| File name: | CSHacked PhasmoMenu v0.5.1.2.exe |
| Full analysis: | https://app.any.run/tasks/864d8471-6f28-4638-8050-ef80bb4c1f55 |
| Verdict: | Malicious activity |
| Analysis date: | October 29, 2023, 07:08:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 6443B68B8BB0DB8101EDCD130A63156D |
| SHA1: | 563434D726A04B92F9988F2D00FF11FB5B9F9D74 |
| SHA256: | E1B2F2BAAF02375E4B629306C3B70FC8B129FC60E1A283A1601A2566B38DADA7 |
| SSDEEP: | 98304:iiKP1/o0/95cOv/3SGLThacuRZDXjljIsPELCuEv2/8CZFhEim+EtJM+E8F77Pa8:Is2VPWETncoaYP |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2013:06:28 16:45:44+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 36352 |
| InitializedDataSize: | 7505408 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x15eb |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1396 | "C:\Users\admin\AppData\Local\Temp\CSHacked PhasmoMenu v0.5.1.2.exe" | C:\Users\admin\AppData\Local\Temp\CSHacked PhasmoMenu v0.5.1.2.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1484 | "C:\Users\admin\AppData\Local\Temp\CSHacked PhasmoMenu v0.5.1.2.exe" | C:\Users\admin\AppData\Local\Temp\CSHacked PhasmoMenu v0.5.1.2.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1768 | "C:\Users\admin\AppData\Local\Temp\cetrainers\CETB37F.tmp\CSHacked PhasmoMenu v0.5.1.2.exe" -ORIGIN:"C:\Users\admin\AppData\Local\Temp\" | C:\Users\admin\AppData\Local\Temp\cetrainers\CETB37F.tmp\CSHacked PhasmoMenu v0.5.1.2.exe | — | CSHacked PhasmoMenu v0.5.1.2.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1484 | CSHacked PhasmoMenu v0.5.1.2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETB37F.tmp\CET_Archive.dat | — | |
MD5:— | SHA256:— | |||
| 1768 | CSHacked PhasmoMenu v0.5.1.2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETB37F.tmp\extracted\autorun\luasymbols.lua | text | |
MD5:DF4D243AB0407A1F03CCF448232FCF62 | SHA256:C5A35380AF8BEBE96B85377F5F41F8C068CB857C74B9CB85B7467B35C1DE10C4 | |||
| 1768 | CSHacked PhasmoMenu v0.5.1.2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETB37F.tmp\extracted\CET_TRAINER.CETRAINER | binary | |
MD5:8D45E90470D55C3C29ADE4EB6E8EE3AA | SHA256:648823E4D7E4B40A7B137418D73F8B33422F4B89DB7A20C17689F62E1428E458 | |||
| 1768 | CSHacked PhasmoMenu v0.5.1.2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETB37F.tmp\extracted\defines.lua | text | |
MD5:62E1FA241D417668F7C5DA6E4009A5A6 | SHA256:82E8EF7DF20A86791CEF062F2DCACB1D91B4ADC9F5DEA2FD274886BE8365B2F8 | |||
| 1484 | CSHacked PhasmoMenu v0.5.1.2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETB37F.tmp\CSHacked PhasmoMenu v0.5.1.2.exe | executable | |
MD5:971B37CEDF686E0AC8CA0297A953AAD9 | SHA256:1965546A19990B4523A1588EB0D7FDD42BD443E2BCC632DAE04343D358394AE7 | |||
| 1768 | CSHacked PhasmoMenu v0.5.1.2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETB37F.tmp\extracted\CSHacked PhasmoMenu v0.5.1.2.exe | executable | |
MD5:EDEEF697CBF212B5ECFCD9C1D9A8803D | SHA256:AC9BCC7813C0063BDCD36D8E4E79A59B22F6E95C2D74C65A4249C7D5319AE3F6 | |||
| 1768 | CSHacked PhasmoMenu v0.5.1.2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETB37F.tmp\extracted\lua53-64.dll | executable | |
MD5:B7C9F1E7E640F1A034BE84AF86970D45 | SHA256:6D0A06B90213F082CB98950890518C0F08B9FC16DBFAB34D400267CB6CDADEFF | |||
| 1768 | CSHacked PhasmoMenu v0.5.1.2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETB37F.tmp\extracted\autorun\forms\MonoDataCollector.frm | xml | |
MD5:03D4DD46084BCBE16A39D72BA22E5446 | SHA256:4F254BBC897AD0E165986D18577E0A04FD31C93CCA542A0999FA0093EDC5BC61 | |||
| 1768 | CSHacked PhasmoMenu v0.5.1.2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETB37F.tmp\extracted\autorun\dlls\MonoDataCollector32.dll | executable | |
MD5:C5B870CE07DA5206D8A81E139920B7DC | SHA256:EB26B38A604CF98B95A39FD249C0771E351061A9894D22284CDFE984E8FC7A6C | |||
| 1768 | CSHacked PhasmoMenu v0.5.1.2.exe | C:\Users\admin\AppData\Local\Temp\cetrainers\CETB37F.tmp\extracted\autorun\dlls\MonoDataCollector64.dll | executable | |
MD5:4237719534B21BB179480ED8BB23C0CC | SHA256:15EE5851FF1B33E369B43C66D44E3D1452A212C2A37F337B680FE8BD88DF8748 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |