File name:

Twitch Drops Miner (by DevilXD).exe

Full analysis: https://app.any.run/tasks/0053a20d-b365-41df-bdbb-44bdab80e6e1
Verdict: Malicious activity
Analysis date: August 04, 2024, 18:42:25
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
pyinstaller
python
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

79DB2D66910296E65C09361A92188B92

SHA1:

7118CFD463AE350FE4C8CA1891F6B9803FBD9F1B

SHA256:

0255BD9DB00D033438A948B3F6A7B505F7906F0319BF5C3E40232AF85C3923C3

SSDEEP:

98304:Iv7zWacMFwvA5aH2taULygJn5DbxBevBHCpShl0xUMfs12yVFVZ3+cfW6sXem9sq:bM7PuVNtHz5o1iBInFQ9KKV1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Twitch Drops Miner (by DevilXD).exe (PID: 6364)
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • Twitch Drops Miner (by DevilXD).exe (PID: 6364)
    • Process drops python dynamic module

      • Twitch Drops Miner (by DevilXD).exe (PID: 6364)
    • Process drops legitimate windows executable

      • Twitch Drops Miner (by DevilXD).exe (PID: 6364)
    • Executable content was dropped or overwritten

      • Twitch Drops Miner (by DevilXD).exe (PID: 6364)
    • Application launched itself

      • Twitch Drops Miner (by DevilXD).exe (PID: 6364)
    • Starts CMD.EXE for commands execution

      • Twitch Drops Miner (by DevilXD).exe (PID: 6600)
    • Loads Python modules

      • Twitch Drops Miner (by DevilXD).exe (PID: 6600)
  • INFO

    • Reads the computer name

      • Twitch Drops Miner (by DevilXD).exe (PID: 6364)
      • Twitch Drops Miner (by DevilXD).exe (PID: 6600)
      • TextInputHost.exe (PID: 7040)
    • Checks supported languages

      • Twitch Drops Miner (by DevilXD).exe (PID: 6364)
      • Twitch Drops Miner (by DevilXD).exe (PID: 6600)
      • TextInputHost.exe (PID: 7040)
    • Create files in a temporary directory

      • Twitch Drops Miner (by DevilXD).exe (PID: 6364)
      • Twitch Drops Miner (by DevilXD).exe (PID: 6600)
    • PyInstaller has been detected (YARA)

      • Twitch Drops Miner (by DevilXD).exe (PID: 6364)
    • Reads the machine GUID from the registry

      • Twitch Drops Miner (by DevilXD).exe (PID: 6600)
    • Checks operating system version

      • Twitch Drops Miner (by DevilXD).exe (PID: 6600)
    • Reads the software policy settings

      • Twitch Drops Miner (by DevilXD).exe (PID: 6600)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:02:18 09:14:06+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.37
CodeSize: 171520
InitializedDataSize: 162304
UninitializedDataSize: -
EntryPoint: 0xc2f0
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT twitch drops miner (by devilxd).exe twitch drops miner (by devilxd).exe cmd.exe no specs conhost.exe no specs textinputhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6184C:\WINDOWS\system32\cmd.exe /c "ver"C:\Windows\System32\cmd.exeTwitch Drops Miner (by DevilXD).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
6224\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6364"C:\Users\admin\AppData\Local\Temp\Twitch Drops Miner (by DevilXD).exe" C:\Users\admin\AppData\Local\Temp\Twitch Drops Miner (by DevilXD).exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\twitch drops miner (by devilxd).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6600"C:\Users\admin\AppData\Local\Temp\Twitch Drops Miner (by DevilXD).exe" C:\Users\admin\AppData\Local\Temp\Twitch Drops Miner (by DevilXD).exe
Twitch Drops Miner (by DevilXD).exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\twitch drops miner (by devilxd).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7040"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mcaC:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Version:
123.26505.0.0
Modules
Images
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\textinputhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\vcruntime140_app.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
Total events
7 826
Read events
7 826
Write events
0
Delete events
0

Modification events

No data
Executable files
85
Suspicious files
15
Text files
941
Unknown types
4

Dropped files

PID
Process
Filename
Type
6364Twitch Drops Miner (by DevilXD).exeC:\Users\admin\AppData\Local\Temp\_MEI63642\PIL\_imagingcms.cp310-win_amd64.pydexecutable
MD5:F66EA0D2F36392DC427BB68E5476531B
SHA256:574970CA3299C6E02A965BD9EEF939012CAF30C851D89A550B33381C85FD96CE
6364Twitch Drops Miner (by DevilXD).exeC:\Users\admin\AppData\Local\Temp\_MEI63642\PIL\_webp.cp310-win_amd64.pydexecutable
MD5:9636BDBDE4C242814F66B2FB7FC3BF63
SHA256:25603490E427A8252489D4FA40847D1C641AFC600D89F04A31DF4CE3529F2BB1
6364Twitch Drops Miner (by DevilXD).exeC:\Users\admin\AppData\Local\Temp\_MEI63642\Pythonwin\win32ui.pydexecutable
MD5:2DC4AFB4D80FE4F45CE23446D27A291E
SHA256:EFBD6798CE0F26704DF18139BECAF03CA47DA80B5BC127178EB0B67E36C60A69
6364Twitch Drops Miner (by DevilXD).exeC:\Users\admin\AppData\Local\Temp\_MEI63642\PIL\_imagingmath.cp310-win_amd64.pydexecutable
MD5:7B4F252729F92836751DFEBBE95C9A02
SHA256:D06ADF706A7E3E187195281D44BB5576CAD79DECD029B6058A6ACC32B68FE197
6364Twitch Drops Miner (by DevilXD).exeC:\Users\admin\AppData\Local\Temp\_MEI63642\PIL\_imaging.cp310-win_amd64.pydexecutable
MD5:C914A28948F30173F677944CAA9B0384
SHA256:89C78F93CEBC3B288DE5723AA020093C1B851FF19F4CE4C695BE8F3025BB5CD5
6364Twitch Drops Miner (by DevilXD).exeC:\Users\admin\AppData\Local\Temp\_MEI63642\PIL\_imagingtk.cp310-win_amd64.pydexecutable
MD5:B8AAD6AAEF007E20B0570973A49E8000
SHA256:80E1916AE8784162BD8B1353C3671B928AF8A3454AE8CE986C61A3216C6154B7
6364Twitch Drops Miner (by DevilXD).exeC:\Users\admin\AppData\Local\Temp\_MEI63642\VCRUNTIME140_1.dllexecutable
MD5:135359D350F72AD4BF716B764D39E749
SHA256:34048ABAA070ECC13B318CEA31425F4CA3EDD133D350318AC65259E6058C8B32
6364Twitch Drops Miner (by DevilXD).exeC:\Users\admin\AppData\Local\Temp\_MEI63642\Pythonwin\mfc140u.dllexecutable
MD5:03A161718F1D5E41897236D48C91AE3C
SHA256:E06C4BD078F4690AA8874A3DEB38E802B2A16CCB602A7EDC2E077E98C05B5807
6364Twitch Drops Miner (by DevilXD).exeC:\Users\admin\AppData\Local\Temp\_MEI63642\VCRUNTIME140.dllexecutable
MD5:F34EB034AA4A9735218686590CBA2E8B
SHA256:9D2B40F0395CC5D1B4D5EA17B84970C29971D448C37104676DB577586D4AD1B1
6364Twitch Drops Miner (by DevilXD).exeC:\Users\admin\AppData\Local\Temp\_MEI63642\_asyncio.pydexecutable
MD5:4679FB6C4927612A1F13FA3883533F47
SHA256:A2EA28CA2BE4326A113DA539A081C8A889D55C13AABED755AD27C1738A1D10C1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
38
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5484
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6708
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5484
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6656
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1420
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5600
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1420
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5336
SearchApp.exe
92.123.104.28:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5484
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.78
whitelisted
www.bing.com
  • 92.123.104.28
  • 92.123.104.59
  • 92.123.104.62
  • 92.123.104.8
  • 92.123.104.60
  • 92.123.104.44
  • 92.123.104.32
  • 92.123.104.52
  • 92.123.104.34
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.0
  • 20.190.159.73
  • 20.190.159.64
  • 20.190.159.75
  • 40.126.31.73
  • 20.190.159.68
  • 20.190.159.2
  • 40.126.31.67
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
th.bing.com
  • 92.123.104.34
  • 92.123.104.33
  • 92.123.104.44
  • 92.123.104.62
  • 92.123.104.59
  • 92.123.104.60
  • 92.123.104.8
  • 92.123.104.32
  • 92.123.104.52
whitelisted
fd.api.iris.microsoft.com
  • 20.74.47.205
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 40.127.169.103
whitelisted

Threats

No threats detected
No debug info