File name:

Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe

Full analysis: https://app.any.run/tasks/039c003b-80a0-4139-a927-4e45754adb7b
Verdict: Malicious activity
Analysis date: June 29, 2025, 00:50:57
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
github
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 9 sections
MD5:

B512457D716D1473DCE880D473A31C9E

SHA1:

1FD74813198BCACFE614519493ECC5778B62F248

SHA256:

C9D418A98346CFF783B18D248E88D6E4312F0A07D40E6EEE7348E7AB8DD43595

SSDEEP:

98304:ZhuDfZ52Bir65ew6CEjJc7vNGNeYX2SmhyUFOwdhrXki+iJwewJinjXYtPEUMajr:bsrMJwmICk9gQYAqk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe (PID: 440)
      • Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe (PID: 2160)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe (PID: 2160)
    • There is functionality for taking screenshot (YARA)

      • Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe (PID: 2160)
  • INFO

    • Creates files or folders in the user directory

      • Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe (PID: 2160)
    • Reads the machine GUID from the registry

      • Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe (PID: 2160)
    • Reads the computer name

      • Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe (PID: 2160)
    • Checks supported languages

      • Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe (PID: 2160)
    • Checks proxy server information

      • Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe (PID: 2160)
    • Reads the software policy settings

      • Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe (PID: 2160)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:09:15 16:32:59+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 11013120
InitializedDataSize: 5287424
UninitializedDataSize: -
EntryPoint: 0xa56f95
OSVersion: 6
ImageVersion: 1.6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.6.0.0
ProductVersionNumber: 1.6.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Process default
CharacterSet: Unicode
CompanyName: PlayGround.ru & Nexus Mods
FileDescription: Trainer +44 for Far Cry 3 [1.05-1.06] by hex
FileVersion: 1.6
InternalName: Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
LegalCopyright: Copyright (C) 2024 hex (PlayGround.ru & Nexus Mods)
OriginalFileName: Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
ProductName: Far Cry 3 Trainer (+44) [1.05-1.06 Steam/Ubisoft Connect] by hex
ProductVersion: 1.6
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
3
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start far cry 3 trainer (+44) [1.05-1.06] {hex}.exe slui.exe no specs far cry 3 trainer (+44) [1.05-1.06] {hex}.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
440"C:\Users\admin\AppData\Local\Temp\Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe" C:\Users\admin\AppData\Local\Temp\Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exeexplorer.exe
User:
admin
Company:
PlayGround.ru & Nexus Mods
Integrity Level:
MEDIUM
Description:
Trainer +44 for Far Cry 3 [1.05-1.06] by hex
Exit code:
3221226540
Version:
1.6
Modules
Images
c:\users\admin\appdata\local\temp\far cry 3 trainer (+44) [1.05-1.06] {hex}.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2136C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2160"C:\Users\admin\AppData\Local\Temp\Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe" C:\Users\admin\AppData\Local\Temp\Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
explorer.exe
User:
admin
Company:
PlayGround.ru & Nexus Mods
Integrity Level:
HIGH
Description:
Trainer +44 for Far Cry 3 [1.05-1.06] by hex
Version:
1.6
Modules
Images
c:\users\admin\appdata\local\temp\far cry 3 trainer (+44) [1.05-1.06] {hex}.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
851
Read events
848
Write events
3
Delete events
0

Modification events

(PID) Process:(2160) Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2160) Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2160) Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
0
Suspicious files
4
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2160Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exeC:\Users\admin\AppData\Local\PlayGround.ru\hex\Trainers\Data\Public\FC3\Config.initext
MD5:B88B3ABEBDFFD740DB607B249698EC87
SHA256:1EE9B993AFB0E67D16D8AFFAC1282AF10BCB2AA608833E36AC6CDB53BDFCC13E
2160Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exeC:\Users\admin\AppData\Local\PlayGround.ru\hex\Trainers\Settings.initext
MD5:F7123164D6ED61E9364E16DD75172F26
SHA256:1E51D6DAB64768B9B4999EBB816A975C4263B1B1823C97FBBE5538FB5DB4B8EB
2160Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:3F02CE093EDA9E560F5F7456B47005CD
SHA256:4907C5128959C4D5D70FBC1AFA9117A9DD6F80BA09F102883EC3AE923AA4B1DD
2160Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dbinary
MD5:5CB90BCF617A0988692AD5BB6797D670
SHA256:7319E468508BB234C9792DB147436F9E0F9E19DA89FDF56621987C7ADD875860
2160Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\Version[1].txttext
MD5:E2D8DC604425E9B90D80065084B79888
SHA256:12A055B20F6D9A65AC8E14DE10D6F0753C7DB7A1C97FF9F239B8F3CA79627085
2160Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:8A4F2C86E1B4B466F0A61C2AB5905758
SHA256:F1C96FB3417DE1222B9376B29676EFF058A639071F6FEBF53C94B084EA5F5818
2160Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dbinary
MD5:E351068C9354EBBDEB7272E7CBB6B5FF
SHA256:CA1DEBBF130AA57FF6C19F14E7056EA352C20468831BCF0C94BE21BAA6D1C8DC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
26
DNS requests
20
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2160
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
GET
301
185.199.111.133:80
http://raw.githubusercontent.com/xx-hex-xx/Trainers/main/Data/Public/FC3/Version.txt
unknown
whitelisted
2160
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
whitelisted
2160
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
whitelisted
1268
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2464
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4768
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4768
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7092
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2160
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
185.199.111.133:80
raw.githubusercontent.com
FASTLY
US
whitelisted
2160
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
185.199.111.133:443
raw.githubusercontent.com
FASTLY
US
whitelisted
2160
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.174
whitelisted
raw.githubusercontent.com
  • 185.199.111.133
  • 185.199.110.133
  • 185.199.109.133
  • 185.199.108.133
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
login.live.com
  • 40.126.32.72
  • 20.190.160.4
  • 20.190.160.22
  • 20.190.160.66
  • 20.190.160.3
  • 40.126.32.74
  • 20.190.160.14
  • 20.190.160.64
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Process
Message
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
Unknown property font-color
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
libpng warning: iCCP: known incorrect sRGB profile
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
libpng warning: iCCP: known incorrect sRGB profile
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
libpng warning: iCCP: known incorrect sRGB profile
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
libpng warning: iCCP: known incorrect sRGB profile
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
libpng warning: iCCP: known incorrect sRGB profile
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
libpng warning: iCCP: known incorrect sRGB profile
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
libpng warning: iCCP: known incorrect sRGB profile
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
QCssParser::parseColorValue: Specified color with alpha value but no alpha given: 'rgba 65, 105, 225'
Far Cry 3 Trainer (+44) [1.05-1.06] {hex}.exe
Unknown property foreground-color