File name:

TwitchChatOverlay-Setup.exe

Full analysis: https://app.any.run/tasks/6034811e-622f-48a6-94e7-0fe66b094fed
Verdict: Malicious activity
Analysis date: February 22, 2024, 20:46:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

8BD203587657B8F9F024F7EAA94B1E39

SHA1:

E4903963A3E5B24746ED1D6126155187E2F25D1C

SHA256:

3693B0158B9886B2F4B27572D78A28B999539550A6B71B424D87EDB992695946

SSDEEP:

98304:8DFycIpSrUM/+FHm5eaFbQuiuW7eHaXveATvHfouJ+UosEvJ7GKDJci0TgSnivCo:RYC4w/31I

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • TwitchChatOverlay-Setup.exe (PID: 3864)
      • Update.exe (PID: 4052)
      • TransparentTwitchChatWPF.exe (PID: 3732)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Update.exe (PID: 4052)
      • TwitchChatOverlay-Setup.exe (PID: 3864)
      • TransparentTwitchChatWPF.exe (PID: 3732)
    • Reads security settings of Internet Explorer

      • Update.exe (PID: 4052)
      • TransparentTwitchChatWPF.exe (PID: 3732)
    • Reads the Internet Settings

      • Update.exe (PID: 4052)
      • TransparentTwitchChatWPF.exe (PID: 3732)
    • Searches for installed software

      • Update.exe (PID: 4052)
    • Creates a software uninstall entry

      • Update.exe (PID: 4052)
    • Process drops legitimate windows executable

      • TransparentTwitchChatWPF.exe (PID: 3732)
    • Reads the date of Windows installation

      • TransparentTwitchChatWPF.exe (PID: 3732)
  • INFO

    • Checks supported languages

      • TwitchChatOverlay-Setup.exe (PID: 3864)
      • Update.exe (PID: 4052)
      • TransparentTwitchChatWPF.exe (PID: 3732)
    • Reads the computer name

      • Update.exe (PID: 4052)
      • TransparentTwitchChatWPF.exe (PID: 3732)
    • Creates files or folders in the user directory

      • TwitchChatOverlay-Setup.exe (PID: 3864)
      • Update.exe (PID: 4052)
      • TransparentTwitchChatWPF.exe (PID: 3732)
    • Create files in a temporary directory

      • Update.exe (PID: 4052)
      • TransparentTwitchChatWPF.exe (PID: 3732)
    • Reads the machine GUID from the registry

      • Update.exe (PID: 4052)
      • TransparentTwitchChatWPF.exe (PID: 3732)
    • Reads Environment values

      • TransparentTwitchChatWPF.exe (PID: 3732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:02:08 02:59:34+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 117248
InitializedDataSize: 6223872
UninitializedDataSize: -
EntryPoint: 0xab0b
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.2.0
ProductVersionNumber: 1.0.2.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Application for Windows that will display Twitch chat on top of a windowed or borderless windowed game.
FileVersion: 1.0.2
InternalName: Setup.exe
LegalCopyright: 2024
OriginalFileName: Setup.exe
ProductName: Application for Windows that will display Twitch chat on top of a windowed or borderless windowed game.
ProductVersion: 1.0.2
SquirrelAwareVersion: 1
CompanyName: baffler
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start twitchchatoverlay-setup.exe update.exe transparenttwitchchatwpf.exe

Process information

PID
CMD
Path
Indicators
Parent process
3732"C:\Users\admin\AppData\Local\TransparentTwitchChatOverlay\app-1.0.2\TransparentTwitchChatWPF.exe" --squirrel-firstrunC:\Users\admin\AppData\Local\TransparentTwitchChatOverlay\app-1.0.2\TransparentTwitchChatWPF.exe
Update.exe
User:
admin
Integrity Level:
MEDIUM
Description:
TransparentTwitchChatWPF
Exit code:
0
Version:
1.0.2
Modules
Images
c:\users\admin\appdata\local\transparenttwitchchatoverlay\app-1.0.2\transparenttwitchchatwpf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3864"C:\Users\admin\AppData\Local\Temp\TwitchChatOverlay-Setup.exe" C:\Users\admin\AppData\Local\Temp\TwitchChatOverlay-Setup.exe
explorer.exe
User:
admin
Company:
baffler
Integrity Level:
MEDIUM
Description:
Application for Windows that will display Twitch chat on top of a windowed or borderless windowed game.
Exit code:
0
Version:
1.0.2
Modules
Images
c:\users\admin\appdata\local\temp\twitchchatoverlay-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
4052"C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe" --install . C:\Users\admin\AppData\Local\SquirrelTemp\Update.exe
TwitchChatOverlay-Setup.exe
User:
admin
Company:
GitHub
Integrity Level:
MEDIUM
Description:
Update
Exit code:
0
Version:
1.9.1.0
Modules
Images
c:\users\admin\appdata\local\squirreltemp\update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
9 316
Read events
9 216
Write events
100
Delete events
0

Modification events

(PID) Process:(4052) Update.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4052) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4052) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4052) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4052) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4052) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\TransparentTwitchChatOverlay
Operation:writeName:DisplayName
Value:
Transparent Twitch Chat Overlay
(PID) Process:(4052) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\TransparentTwitchChatOverlay
Operation:writeName:DisplayVersion
Value:
1.0.2
(PID) Process:(4052) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\TransparentTwitchChatOverlay
Operation:writeName:InstallDate
Value:
20240222
(PID) Process:(4052) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\TransparentTwitchChatOverlay
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\TransparentTwitchChatOverlay
(PID) Process:(4052) Update.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\TransparentTwitchChatOverlay
Operation:writeName:Publisher
Value:
baffler
Executable files
7
Suspicious files
8
Text files
8
Unknown types
4

Dropped files

PID
Process
Filename
Type
3864TwitchChatOverlay-Setup.exeC:\Users\admin\AppData\Local\SquirrelTemp\Update.exeexecutable
MD5:C5F6CDA4976AE38CD9FBA3D1E5EBD244
SHA256:DAE7BD888B715B8E215482BC5EA6F028DED32A3AD88BF4ACB6431D2A62FFE3F4
4052Update.exeC:\Users\admin\AppData\Local\TransparentTwitchChatOverlay\app-1.0.2\TransparentTwitchChatWPF.exeexecutable
MD5:B2B928577FDC2930347DD41D0C621088
SHA256:1AD5408B4B2F595D48D22441811006EA591B93F2B004D77ED49B634F89235CB9
4052Update.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\baffler\TransparentTwitchChatWPF.lnkbinary
MD5:1F433EA4BBF3AC5E9B903D524737E68D
SHA256:297DE3994E7E35A063332BB19F8C8A442CB82A4365B7E1952B886DC3890B2FF3
4052Update.exeC:\Users\admin\AppData\Local\TransparentTwitchChatOverlay\app-1.0.2\index.htmlhtml
MD5:140229453088721FC4EC658F53A1AAF8
SHA256:188F7E91BD347D09137073A890249838C8A8AF7184BCDE1474D4EF460E722E35
4052Update.exeC:\Users\admin\AppData\Local\TransparentTwitchChatOverlay\app-1.0.2\TransparentTwitchChatWPF.exe.manifestxml
MD5:A4020D522E698E87352E00E2296720BB
SHA256:98FF3F6E9928C1C7F3F5E194B48F050426A14172A458D4DE6946E1E2A2AC925D
4052Update.exeC:\Users\admin\AppData\Local\TransparentTwitchChatOverlay\app-1.0.2\assets\Alert 3 (Low).wavwav
MD5:4B3B40D5971ECB4B99CE3B3262AAB976
SHA256:E110A39BB7E5031E4470F134E93725F9627DB8087CA005973267D9585447350F
4052Update.exeC:\Users\admin\AppData\Local\TransparentTwitchChatOverlay\packages\SquirrelTemp\tempatext
MD5:6E2A06F84F1EF9294CB3474904A2A733
SHA256:A1A39BCD48020D279CD1569CD9DAA10309AFDEB73092CF8D9C04BAABB0B90942
4052Update.exeC:\Users\admin\AppData\Local\TransparentTwitchChatOverlay\packages\RELEASEStext
MD5:6E2A06F84F1EF9294CB3474904A2A733
SHA256:A1A39BCD48020D279CD1569CD9DAA10309AFDEB73092CF8D9C04BAABB0B90942
4052Update.exeC:\Users\admin\AppData\Local\TransparentTwitchChatOverlay\packages\TransparentTwitchChatOverlay-1.0.2-full.nupkgcompressed
MD5:52D974B54EE2987A77E71619DCCA50B7
SHA256:9A310D78F131E51045C71805CE806F6D2372C53BF62E49954F694C707E3E6151
4052Update.exeC:\Users\admin\AppData\Local\TransparentTwitchChatOverlay\app-1.0.2\assets\Alert 2.wavwav
MD5:F71F3D354A4EE1565FFE7C5F5237FCB6
SHA256:74874F73F6A5801CF56D0AA85A562C63F77B647ECC26B8A8313FFCBE9B3483BF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3732
TransparentTwitchChatWPF.exe
140.82.121.6:443
api.github.com
GITHUB
US
unknown

DNS requests

Domain
IP
Reputation
api.github.com
  • 140.82.121.6
whitelisted

Threats

No threats detected
Process
Message
TransparentTwitchChatWPF.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
TransparentTwitchChatWPF.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
TransparentTwitchChatWPF.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
TransparentTwitchChatWPF.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
TransparentTwitchChatWPF.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
TransparentTwitchChatWPF.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
TransparentTwitchChatWPF.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
TransparentTwitchChatWPF.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
TransparentTwitchChatWPF.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
TransparentTwitchChatWPF.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.