analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Twitch God 2018 v1.2 (Vip Pro Edition) - Nulled.to - isssrrrraaaa.rar (2).zip

Full analysis: https://app.any.run/tasks/c71cd2f6-51d6-4d84-9ef7-dd59f70ed771
Verdict: Malicious activity
Analysis date: June 18, 2019, 22:25:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

3266D9B78B9F72723D3BB20CC0AC6625

SHA1:

8B31E539F1CB4FA1A1A05A944A998269D2A30D43

SHA256:

41F20D3A286494DCD8945676D4777684942E8648727B2E1FB1CB29FFBCA7FECC

SSDEEP:

196608:Z5wuB4ch2OA9MhMZmvrrPUq8yuJQmxDpEnY++v9TJwBK:Z5w04cUOALZIPuprEY+2TeBK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3516)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2636)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2640)
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 3112)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2796)
  • INFO

    • Manual execution by user

      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3516)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2640)
    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 2796)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Twitch God 2018 v1.2 (Vip Pro Edition) - Nulled.to - isssrrrraaaa.rar
ZipUncompressedSize: 9291890
ZipCompressedSize: 9291570
ZipCRC: 0x173a1ef2
ZipModifyDate: 2019:06:19 01:18:04
ZipCompression: Unknown (99)
ZipBitFlag: 0x0009
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs winrar.exe twitch god 2018 v1.1 (vip pro edition).exe notepad.exe no specs twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe

Process information

PID
CMD
Path
Indicators
Parent process
3112"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Twitch God 2018 v1.2 (Vip Pro Edition) - Nulled.to - isssrrrraaaa.rar (2).zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2796"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIb3112.26583\Twitch God 2018 v1.2 (Vip Pro Edition) - Nulled.to - isssrrrraaaa.rar"C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2636"C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.27836\Twitch God 2018 v1.1 (Vip Pro Edition).exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.27836\Twitch God 2018 v1.1 (Vip Pro Edition).exe
WinRAR.exe
User:
admin
Company:
Pooria Sharaffodin www.BabaTools.com
Integrity Level:
MEDIUM
Description:
Twitch God 2018 v1.1 (Vip Pro Edition)
Exit code:
3489660927
Version:
1.1.0.0
3344"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa2796.28483\settings.txtC:\Windows\system32\NOTEPAD.EXEWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3516"C:\Users\admin\Desktop\Twitch God 2018 v1.1 (Vip Pro Edition).exe" C:\Users\admin\Desktop\Twitch God 2018 v1.1 (Vip Pro Edition).exe
explorer.exe
User:
admin
Company:
Pooria Sharaffodin www.BabaTools.com
Integrity Level:
MEDIUM
Description:
Twitch God 2018 v1.1 (Vip Pro Edition)
Exit code:
3489660927
Version:
1.1.0.0
2640"C:\Users\admin\Desktop\Twitch God 2018 v1.1 (Vip Pro Edition).exe" C:\Users\admin\Desktop\Twitch God 2018 v1.1 (Vip Pro Edition).exe
explorer.exe
User:
admin
Company:
Pooria Sharaffodin www.BabaTools.com
Integrity Level:
MEDIUM
Description:
Twitch God 2018 v1.1 (Vip Pro Edition)
Version:
1.1.0.0
Total events
1 195
Read events
1 083
Write events
0
Delete events
0

Modification events

No data
Executable files
35
Suspicious files
0
Text files
13
Unknown types
0

Dropped files

PID
Process
Filename
Type
3112WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb3112.26583\Twitch God 2018 v1.2 (Vip Pro Edition) - Nulled.to - isssrrrraaaa.rar
MD5:
SHA256:
2796WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2796.27836\Lizenz-Deutsch.txttext
MD5:4A916074230757545A519A59E19106D0
SHA256:F6192E1CF939F09F340F6923E78450416C92861CA7987B5AE07E4A75915BD909
2796WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa2796.28483\settings.txttext
MD5:55FDC18F67D48B0C6CE6B8E22F7FBD3C
SHA256:7B6614EAFD25000B4CBCBDF31ECCDCE8957676003D440A76B27EF084800886E2
2796WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2796.27836\Twitch God 2018 v1.1 (Vip Pro Edition).exeexecutable
MD5:A86A9B66D20FE9A4A8FE941A6DE03EB2
SHA256:C95DEBE690104C6B6D6FF94F36354B1A12E903CBD3A93E9E75020E1271EBDFB9
2796WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2796.27836\msvcp110.dllexecutable
MD5:7CAA1B97A3311EB5A695E3C9028616E7
SHA256:27F394AE01D12F851F1DEE3632DEE3C5AFA1D267F7A96321D35FD43105B035AD
2796WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2796.27836\Qt5Network.dllexecutable
MD5:074093F29D518B0EEC4A8A052F908979
SHA256:886903ABCB6A16910C8C33FD17BD901F1A2D2CD98ABDE8B5C5E6281C8A1816BC
2796WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2796.27836\cudart64_60.dllexecutable
MD5:FAAD9C823EDB11ECEA64C2BA9BEFDC4F
SHA256:C23167C90D7B7B410CD87DB20EADBE46DC13100EF2FE9CE5DB495785AB7734C5
2796WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2796.27836\service_ba.exeexecutable
MD5:0FEC796CB2219E0FC5F961BD0FB9126D
SHA256:9ADEC6F3A2EF418EEDFCE319EC8776505CFC96AB80DB0CBC9E4E456CC725E7D5
2796WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2796.27836\Licence-English.txttext
MD5:B550164F724F1FF24D10D79B8DF4945E
SHA256:F5E6016BD08EC116F6A62B4AA0739E1541B3A80CFEA56A60E12EE84194F7E708
2796WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2796.27836\settings.txttext
MD5:55FDC18F67D48B0C6CE6B8E22F7FBD3C
SHA256:7B6614EAFD25000B4CBCBDF31ECCDCE8957676003D440A76B27EF084800886E2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
5
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3516
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
173.254.28.147:80
http://www.babatools.com/pool.txt
US
malicious
3516
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
173.254.28.147:80
http://www.babatools.com/pool.txt
US
malicious
2636
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
173.254.28.147:80
http://www.babatools.com/pool.txt
US
malicious
2640
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
173.254.28.147:80
http://www.babatools.com/pool.txt
US
malicious
3556
werfault.exe
GET
52.158.209.219:80
http://watson.microsoft.com/StageOne/Generic/AppHangB1/Twitch%20God%202018%20v1_1%20(Vip%20Pro%20Edition)_exe/1_1_0_0/5000a574/762b/262144.htm?LCID=1033&OS=6.1.7601.2.00010100.1.0.48.17514&SM=DELL&SPN=DELL&BV=DELL&MID=3ADE2C42-4AB9-49B7-B142-BE9AEEA69063
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3556
werfault.exe
52.158.209.219:80
watson.microsoft.com
Microsoft Corporation
US
suspicious
2636
Twitch God 2018 v1.1 (Vip Pro Edition).exe
173.254.28.147:80
www.babatools.com
Unified Layer
US
malicious
2640
Twitch God 2018 v1.1 (Vip Pro Edition).exe
173.254.28.147:80
www.babatools.com
Unified Layer
US
malicious
3516
Twitch God 2018 v1.1 (Vip Pro Edition).exe
173.254.28.147:80
www.babatools.com
Unified Layer
US
malicious

DNS requests

Domain
IP
Reputation
www.babatools.com
  • 173.254.28.147
unknown
watson.microsoft.com
  • 52.158.209.219
whitelisted

Threats

PID
Process
Class
Message
3556
werfault.exe
Potential Corporate Privacy Violation
ET POLICY Application Crash Report Sent to Microsoft
3556
werfault.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info