Overview
overview
3Static
static
3Roblox Aim...le.vbs
windows11-21h2-x64
1Roblox Aim...ry.vbs
windows11-21h2-x64
1Roblox Aim...us.vbs
windows11-21h2-x64
1Roblox Aim...er.vbs
windows11-21h2-x64
1Roblox Aim...st.vbs
windows11-21h2-x64
1Roblox Aim...ox.vbs
windows11-21h2-x64
1Roblox Aim...et.vbs
windows11-21h2-x64
1Roblox Aim...nu.vbs
windows11-21h2-x64
1Roblox Aim...nc.ps1
windows11-21h2-x64
3Roblox Aim...ox.vbs
windows11-21h2-x64
1Roblox Aim...te.vbs
windows11-21h2-x64
1Roblox Aim...tk.vbs
windows11-21h2-x64
1Roblox Aim...ox.vbs
windows11-21h2-x64
1Roblox Aim...xt.vbs
windows11-21h2-x64
1Roblox Aim...tk.vbs
windows11-21h2-x64
1Roblox Aim...ox.vbs
windows11-21h2-x64
1Roblox Aim...rs.vbs
windows11-21h2-x64
1Roblox Aim...ry.vbs
windows11-21h2-x64
1Roblox Aim...on.vbs
windows11-21h2-x64
1Roblox Aim...ew.vbs
windows11-21h2-x64
1Roblox Aim...tk.vbs
windows11-21h2-x64
1Roblox Aim...ox.vbs
windows11-21h2-x64
1Roblox Aim...6t.dll
windows11-21h2-x64
1Roblox Aim...se.dll
windows11-21h2-x64
1Roblox Aim...ta.dll
windows11-21h2-x64
1Roblox Aim...pi.dll
windows11-21h2-x64
1Roblox Aim...ui.dll
windows11-21h2-x64
1Roblox Aim...dh.dll
windows11-21h2-x64
1Roblox Aim...64.dll
windows11-21h2-x64
1Roblox Aim...b1.dll
windows11-21h2-x64
1Roblox Aim...ot.exe
windows11-21h2-x64
1Roblox Aim...nds.py
windows11-21h2-x64
3Resubmissions
30-06-2024 17:31
240630-v3n95a1fja 3Analysis
-
max time kernel
141s -
max time network
96s -
platform
windows11-21h2_x64 -
resource
win11-20240611-en -
resource tags
arch:x64arch:x86image:win11-20240611-enlocale:en-usos:windows11-21h2-x64system -
submitted
30-06-2024 17:31
Behavioral task
behavioral1
Sample
Roblox Aimbot UD/_internal/tk/console.vbs
Resource
win11-20240611-en
Behavioral task
behavioral2
Sample
Roblox Aimbot UD/_internal/tk/entry.vbs
Resource
win11-20240611-en
Behavioral task
behavioral3
Sample
Roblox Aimbot UD/_internal/tk/focus.vbs
Resource
win11-20240611-en
Behavioral task
behavioral4
Sample
Roblox Aimbot UD/_internal/tk/fontchooser.vbs
Resource
win11-20240508-en
Behavioral task
behavioral5
Sample
Roblox Aimbot UD/_internal/tk/iconlist.vbs
Resource
win11-20240508-en
Behavioral task
behavioral6
Sample
Roblox Aimbot UD/_internal/tk/listbox.vbs
Resource
win11-20240419-en
Behavioral task
behavioral7
Sample
Roblox Aimbot UD/_internal/tk/megawidget.vbs
Resource
win11-20240508-en
Behavioral task
behavioral8
Sample
Roblox Aimbot UD/_internal/tk/menu.vbs
Resource
win11-20240611-en
Behavioral task
behavioral9
Sample
Roblox Aimbot UD/_internal/tk/mkpsenc.ps1
Resource
win11-20240611-en
Behavioral task
behavioral10
Sample
Roblox Aimbot UD/_internal/tk/msgbox.vbs
Resource
win11-20240611-en
Behavioral task
behavioral11
Sample
Roblox Aimbot UD/_internal/tk/palette.vbs
Resource
win11-20240611-en
Behavioral task
behavioral12
Sample
Roblox Aimbot UD/_internal/tk/safetk.vbs
Resource
win11-20240508-en
Behavioral task
behavioral13
Sample
Roblox Aimbot UD/_internal/tk/spinbox.vbs
Resource
win11-20240611-en
Behavioral task
behavioral14
Sample
Roblox Aimbot UD/_internal/tk/text.vbs
Resource
win11-20240611-en
Behavioral task
behavioral15
Sample
Roblox Aimbot UD/_internal/tk/tk.vbs
Resource
win11-20240508-en
Behavioral task
behavioral16
Sample
Roblox Aimbot UD/_internal/tk/tkfbox.vbs
Resource
win11-20240508-en
Behavioral task
behavioral17
Sample
Roblox Aimbot UD/_internal/tk/ttk/cursors.vbs
Resource
win11-20240419-en
Behavioral task
behavioral18
Sample
Roblox Aimbot UD/_internal/tk/ttk/entry.vbs
Resource
win11-20240508-en
Behavioral task
behavioral19
Sample
Roblox Aimbot UD/_internal/tk/ttk/menubutton.vbs
Resource
win11-20240611-en
Behavioral task
behavioral20
Sample
Roblox Aimbot UD/_internal/tk/ttk/treeview.vbs
Resource
win11-20240611-en
Behavioral task
behavioral21
Sample
Roblox Aimbot UD/_internal/tk/ttk/ttk.vbs
Resource
win11-20240611-en
Behavioral task
behavioral22
Sample
Roblox Aimbot UD/_internal/tk/xmfbox.vbs
Resource
win11-20240611-en
Behavioral task
behavioral23
Sample
Roblox Aimbot UD/_internal/tk86t.dll
Resource
win11-20240508-en
Behavioral task
behavioral24
Sample
Roblox Aimbot UD/_internal/ucrtbase.dll
Resource
win11-20240508-en
Behavioral task
behavioral25
Sample
Roblox Aimbot UD/_internal/unicodedata.dll
Resource
win11-20240508-en
Behavioral task
behavioral26
Sample
Roblox Aimbot UD/_internal/win32/win32api.dll
Resource
win11-20240611-en
Behavioral task
behavioral27
Sample
Roblox Aimbot UD/_internal/win32/win32gui.dll
Resource
win11-20240611-en
Behavioral task
behavioral28
Sample
Roblox Aimbot UD/_internal/win32/win32pdh.dll
Resource
win11-20240508-en
Behavioral task
behavioral29
Sample
Roblox Aimbot UD/_internal/yaml/_yaml.cp312-win_amd64.dll
Resource
win11-20240611-en
Behavioral task
behavioral30
Sample
Roblox Aimbot UD/_internal/zlib1.dll
Resource
win11-20240508-en
Behavioral task
behavioral31
Sample
Roblox Aimbot UD/aimbot.exe
Resource
win11-20240611-en
Behavioral task
behavioral32
Sample
Roblox Aimbot UD/keybinds.py
Resource
win11-20240508-en
General
-
Target
Roblox Aimbot UD/aimbot.exe
-
Size
6.8MB
-
MD5
ac7ecf7be597f995702d9fef9c8417e7
-
SHA1
3edd520d786e7c2d93bebdeb9faec5d1e0df0d90
-
SHA256
31e9202417bf78b6bd78a29dd3a483896bab7fd108974e1c28e7eee4c2edd397
-
SHA512
9a6a069749004b64afc270dbd77482a0099bea764e1b008b7a08a8f543c8522adef977376a89ffed45e6568af3cb5a47040a14c94c3095601363927bd28a0ce2
-
SSDEEP
196608:WHKmw30l64nzubQbXGy7887vahw2AYVrEQDVu:WHocabAG4vSwoWaVu
Malware Config
Signatures
-
Suspicious use of SetWindowsHookEx 1 IoCs
Processes:
aimbot.exepid process 4556 aimbot.exe -
Suspicious use of WriteProcessMemory 4 IoCs
Processes:
aimbot.exedescription pid process target process PID 4556 wrote to memory of 3412 4556 aimbot.exe cmd.exe PID 4556 wrote to memory of 3412 4556 aimbot.exe cmd.exe PID 4556 wrote to memory of 3384 4556 aimbot.exe cmd.exe PID 4556 wrote to memory of 3384 4556 aimbot.exe cmd.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\Roblox Aimbot UD\aimbot.exe"C:\Users\Admin\AppData\Local\Temp\Roblox Aimbot UD\aimbot.exe"1⤵
- Suspicious use of SetWindowsHookEx
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\cmd.exeC:\Windows\system32\cmd.exe /c title Colorbot2⤵
-
C:\Windows\system32\cmd.exeC:\Windows\system32\cmd.exe /c cls2⤵