analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Simple CSGO Essentials.exe

Full analysis: https://app.any.run/tasks/82fe4379-1a24-4c97-933a-f65080fdbe31
Verdict: Malicious activity
Analysis date: April 25, 2019, 15:47:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

D7F64998A0674309A0EF0E183D78288F

SHA1:

7608A46F693BABFD59507CB7ABBE5CDE9E7B91A3

SHA256:

D27B123B772935EA85A31CCEB5585C3ADDC26A4CBE3672DA313FE471447A7B83

SSDEEP:

3072:VmmRiilxLXS7bBeniD7BlgZRiJQG6O87RRJrHFjSRuaZFM84oGT9bWoN4:XHldiReiD7BlgZRivojHFgZNN7oN4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • Simple CSGO Essentials.exe (PID: 2480)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

ProductVersion: 2.9.9.9
ProductName: Simple CSGO Essentials
OriginalFileName: Simple CSGO Essentials.exe
LegalCopyright: Sandwich (CSGO Essentials) © 2019
InternalName: Simple CSGO Essentials.exe
FileVersion: 2.9.9.9
CompanyName: CSGO Essentials
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 2.9.9.9
FileVersionNumber: 2.9.9.9
Subsystem: Windows command line
SubsystemVersion: 6
ImageVersion: -
OSVersion: 6
EntryPoint: 0x1c722
UninitializedDataSize: -
InitializedDataSize: 342528
CodeSize: 127488
LinkerVersion: 14.2
PEType: PE32
TimeStamp: 2019:04:23 18:34:45+02:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date: 23-Apr-2019 16:34:45
Detected languages:
  • English - United States
Debug artifacts:
  • C:\Users\Zach\Desktop\CS\Simple CSGO Essentials\Release\Simple CSGO Essentials.pdb
CompanyName: CSGO Essentials
FileVersion: 2.9.9.9
InternalName: Simple CSGO Essentials.exe
LegalCopyright: Sandwich (CSGO Essentials) © 2019
OriginalFilename: Simple CSGO Essentials.exe
ProductName: Simple CSGO Essentials
ProductVersion: 2.9.9.9

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 23-Apr-2019 16:34:45
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0001F1DF
0x0001F200
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.2576
.rdata
0x00021000
0x00007556
0x00007600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.38584
.data
0x00029000
0x0000216C
0x00000600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.03427
.rsrc
0x0002C000
0x00046308
0x00046400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.31933
.reloc
0x00073000
0x00003D50
0x00003E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.79482

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.89623
392
UNKNOWN
English - United States
RT_MANIFEST
2
5.40811
2440
UNKNOWN
English - United States
RT_ICON
3
5.20404
4264
UNKNOWN
English - United States
RT_ICON
4
4.72369
9640
UNKNOWN
English - United States
RT_ICON
5
4.22478
268300
UNKNOWN
English - United States
RT_ICON
101
2.81386
76
UNKNOWN
English - United States
RT_GROUP_ICON

Imports

KERNEL32.dll
MSVCP140.dll
SHELL32.dll
USER32.dll
VCRUNTIME140.dll
api-ms-win-crt-filesystem-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
108
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start simple csgo essentials.exe no specs simple csgo essentials.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3296"C:\Users\admin\AppData\Local\Temp\Simple CSGO Essentials.exe" C:\Users\admin\AppData\Local\Temp\Simple CSGO Essentials.exeexplorer.exe
User:
admin
Company:
CSGO Essentials
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
2.9.9.9
2480"C:\Users\admin\AppData\Local\Temp\Simple CSGO Essentials.exe" C:\Users\admin\AppData\Local\Temp\Simple CSGO Essentials.exe
explorer.exe
User:
admin
Company:
CSGO Essentials
Integrity Level:
HIGH
Version:
2.9.9.9
3072C:\Windows\system32\cmd.exe /c clsC:\Windows\system32\cmd.exeSimple CSGO Essentials.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2104C:\Windows\system32\cmd.exe /c clsC:\Windows\system32\cmd.exeSimple CSGO Essentials.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2940C:\Windows\system32\cmd.exe /c clsC:\Windows\system32\cmd.exeSimple CSGO Essentials.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2032C:\Windows\system32\cmd.exe /c clsC:\Windows\system32\cmd.exeSimple CSGO Essentials.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
404C:\Windows\system32\cmd.exe /c clsC:\Windows\system32\cmd.exeSimple CSGO Essentials.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2368C:\Windows\system32\cmd.exe /c clsC:\Windows\system32\cmd.exeSimple CSGO Essentials.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2936C:\Windows\system32\cmd.exe /c clsC:\Windows\system32\cmd.exeSimple CSGO Essentials.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2504C:\Windows\system32\cmd.exe /c clsC:\Windows\system32\cmd.exeSimple CSGO Essentials.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Total events
630
Read events
630
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
1
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
2480Simple CSGO Essentials.exeC:\Users\admin\AppData\Local\Temp\Glow.txttext
MD5:F44D1EEBC27D10A468AC117A2963C203
SHA256:6DE0E5A2206CF3D01A139D832812966B9EA482A7FFA776BAF53EC5E5CEDE09BB
2480Simple CSGO Essentials.exeC:\Users\admin\AppData\Local\Temp\Aimbot.txttext
MD5:A0B45124568CA04DC93F92FD0E3ABB6C
SHA256:5F3D554209E9118C363390FE8E096A18E6B5E4270A12573CEE9AA42637557E0E
2480Simple CSGO Essentials.exeC:\Users\admin\AppData\Local\Temp\Hotkey Layout.txttext
MD5:C67033B57B8BE9198E05A9162EBE9FA8
SHA256:38D9CFCE06656C3B3276CDEFEA08FC55FA38EC467329541DDE7AAFC653A90113
2480Simple CSGO Essentials.exeC:\Users\admin\AppData\Local\Temp\Misc.txttext
MD5:2E991048F08C706E0CBD758886571723
SHA256:5D1B0B0A0360B568DF0AD869D587FAB8074426443BA7B1E38567DC285C93DAD6
2480Simple CSGO Essentials.exeC:\Users\admin\AppData\Local\Temp\Chams.txtbinary
MD5:38E8A7EE7417ECB43D31586131CBF5A1
SHA256:98DC309D77A685AA8B129C258FBFEB909986EC9C54EE3240CBF5FB4C3D6E3AB4
2480Simple CSGO Essentials.exeC:\Users\admin\AppData\Local\Temp\Skinchanger.txttext
MD5:CBF7A21CD3C9BE6DDED5E0AFD2AE2D91
SHA256:E72CD115AFA48DB1D0EADDB63C2C108CF7C21767D9E3B99E3A20A6AA11FD2C1F
2480Simple CSGO Essentials.exeC:\Users\admin\AppData\Local\Temp\Triggerbot.txttext
MD5:CCB75131CADFAC46F541E4D772C2B7B0
SHA256:96295B3657FE6FF53D4E33991993BAA37916928F3BE5C807AC8BE87D87E1C524
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info