| File name: | ChessBotX+Turbo.zip |
| Full analysis: | https://app.any.run/tasks/12645848-7878-4ccb-a8cb-e55951e47e98 |
| Verdict: | Malicious activity |
| Analysis date: | November 29, 2023, 09:59:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | B45B4A67864314E4B26FB5CE9D9199BA |
| SHA1: | B61F67CC5F95440080E11BB1BE6C87C682A090F8 |
| SHA256: | 01F4D3836960BBA79A312A7A08B9CB6CC852AB3A4DC442E85569C956CDB17BE6 |
| SSDEEP: | 98304:UMffMP8rdAeWr2VythBhVtS2zXeB03gZ7IZSlDvONSBQsg1D7sFL4BBt32qRHXEQ:0XunvFazFj |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2023:11:19 06:38:08 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | ChessBotX Turbo/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 372 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=28 --mojo-platform-channel-handle=5176 --field-trial-handle=1096,i,4708156025325046769,17496130294960506547,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 732 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=29 --mojo-platform-channel-handle=5300 --field-trial-handle=1096,i,4708156025325046769,17496130294960506547,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 844 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ChessBotX+Turbo.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 952 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3348 --field-trial-handle=1096,i,4708156025325046769,17496130294960506547,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 952 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=30 --mojo-platform-channel-handle=5360 --field-trial-handle=1096,i,4708156025325046769,17496130294960506547,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1236 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=14 --mojo-platform-channel-handle=3948 --field-trial-handle=1096,i,4708156025325046769,17496130294960506547,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1248 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1128 --field-trial-handle=1096,i,4708156025325046769,17496130294960506547,131072 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1436 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1496 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5376 --field-trial-handle=1096,i,4708156025325046769,17496130294960506547,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1728 | "C:\Users\admin\Desktop\ChessBotX Turbo\ChessBotX Turbo.exe" | C:\Users\admin\Desktop\ChessBotX Turbo\ChessBotX Turbo.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1143130765 Modules
| |||||||||||||||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa844.46527\ChessBotX Turbo\Books\GM.book | — | |
MD5:— | SHA256:— | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa844.46527\ChessBotX Turbo\Books\Basic.book | text | |
MD5:A1C8E87C5852D13D050D4DBE08B43A94 | SHA256:6097925BA0DC7280303A1BBAD83F31912E6084F2BADBA859632C6ED2F5EBFA8B | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa844.46527\ChessBotX Turbo\ChessBotX Turbo Key.txt | text | |
MD5:ADBA8CFF0FF0E186BF8513601836F9F8 | SHA256:CDD7BEAB477DFCBDA1BE9D7FCDB22CD66B2F0E03C2DE49762A9DA037FB052FFB | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa844.46527\ChessBotX Turbo\Config\Instant (without delay).cfg | text | |
MD5:F010618E4182AF042A52A43842133D63 | SHA256:BDF694978E13BEBE3E4987D888A119CA76AC36F8ECB5033DD2D6ECE5C42687AE | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa844.46527\ChessBotX Turbo\voiceover\a6.mp3 | mp3 | |
MD5:54C69A2E4BECF27CEF9068F4F656C062 | SHA256:5C0665238AB5A256E5994B5971973F9D94452C280C80CCD20B18C2CB73C83676 | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa844.46527\ChessBotX Turbo\EngineList.ini | text | |
MD5:0E3541FD302F4DDE0D7CD785C4E07A85 | SHA256:C827616C69BE43B80D0D0CDE6DC60618C00AD7089C63D4E81519362FB099A8BC | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa844.46527\ChessBotX Turbo\ChessBotX Turbo.exe | executable | |
MD5:F0FD12DC9D949790365E637F81CCEFC5 | SHA256:56D225B16024EFCCF37906EBABD36C350401D01279A1CF97FCA572B2C8AA3D0B | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa844.46527\ChessBotX Turbo\Settings.ini | text | |
MD5:0F5B564EA5B4D957738A786D51CEC1AE | SHA256:964D926C14FF822BE056271060E5A47259B264B02E71367BF0797FDFA00786A5 | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa844.46527\ChessBotX Turbo\Engines Settings\stockfish.cfg | text | |
MD5:4471249005B5DDDDC2F630F271CE946A | SHA256:4EBEAC84F38EC2931C6EDCD9388E696693A32863D49AC3CA55D519A0D54C77D0 | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa844.46527\ChessBotX Turbo\System\ChessBotX Turbo.ico | image | |
MD5:1BD1987F01F178BFAFF7C1EFFF597881 | SHA256:EB1E1736BE30EEECFCC859B6451F722E8EA34651DCD086B8CE29C5888DE14B12 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1080 | svchost.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b257947f6e02507e | unknown | compressed | 4.66 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3888 | chrome.exe | 142.250.186.141:443 | accounts.google.com | GOOGLE | US | whitelisted |
3348 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3888 | chrome.exe | 142.250.186.36:443 | www.google.com | GOOGLE | US | whitelisted |
3888 | chrome.exe | 142.250.186.131:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
3888 | chrome.exe | 216.58.212.131:443 | www.gstatic.com | GOOGLE | US | whitelisted |
3888 | chrome.exe | 142.250.186.142:443 | apis.google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
apis.google.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
encrypted-tbn0.gstatic.com |
| whitelisted |
optimizationguide-pa.googleapis.com |
| whitelisted |
www.chess.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
3888 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |