File name:

Youtube Commenter Pro.zip

Full analysis: https://app.any.run/tasks/1587e48c-56ab-4b65-9baa-173858c277d5
Verdict: Malicious activity
Analysis date: July 18, 2020, 07:27:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

A6AE906E73338BECAC83AAA06E0E6CB0

SHA1:

E6A373D21BD70A627DC0870BDD7E427EA6B4ACFA

SHA256:

28F134CD7F71FAD17BDCD6DB4A0508486BADA62FCB0797414FDC5D1D1E28985C

SSDEEP:

393216:6xzE4Y+xcgkyOukUPsu8SZcZo0/yey3FxQ:U/+g7pku8ey/yey1xQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3652)
      • YouBotTube Commenter Pro.exe (PID: 2236)
    • Application was dropped or rewritten from another process

      • YouBotTube Commenter Pro.exe (PID: 2236)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2480)
  • INFO

    • Manual execution by user

      • YouBotTube Commenter Pro.exe (PID: 2236)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:07:18 00:05:13
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: x64/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs youbottube commenter pro.exe

Process information

PID
CMD
Path
Indicators
Parent process
2236"C:\Users\admin\Desktop\YouBotTube Commenter Pro.exe" C:\Users\admin\Desktop\YouBotTube Commenter Pro.exe
explorer.exe
User:
admin
Company:
WhiteHatBox.com
Integrity Level:
MEDIUM
Description:
ComplieCustom
Exit code:
0
Version:
4.8.0.0
Modules
Images
c:\users\admin\desktop\youbottube commenter pro.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2480"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Youtube Commenter Pro.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3652"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
868
Read events
827
Write events
41
Delete events
0

Modification events

(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2480) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Youtube Commenter Pro.zip
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(3652) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
31
Suspicious files
1
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\WhbPack.exeexecutable
MD5:
SHA256:
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\Geckofx29.0\Geckofx-Core.dllexecutable
MD5:6B585B22AC98D1F495C8DDC7610CE6E9
SHA256:2784E6CCE7D4E4D10D513D7A13A30F9AAFBC4D7D026200ECCFE1B4EC92C8D32F
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\System.Data.SQLite.dllexecutable
MD5:09E1D3884873594523EEFF74D5E329D4
SHA256:D44F9DDD0362306BC059D3CF8A9691EB219E26296EC4AD2F5F5F58AD10F77CA7
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\Geckofx29.0\Geckofx-Winforms.dllexecutable
MD5:C8441F6BBDDD913BA342046F19111E6F
SHA256:346A00C08F49B0473967299E85AAE5FD446B2A4B7ED5C0FC042D6F90911A3ED4
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\MuterHook-32.dllexecutable
MD5:3BFA4922D5187D5080B1CF5AB86C58E3
SHA256:161570872D495207BB60124B97CD6C9A47F2368B24F52625DB99BA17A9EB507C
2480WinRAR.exeC:\Users\admin\Desktop\x86\SQLite.Interop.dllexecutable
MD5:9305E01488F7B3126D54C9111A51D2CE
SHA256:EBC23DE5E79813B43DD0DDB2DF98B1B76B46E59FBF2E31C75CF32ECAAB072C43
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\upload_file.exeexecutable
MD5:A5541A016A034E04C3391B6D083D7D44
SHA256:20895EC603C6C510FEC855EBEED2893978BABB3021A3B10DD9C25F2ED56C8E1B
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\WebDriver.Support.dllexecutable
MD5:830B211E669213B31909F05D2EE3957D
SHA256:E554ED189379CD80CC88130D972869EF965BA12B371553735CDA97BC130FEAF4
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\YouBotTubeDebug.exeexecutable
MD5:
SHA256:
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\MailBee.NET.dllexecutable
MD5:675D51B8B09BE135219AB861952F9FD4
SHA256:1BCC5E84D759107F058EA29742FF580008318F8F888D5F4CCE286BCF8262AF90
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
1
DNS requests
1
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2236
YouBotTube Commenter Pro.exe
GET
104.28.15.20:80
http://www.botchief.com/xulrunner29.0.zip
US
malicious
2236
YouBotTube Commenter Pro.exe
GET
200
104.28.15.20:80
http://www.botchief.com/IbotUpdate/browserinfo.txt
US
text
419 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2236
YouBotTube Commenter Pro.exe
104.28.15.20:80
www.botchief.com
Cloudflare Inc
US
malicious

DNS requests

Domain
IP
Reputation
www.botchief.com
  • 104.28.15.20
  • 104.28.14.20
  • 172.67.129.70
malicious

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info