process: | (7892) Update.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TheLastWar |
Operation: | write | Name: | EstimatedSize |
Value: 133253 | |||
(PID) Process: | (7892) Update.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TheLastWar |
Operation: | write | Name: | NoModify |
Value: 1 | |||
(PID) Process: | (7892) Update.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TheLastWar |
Operation: | write | Name: | NoRepair |
Value: 1 | |||
(PID) Process: | (7892) Update.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TheLastWar |
Operation: | write | Name: | Language |
Value: 1033 | |||
(PID) Process: | (7892) Update.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TheLastWar |
Operation: | write | Name: | DisplayName |
Value: Last War:Survival Game | |||
(PID) Process: | (7892) Update.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TheLastWar |
Operation: | write | Name: | DisplayVersion |
Value: 1.0.98 |
PID | Process | Filename | Type | |
---|---|---|---|---|
8072 | Setup.exe | C:\Users\admin\AppData\Local\SquirrelTemp\TheLastWar-1.0.98-full.nupkg | — | |
MD5:— | SHA256:— | |||
7892 | Update.exe | C:\Users\admin\AppData\Local\TheLastWar\packages\TheLastWar-1.0.98-full.nupkg | — | |
MD5:— | SHA256:— | |||
7892 | Update.exe | C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\AntiCheatExpert\ACE-Base64.dll | — | |
MD5:— | SHA256:— | |||
7892 | Update.exe | C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\GameAssembly.dll | — | |
MD5:— | SHA256:— | |||
7892 | Update.exe | C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\LastWarBase.dll | — | |
MD5:— | SHA256:— | |||
7892 | Update.exe | C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\AntiCheatExpert\ACE-BASE.sys | executable | |
MD5:0B4781B9A6A193CFFFA01F1E3DD7AB90 | SHA256:C07D6E1F4D77683C54B66D8346CFB86DA4770CFCC18A8A8844622C8ED07859AA | |||
7892 | Update.exe | C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\AntiCheatExpert\ACE-CORE.sys2 | executable | |
MD5:8143A7C5BB551818542DDE20F3E95B12 | SHA256:E407AFC8E5584364D9E061279291C7DC3EF60DA183834244631CB38B3AA6902D | |||
7892 | Update.exe | C:\Users\admin\AppData\Local\TheLastWar\app-1.0.98\AntiCheatExpert\ACE-Base.dat | binary | |
MD5:0BD78C8579467C05FDAF57D400042358 | SHA256:552CEEBE361DDBE19E5886DA64F7091E532CE97E2536EA8FF53D537852CF8007 | |||
7892 | Update.exe | C:\Users\admin\AppData\Local\TheLastWar\Update.exe | executable | |
MD5:AFA32BD2F77013B3D27D7731B6076960 | SHA256:093F750983DA16669310235E1317CAFE6E95497BFB37EEDF6DCCBF9B38208EB8 | |||
8072 | Setup.exe | C:\Users\admin\AppData\Local\SquirrelTemp\setupIcon.ico | image | |
MD5:23BEDC4D32BC71E1D47487752EE52975 | SHA256:91526CA3BF8F89E8DCCCE6EA5E1F3BE20626BCF0EF35A2A818EDE393F04D6431 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 104.124.11.58:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 104.123.41.162:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | HEAD | 200 | 2.18.121.16:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/f0a82376-a390-4752-ab77-2cdbdcb1da8a?P1=1744828617&P2=404&P3=2&P4=gFfG6UEeMHUpDErwtZyR7%2bghyXw8s5uRzYOvwWVlzkAUcs9aLLGM12CrbnNA4dwjAQdse%2b8zmp9cEGtWHnlofQ%3d%3d | unknown | — | — | whitelisted |
— | — | GET | 200 | 104.123.41.162:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
— | — | GET | 206 | 2.18.121.16:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/f0a82376-a390-4752-ab77-2cdbdcb1da8a?P1=1744828617&P2=404&P3=2&P4=gFfG6UEeMHUpDErwtZyR7%2bghyXw8s5uRzYOvwWVlzkAUcs9aLLGM12CrbnNA4dwjAQdse%2b8zmp9cEGtWHnlofQ%3d%3d | unknown | — | — | whitelisted |
— | — | GET | 206 | 2.18.121.16:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/f0a82376-a390-4752-ab77-2cdbdcb1da8a?P1=1744828617&P2=404&P3=2&P4=gFfG6UEeMHUpDErwtZyR7%2bghyXw8s5uRzYOvwWVlzkAUcs9aLLGM12CrbnNA4dwjAQdse%2b8zmp9cEGtWHnlofQ%3d%3d | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAyOeKovh9FA7EPQdwurqDQ%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 104.124.11.58:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
2104 | svchost.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 239.255.255.250:1900 | — | — | — | whitelisted |
— | — | 150.171.28.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 13.107.253.45:443 | edge-mobile-static.azureedge.net | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 163.181.131.232:443 | www.lastwar.com | — | US | unknown |
Domain | IP | Reputation |
---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.lastwar.com |
| unknown |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
edge-mobile-static.azureedge.net |
| whitelisted |
business.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
bzib.nelreports.net |
| whitelisted |
xpaywalletcdn.azureedge.net |
| whitelisted |