File name:

Youtube Commenter Pro.zip

Full analysis: https://app.any.run/tasks/1587e48c-56ab-4b65-9baa-173858c277d5
Verdict: Malicious activity
Analysis date: July 18, 2020, 07:27:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

A6AE906E73338BECAC83AAA06E0E6CB0

SHA1:

E6A373D21BD70A627DC0870BDD7E427EA6B4ACFA

SHA256:

28F134CD7F71FAD17BDCD6DB4A0508486BADA62FCB0797414FDC5D1D1E28985C

SSDEEP:

393216:6xzE4Y+xcgkyOukUPsu8SZcZo0/yey3FxQ:U/+g7pku8ey/yey1xQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3652)
      • YouBotTube Commenter Pro.exe (PID: 2236)
    • Application was dropped or rewritten from another process

      • YouBotTube Commenter Pro.exe (PID: 2236)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2480)
  • INFO

    • Manual execution by user

      • YouBotTube Commenter Pro.exe (PID: 2236)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:07:18 00:05:13
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: x64/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs youbottube commenter pro.exe

Process information

PID
CMD
Path
Indicators
Parent process
2236"C:\Users\admin\Desktop\YouBotTube Commenter Pro.exe" C:\Users\admin\Desktop\YouBotTube Commenter Pro.exe
explorer.exe
User:
admin
Company:
WhiteHatBox.com
Integrity Level:
MEDIUM
Description:
ComplieCustom
Exit code:
0
Version:
4.8.0.0
Modules
Images
c:\users\admin\desktop\youbottube commenter pro.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2480"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Youtube Commenter Pro.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3652"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
868
Read events
827
Write events
41
Delete events
0

Modification events

(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2480) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Youtube Commenter Pro.zip
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2480) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(3652) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
31
Suspicious files
1
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
2480WinRAR.exeC:\Users\admin\Desktop\x64\SQLite.Interop.dllexecutable
MD5:9E3C113A301F93CDFACD8EC2CC3AA47C
SHA256:F29301BF3A56A42BAFE8B675D01280F749541038D7D5BD877BF300871F9D41EB
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\System.Data.SQLite.dllexecutable
MD5:09E1D3884873594523EEFF74D5E329D4
SHA256:D44F9DDD0362306BC059D3CF8A9691EB219E26296EC4AD2F5F5F58AD10F77CA7
2480WinRAR.exeC:\Users\admin\Desktop\x86\SQLite.Interop.dllexecutable
MD5:9305E01488F7B3126D54C9111A51D2CE
SHA256:EBC23DE5E79813B43DD0DDB2DF98B1B76B46E59FBF2E31C75CF32ECAAB072C43
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\MailBee.NET.dllexecutable
MD5:675D51B8B09BE135219AB861952F9FD4
SHA256:1BCC5E84D759107F058EA29742FF580008318F8F888D5F4CCE286BCF8262AF90
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\WebDriver.Support.dllexecutable
MD5:830B211E669213B31909F05D2EE3957D
SHA256:E554ED189379CD80CC88130D972869EF965BA12B371553735CDA97BC130FEAF4
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\WebDriver.dllexecutable
MD5:C357DCEC43DD312C93D26070559E1E2A
SHA256:E8FEB982C8B478BA941F521F0105F670C9C7A360C7FCF45149532637534E8A79
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\YouBotTubeDebug.exeexecutable
MD5:
SHA256:
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\WhbPack.exeexecutable
MD5:
SHA256:
2480WinRAR.exeC:\Users\admin\Desktop\7z1.dllexecutable
MD5:42EDF51C86E726F00379CCBDAD2BC796
SHA256:F7E6FB7F23AC191CCAE310DEAEA112D03A17D507755D3E041D4213C02AD7BE9D
2480WinRAR.exeC:\Users\admin\Desktop\YouBotTubeDll\x64\SQLite.Interop.dllexecutable
MD5:9E3C113A301F93CDFACD8EC2CC3AA47C
SHA256:F29301BF3A56A42BAFE8B675D01280F749541038D7D5BD877BF300871F9D41EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
1
DNS requests
1
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2236
YouBotTube Commenter Pro.exe
GET
104.28.15.20:80
http://www.botchief.com/xulrunner29.0.zip
US
malicious
2236
YouBotTube Commenter Pro.exe
GET
200
104.28.15.20:80
http://www.botchief.com/IbotUpdate/browserinfo.txt
US
text
419 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2236
YouBotTube Commenter Pro.exe
104.28.15.20:80
www.botchief.com
Cloudflare Inc
US
malicious

DNS requests

Domain
IP
Reputation
www.botchief.com
  • 104.28.15.20
  • 104.28.14.20
  • 172.67.129.70
malicious

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info