URL:

https://www.babatools.net/super-twitch-god-2020-v1-2-vip-pro-edition/

Full analysis: https://app.any.run/tasks/acfa2894-0752-4ba1-abdd-db23a09c894e
Verdict: No threats detected
Analysis date: December 21, 2019, 21:09:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

5D4637AC463CCEF6B2F3309B583D63EB

SHA1:

C53F5A56BBAEFD6ED4FE338BAF530F6830D76B07

SHA256:

30662E53A3CAFCAC6386502C2E1DDFB98D6B23C74336FE937137CC976913BF05

SSDEEP:

3:N8DSLkkRRJ1KXVbiNICaq9VbzwoXKjQC:2OLkS1WmoqLzwoakC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Super Twitch God 2020 v1.2 (Vip Pro Edition).exe (PID: 3304)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3908)
    • Reads Environment values

      • Super Twitch God 2020 v1.2 (Vip Pro Edition).exe (PID: 3304)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1016)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 1820)
    • Creates files in the user directory

      • iexplore.exe (PID: 1820)
    • Changes internet zones settings

      • iexplore.exe (PID: 1016)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 1820)
      • iexplore.exe (PID: 1016)
    • Reads internet explorer settings

      • iexplore.exe (PID: 1820)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 1016)
      • Super Twitch God 2020 v1.2 (Vip Pro Edition).exe (PID: 3304)
    • Changes settings of System certificates

      • iexplore.exe (PID: 1016)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 1016)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
4
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1016"C:\Program Files\Internet Explorer\iexplore.exe" "https://www.babatools.net/super-twitch-god-2020-v1-2-vip-pro-edition/"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1820"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1016 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3304"C:\Users\admin\AppData\Local\Temp\Rar$EXa3908.9448\Super Twitch God 2020 v1.2 (Vip Pro Edition)\Super Twitch God 2020 v1.2 (Vip Pro Edition).exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3908.9448\Super Twitch God 2020 v1.2 (Vip Pro Edition)\Super Twitch God 2020 v1.2 (Vip Pro Edition).exe
WinRAR.exe
User:
admin
Company:
Pooria Sharaffodin www.BabaTools.net
Integrity Level:
MEDIUM
Description:
Super Twitch God 2020 v1.2 (Vip Pro Edition)
Exit code:
0
Version:
1.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3908.9448\super twitch god 2020 v1.2 (vip pro edition)\super twitch god 2020 v1.2 (vip pro edition).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3908"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5LK9JSOE\Super-Twitch-God-2020-v1.2-Vip-Pro-Edition[1].zip"C:\Program Files\WinRAR\WinRAR.exe
iexplore.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
1 240
Read events
1 123
Write events
114
Delete events
3

Modification events

(PID) Process:(1016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(1016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(1016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(1016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{2A3282F1-2436-11EA-AB41-5254004A04AF}
Value:
0
(PID) Process:(1016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(1016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
2
(PID) Process:(1016) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E3070C0006001500150009001900F801
Executable files
3
Suspicious files
1
Text files
38
Unknown types
13

Dropped files

PID
Process
Filename
Type
1016iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
1016iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
1820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7AI0KKS9\super-twitch-god-2020-v1-2-vip-pro-edition[1].txt
MD5:
SHA256:
1820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:C02D961C979DC3AC8E28430F0723D6CD
SHA256:7E6733AF34E3B910931BFC7C2561E74FAE1B648BFFA4BC11C8489491F51C4C92
1820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7AI0KKS9\super-twitch-god-2020-v1-2-vip-pro-edition[1].htmhtml
MD5:4200CA420F90ABA8D63FA3CCD3D6C2E7
SHA256:CD3BC97CD4A9FA6373D59339E66C34A90256875C11BFC2C6B86E23FB2CA0884A
1820iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@www.babatools[1].txttext
MD5:BD76A015F89FD198B0D46EBE9E20A211
SHA256:C592D4664B0AE3555539C75F95E8E4A6040DEBAE8E3C23B0AB97E8A14671A967
1820iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.datdat
MD5:872B1D69C0E4F363C66EEC5A445CA93E
SHA256:F1977B923A6223B2303A8E776FDC7ED99B06BD324833724BEB90BA1D3F0EA550
1820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:43257E0921E7009FC61033523D3261AC
SHA256:4D4CBE759ED71A68D7E93F34716EAF5C9207A8B82369BAE0DB7C5329BFCEAFE7
1820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\94VQBRL7\css[1].txttext
MD5:74EFE4CCA2C3554C1DA07F5A86317F06
SHA256:5FB6156C09571F4279BA112CE0C6C347F7CFCC1F42342A4064AE669E54A71EEB
1820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\61CARS0J\desktop.iniini
MD5:4A3DEB274BB5F0212C2419D3D8D08612
SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
14
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1016
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1820
iexplore.exe
173.254.28.147:443
www.babatools.net
Unified Layer
US
malicious
1016
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
1820
iexplore.exe
172.217.18.106:443
fonts.googleapis.com
Google Inc.
US
whitelisted
1820
iexplore.exe
172.217.16.131:443
fonts.gstatic.com
Google Inc.
US
whitelisted
1016
iexplore.exe
173.254.28.147:443
www.babatools.net
Unified Layer
US
malicious
3304
Super Twitch God 2020 v1.2 (Vip Pro Edition).exe
173.254.28.147:443
www.babatools.net
Unified Layer
US
malicious

DNS requests

Domain
IP
Reputation
www.babatools.net
  • 173.254.28.147
suspicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
fonts.googleapis.com
  • 172.217.18.106
whitelisted
fonts.gstatic.com
  • 172.217.16.131
whitelisted

Threats

No threats detected
No debug info