File name:

Clash of Clans Gem Hack.exe

Full analysis: https://app.any.run/tasks/ab5528af-44bd-4183-a28f-604a96e3e2b1
Verdict: Malicious activity
Analysis date: April 09, 2025, 14:30:52
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
python
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 7 sections
MD5:

0A684AE01B16B1158858933DC878CC75

SHA1:

7EF681159CA9F60E16601156A16CC3A5340C3277

SHA256:

AAE2F5B69D63E10DC09409EB89A2864DC8994AA35FC9DB50B08600A5952C4B30

SSDEEP:

98304:sxb2nfvvqeLnc1ZaDPHUFK/uXbQx2Uc9XLDbenkuA83wpYp2twryIUwt0LQ3FaHb:CKVydTyMNUfF4939W

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Clash of Clans Gem Hack.exe (PID: 7316)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Clash of Clans Gem Hack.exe (PID: 7252)
    • The process drops C-runtime libraries

      • Clash of Clans Gem Hack.exe (PID: 7252)
    • Process drops python dynamic module

      • Clash of Clans Gem Hack.exe (PID: 7252)
    • Executing commands from a ".bat" file

      • Clash of Clans Gem Hack.exe (PID: 7316)
    • Loads Python modules

      • Clash of Clans Gem Hack.exe (PID: 7316)
    • Starts CMD.EXE for commands execution

      • Clash of Clans Gem Hack.exe (PID: 7316)
    • Likely accesses (executes) a file from the Public directory

      • attrib.exe (PID: 7416)
      • attrib.exe (PID: 7392)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 7628)
    • Process drops legitimate windows executable

      • Clash of Clans Gem Hack.exe (PID: 7252)
    • Uses ATTRIB.EXE to modify file attributes

      • Clash of Clans Gem Hack.exe (PID: 7316)
    • Application launched itself

      • Clash of Clans Gem Hack.exe (PID: 7252)
  • INFO

    • Reads the computer name

      • Clash of Clans Gem Hack.exe (PID: 7252)
    • Checks supported languages

      • Clash of Clans Gem Hack.exe (PID: 7316)
      • Clash of Clans Gem Hack.exe (PID: 7252)
    • The sample compiled with english language support

      • Clash of Clans Gem Hack.exe (PID: 7252)
    • Create files in a temporary directory

      • Clash of Clans Gem Hack.exe (PID: 7252)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:04:09 14:25:37+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.42
CodeSize: 178688
InitializedDataSize: 153600
UninitializedDataSize: -
EntryPoint: 0xc380
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
7
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start clash of clans gem hack.exe conhost.exe no specs clash of clans gem hack.exe attrib.exe no specs attrib.exe no specs cmd.exe no specs timeout.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
7252"C:\Users\admin\AppData\Local\Temp\Clash of Clans Gem Hack.exe" C:\Users\admin\AppData\Local\Temp\Clash of Clans Gem Hack.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\clash of clans gem hack.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7260\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeClash of Clans Gem Hack.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7316"C:\Users\admin\AppData\Local\Temp\Clash of Clans Gem Hack.exe" C:\Users\admin\AppData\Local\Temp\Clash of Clans Gem Hack.exe
Clash of Clans Gem Hack.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\clash of clans gem hack.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7392attrib +H C:\\Users\\Public\\Documents\\system32_update.pywC:\Windows\System32\attrib.exeClash of Clans Gem Hack.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Attribute Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\attrib.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
7416attrib +H C:\\Users\\Public\\Music\\audio_driver_updater.pywC:\Windows\System32\attrib.exeClash of Clans Gem Hack.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Attribute Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\attrib.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
7628cmd /c C:\Users\admin\AppData\Local\Temp\cleanup.batC:\Windows\System32\cmd.exeClash of Clans Gem Hack.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
7652timeout /t 2 /nobreak C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
114
Read events
112
Write events
2
Delete events
0

Modification events

(PID) Process:(7316) Clash of Clans Gem Hack.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:SystemUpdate
Value:
"C:\Users\admin\AppData\Local\Temp\Clash of Clans Gem Hack.exe" "C:\\Users\\Public\\Documents\\system32_update.pyw"
(PID) Process:(7316) Clash of Clans Gem Hack.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:AudioDriver
Value:
"C:\Users\admin\AppData\Local\Temp\Clash of Clans Gem Hack.exe" "C:\\Users\\Public\\Music\\audio_driver_updater.pyw"
Executable files
53
Suspicious files
1
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
7252Clash of Clans Gem Hack.exeC:\Users\admin\AppData\Local\Temp\_MEI72522\api-ms-win-core-fibers-l1-1-0.dllexecutable
MD5:B5E2760C5A46DBEB8AE18C75F335707E
SHA256:91D249D7BC0E38EF6BCB17158B1FDC6DD8888DC086615C9B8B750B87E52A5FB3
7252Clash of Clans Gem Hack.exeC:\Users\admin\AppData\Local\Temp\_MEI72522\_decimal.pydexecutable
MD5:F465C15E7BACEAC920DC58A5FB922C1C
SHA256:F4A486A0CA6A53659159A404614C7E7EDCCB6BFBCDEB844F6CEE544436A826CB
7252Clash of Clans Gem Hack.exeC:\Users\admin\AppData\Local\Temp\_MEI72522\api-ms-win-core-fibers-l1-1-1.dllexecutable
MD5:050A30A687E7A2FA6F086A0DB89AA131
SHA256:FC9D86CEC621383EAB636EBC87DDD3F5C19A3CB2A33D97BE112C051D0B275429
7252Clash of Clans Gem Hack.exeC:\Users\admin\AppData\Local\Temp\_MEI72522\_hashlib.pydexecutable
MD5:CF4120BAD9A7F77993DD7A95568D83D7
SHA256:14765E83996FE6D50AEDC11BB41D7C427A3E846A6A6293A4A46F7EA7E3F14148
7252Clash of Clans Gem Hack.exeC:\Users\admin\AppData\Local\Temp\_MEI72522\_lzma.pydexecutable
MD5:3E73BC69EFB418E76D38BE5857A77027
SHA256:6F48E7EBA363CB67F3465A6C91B5872454B44FC30B82710DFA4A4489270CE95C
7252Clash of Clans Gem Hack.exeC:\Users\admin\AppData\Local\Temp\_MEI72522\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:226A5983AE2CBBF0C1BDA85D65948ABC
SHA256:591358EB4D1531E9563EE0813E4301C552CE364C912CE684D16576EABF195DC3
7252Clash of Clans Gem Hack.exeC:\Users\admin\AppData\Local\Temp\_MEI72522\api-ms-win-core-file-l1-1-0.dllexecutable
MD5:9F45A47EBFD9D0629F4935764243DD5A
SHA256:1CA895ABA4E7435563A6B43E85EBA67A0F8C74AA6A6A94D0FC48FA35535E2585
7252Clash of Clans Gem Hack.exeC:\Users\admin\AppData\Local\Temp\_MEI72522\_bz2.pydexecutable
MD5:057325E89B4DB46E6B18A52D1A691CAA
SHA256:5BA872CAA7FCEE0F4FB81C6E0201CEED9BD92A3624F16828DD316144D292A869
7252Clash of Clans Gem Hack.exeC:\Users\admin\AppData\Local\Temp\_MEI72522\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:C2F8C03ECCE9941492BFBE4B82F7D2D5
SHA256:D56CE7B1CD76108AD6C137326EC694A14C99D48C3D7B0ACE8C3FF4D9BCEE3CE8
7252Clash of Clans Gem Hack.exeC:\Users\admin\AppData\Local\Temp\_MEI72522\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:8F8EB9CB9E78E3A611BC8ACAEC4399CB
SHA256:1BD81DFD19204B44662510D9054852FB77C9F25C1088D647881C9B976CC16818
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
15
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7864
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7864
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2112
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
7864
SIHClient.exe
4.175.87.197:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7864
SIHClient.exe
2.16.253.202:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.159.0
  • 20.190.159.130
  • 40.126.31.0
  • 20.190.159.23
  • 40.126.31.129
  • 40.126.31.131
  • 40.126.31.1
  • 20.190.159.129
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
www.microsoft.com
  • 2.16.253.202
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
activation-v2.sls.microsoft.com
whitelisted

Threats

No threats detected
No debug info