File name:

CheatEngine561.exe

Full analysis: https://app.any.run/tasks/e61b1ffb-b3dd-469c-87ad-ff55b478998d
Verdict: Malicious activity
Analysis date: November 14, 2023, 19:56:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

3B659E1EF1E544856A716433A17DA61F

SHA1:

92C332A025753F94E0339B82EBE0E54AD3CEC7BD

SHA256:

9E88E7CE1AC737D3B5DFA7B7D972B0D47468AE74843974414D64635CE3400936

SSDEEP:

98304:sSkC9fWDZvJAxpbXl4NIumjgG1dGtZeyA1dg8CRRlk54snKZ0DoNy+XQvGgouStB:6eukNP7T0/9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • CheatEngine561.exe (PID: 3416)
      • CheatEngine561.exe (PID: 3472)
      • CheatEngine561.tmp (PID: 3524)
    • Creates a writable file the system directory

      • CheatEngine561.tmp (PID: 3524)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • CheatEngine561.tmp (PID: 3524)
    • Process drops legitimate windows executable

      • CheatEngine561.tmp (PID: 3524)
    • Reads the Internet Settings

      • CheatEngine561.tmp (PID: 3524)
    • Drops a system driver (possible attempt to evade defenses)

      • CheatEngine561.tmp (PID: 3524)
  • INFO

    • Create files in a temporary directory

      • CheatEngine561.exe (PID: 3416)
      • CheatEngine561.exe (PID: 3472)
      • CheatEngine561.tmp (PID: 3524)
    • Checks supported languages

      • CheatEngine561.exe (PID: 3416)
      • CheatEngine561.tmp (PID: 3128)
      • CheatEngine561.exe (PID: 3472)
      • CheatEngine561.tmp (PID: 3524)
    • Reads the computer name

      • CheatEngine561.tmp (PID: 3128)
      • CheatEngine561.tmp (PID: 3524)
    • Checks proxy server information

      • CheatEngine561.tmp (PID: 3524)
    • Reads the machine GUID from the registry

      • CheatEngine561.tmp (PID: 3524)
    • Creates files in the program directory

      • CheatEngine561.tmp (PID: 3524)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0x9b24
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Dark Byte
FileDescription: Cheat Engine 5.6.1 Setup
FileVersion:
LegalCopyright:
ProductName: Cheat Engine 5.6.1
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
4
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cheatengine561.exe no specs cheatengine561.tmp no specs cheatengine561.exe cheatengine561.tmp no specs

Process information

PID
CMD
Path
Indicators
Parent process
3128"C:\Users\admin\AppData\Local\Temp\is-TSETI.tmp\CheatEngine561.tmp" /SL5="$60134,4411123,54272,C:\Users\admin\AppData\Local\Temp\CheatEngine561.exe" C:\Users\admin\AppData\Local\Temp\is-TSETI.tmp\CheatEngine561.tmpCheatEngine561.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.51.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-tseti.tmp\cheatengine561.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3416"C:\Users\admin\AppData\Local\Temp\CheatEngine561.exe" C:\Users\admin\AppData\Local\Temp\CheatEngine561.exeexplorer.exe
User:
admin
Company:
Dark Byte
Integrity Level:
MEDIUM
Description:
Cheat Engine 5.6.1 Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\cheatengine561.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3472"C:\Users\admin\AppData\Local\Temp\CheatEngine561.exe" /SPAWNWND=$401F4 /NOTIFYWND=$60134 C:\Users\admin\AppData\Local\Temp\CheatEngine561.exe
CheatEngine561.tmp
User:
admin
Company:
Dark Byte
Integrity Level:
HIGH
Description:
Cheat Engine 5.6.1 Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\cheatengine561.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3524"C:\Users\admin\AppData\Local\Temp\is-7VN84.tmp\CheatEngine561.tmp" /SL5="$601F6,4411123,54272,C:\Users\admin\AppData\Local\Temp\CheatEngine561.exe" /SPAWNWND=$401F4 /NOTIFYWND=$60134 C:\Users\admin\AppData\Local\Temp\is-7VN84.tmp\CheatEngine561.tmpCheatEngine561.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.51.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7vn84.tmp\cheatengine561.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
1 736
Read events
1 732
Write events
4
Delete events
0

Modification events

(PID) Process:(3524) CheatEngine561.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3524) CheatEngine561.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3524) CheatEngine561.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
(PID) Process:(3524) CheatEngine561.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Cheat Engine\OpenCandy
Operation:writeName:VOCV
Value:
0
Executable files
53
Suspicious files
27
Text files
186
Unknown types
0

Dropped files

PID
Process
Filename
Type
3524CheatEngine561.tmpC:\Users\admin\AppData\Local\Temp\is-MA3BN.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3472CheatEngine561.exeC:\Users\admin\AppData\Local\Temp\is-7VN84.tmp\CheatEngine561.tmpexecutable
MD5:CE4E0FF83AC2A3256FD5C220562294A1
SHA256:130EC61D37B76FA26A4C7EBCF210467C5BE3AE2ACE7346546C65F093478BB06B
3524CheatEngine561.tmpC:\Program Files\Cheat Engine\Cheat Engine.exeexecutable
MD5:73B1CAE872B35664BD475FC6F4683F43
SHA256:4058B6D4BDEC1F786893DB89A5D5D4F5450FDED7317090E8F5C0E700D2FE419C
3524CheatEngine561.tmpC:\Users\admin\AppData\Local\Temp\is-MA3BN.tmp\OCSetupHlp.dllexecutable
MD5:602BB41454775C49B50E739746D2DED1
SHA256:8FCA7BD9A6836DF00AA71B4E07A6B4032F7442A4C0B76CE4E5046C13E089932B
3524CheatEngine561.tmpC:\Program Files\Cheat Engine\is-MSAHP.tmpexecutable
MD5:F292769A769443CB7E5665E0086C032F
SHA256:B81B621627D652510779539B352C93B85697E6EA67F071F26DA75C8AE752FF31
3524CheatEngine561.tmpC:\Program Files\Cheat Engine\is-SU1LA.tmpexecutable
MD5:73B1CAE872B35664BD475FC6F4683F43
SHA256:4058B6D4BDEC1F786893DB89A5D5D4F5450FDED7317090E8F5C0E700D2FE419C
3524CheatEngine561.tmpC:\Program Files\Cheat Engine\unins000.exeexecutable
MD5:F292769A769443CB7E5665E0086C032F
SHA256:B81B621627D652510779539B352C93B85697E6EA67F071F26DA75C8AE752FF31
3524CheatEngine561.tmpC:\Program Files\Cheat Engine\vmdisk.imgbinary
MD5:ED8E992E60B779A9DA88ECD83345B7CC
SHA256:B08F461CCBF45922A1CAEA50394A57B5C6E654BBD6BBD3C2FD04F76CEFCDBFE2
3524CheatEngine561.tmpC:\Program Files\Cheat Engine\dbghelp.dllexecutable
MD5:4003E34416EBD25E4C115D49DC15E1A7
SHA256:C06430B8CB025BE506BE50A756488E1BCC3827C4F45158D93E4E3EEB98CE1E4F
3524CheatEngine561.tmpC:\Program Files\Cheat Engine\is-3E2S3.tmpexecutable
MD5:3A35FC14DC9A9F96533A671BC85144DB
SHA256:30635BC731BF6256824772909BAF6FABD34E5789E999A46E6A27094E506C95D8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

Domain
IP
Reputation
api.opencandy.com
unknown

Threats

No threats detected
No debug info