File name:

Twitch God 2018 v1.2 (Vip Pro Edition) - Nulled.to - isssrrrraaaa.rar (2).zip

Full analysis: https://app.any.run/tasks/e21df129-f8e7-41eb-978f-6800667ebdac
Verdict: Malicious activity
Analysis date: June 18, 2019, 22:29:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

3266D9B78B9F72723D3BB20CC0AC6625

SHA1:

8B31E539F1CB4FA1A1A05A944A998269D2A30D43

SHA256:

41F20D3A286494DCD8945676D4777684942E8648727B2E1FB1CB29FFBCA7FECC

SSDEEP:

196608:Z5wuB4ch2OA9MhMZmvrrPUq8yuJQmxDpEnY++v9TJwBK:Z5w04cUOALZIPuprEY+2TeBK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3272)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2664)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 252)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 1028)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2948)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2164)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3488)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3928)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 392)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2436)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 1336)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3236)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2584)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3124)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2176)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3968)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 324)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 1352)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2412)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3972)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3432)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3256)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2744)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3680)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3948)
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 2060)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3612)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3612)
    • Manual execution by user

      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 1028)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 392)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2176)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3968)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2412)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3948)
      • NOTEPAD.EXE (PID: 2628)
      • NOTEPAD.EXE (PID: 3600)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 1352)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3972)
      • NOTEPAD.EXE (PID: 3880)
      • NOTEPAD.EXE (PID: 2180)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3432)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 2744)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3256)
      • Twitch God 2018 v1.1 (Vip Pro Edition).exe (PID: 3680)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Unknown (99)
ZipModifyDate: 2019:06:19 01:18:04
ZipCRC: 0x173a1ef2
ZipCompressedSize: 9291570
ZipUncompressedSize: 9291890
ZipFileName: Twitch God 2018 v1.2 (Vip Pro Edition) - Nulled.to - isssrrrraaaa.rar
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
74
Monitored processes
32
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start winrar.exe no specs winrar.exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe no specs twitch god 2018 v1.1 (vip pro edition).exe no specs notepad.exe no specs twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe no specs twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe no specs twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe notepad.exe no specs notepad.exe no specs twitch god 2018 v1.1 (vip pro edition).exe notepad.exe no specs notepad.exe no specs twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe twitch god 2018 v1.1 (vip pro edition).exe

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa3612.878\settings.txtC:\Windows\system32\NOTEPAD.EXEWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
252"C:\Users\admin\AppData\Local\Temp\Rar$EXa3612.49273\Twitch God 2018 v1.1 (Vip Pro Edition).exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3612.49273\Twitch God 2018 v1.1 (Vip Pro Edition).exe
WinRAR.exe
User:
admin
Company:
Pooria Sharaffodin www.BabaTools.com
Integrity Level:
MEDIUM
Description:
Twitch God 2018 v1.1 (Vip Pro Edition)
Exit code:
4294967295
Version:
1.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3612.49273\twitch god 2018 v1.1 (vip pro edition).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
324"C:\Users\admin\AppData\Local\Temp\Rar$EXa3612.2484\Twitch God 2018 v1.1 (Vip Pro Edition).exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3612.2484\Twitch God 2018 v1.1 (Vip Pro Edition).exe
WinRAR.exe
User:
admin
Company:
Pooria Sharaffodin www.BabaTools.com
Integrity Level:
MEDIUM
Description:
Twitch God 2018 v1.1 (Vip Pro Edition)
Exit code:
4294967295
Version:
1.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3612.2484\twitch god 2018 v1.1 (vip pro edition).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
392"C:\Users\admin\Desktop\Twitch God 2018 v1.1 (Vip Pro Edition).exe" C:\Users\admin\Desktop\Twitch God 2018 v1.1 (Vip Pro Edition).exe
explorer.exe
User:
admin
Company:
Pooria Sharaffodin www.BabaTools.com
Integrity Level:
MEDIUM
Description:
Twitch God 2018 v1.1 (Vip Pro Edition)
Exit code:
4294967295
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\twitch god 2018 v1.1 (vip pro edition).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1028"C:\Users\admin\Desktop\Twitch God 2018 v1.1 (Vip Pro Edition).exe" C:\Users\admin\Desktop\Twitch God 2018 v1.1 (Vip Pro Edition).exe
explorer.exe
User:
admin
Company:
Pooria Sharaffodin www.BabaTools.com
Integrity Level:
MEDIUM
Description:
Twitch God 2018 v1.1 (Vip Pro Edition)
Exit code:
4294967295
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\twitch god 2018 v1.1 (vip pro edition).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1336"C:\Users\admin\AppData\Local\Temp\Rar$EXa3612.3037\Twitch God 2018 v1.1 (Vip Pro Edition).exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3612.3037\Twitch God 2018 v1.1 (Vip Pro Edition).exe
WinRAR.exe
User:
admin
Company:
Pooria Sharaffodin www.BabaTools.com
Integrity Level:
MEDIUM
Description:
Twitch God 2018 v1.1 (Vip Pro Edition)
Exit code:
4294967295
Version:
1.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3612.3037\twitch god 2018 v1.1 (vip pro edition).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1352"C:\Users\admin\Desktop\Twitch God 2018 v1.1 (Vip Pro Edition).exe" C:\Users\admin\Desktop\Twitch God 2018 v1.1 (Vip Pro Edition).exe
explorer.exe
User:
admin
Company:
Pooria Sharaffodin www.BabaTools.com
Integrity Level:
HIGH
Description:
Twitch God 2018 v1.1 (Vip Pro Edition)
Exit code:
4294967295
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\twitch god 2018 v1.1 (vip pro edition).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2060"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Twitch God 2018 v1.2 (Vip Pro Edition) - Nulled.to - isssrrrraaaa.rar (2).zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2164"C:\Users\admin\AppData\Local\Temp\Rar$EXa3612.7636\Twitch God 2018 v1.1 (Vip Pro Edition).exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3612.7636\Twitch God 2018 v1.1 (Vip Pro Edition).exe
WinRAR.exe
User:
admin
Company:
Pooria Sharaffodin www.BabaTools.com
Integrity Level:
MEDIUM
Description:
Twitch God 2018 v1.1 (Vip Pro Edition)
Exit code:
4294967295
Version:
1.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3612.7636\twitch god 2018 v1.1 (vip pro edition).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2176"C:\Users\admin\Desktop\Twitch God 2018 v1.1 (Vip Pro Edition).exe" C:\Users\admin\Desktop\Twitch God 2018 v1.1 (Vip Pro Edition).exe
explorer.exe
User:
admin
Company:
Pooria Sharaffodin www.BabaTools.com
Integrity Level:
MEDIUM
Description:
Twitch God 2018 v1.1 (Vip Pro Edition)
Exit code:
4294967295
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\twitch god 2018 v1.1 (vip pro edition).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
6 001
Read events
5 862
Write events
139
Delete events
0

Modification events

(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2060) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Twitch God 2018 v1.2 (Vip Pro Edition) - Nulled.to - isssrrrraaaa.rar (2).zip
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2060) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
Executable files
193
Suspicious files
0
Text files
67
Unknown types
0

Dropped files

PID
Process
Filename
Type
2060WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb2060.48239\Twitch God 2018 v1.2 (Vip Pro Edition) - Nulled.to - isssrrrraaaa.rar
MD5:
SHA256:
3612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3612.49273\settings.txttext
MD5:
SHA256:
3612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3612.49273\Lizenz-Deutsch.txttext
MD5:4A916074230757545A519A59E19106D0
SHA256:F6192E1CF939F09F340F6923E78450416C92861CA7987B5AE07E4A75915BD909
3612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3612.49273\Qt5Network.dllexecutable
MD5:074093F29D518B0EEC4A8A052F908979
SHA256:886903ABCB6A16910C8C33FD17BD901F1A2D2CD98ABDE8B5C5E6281C8A1816BC
3612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3612.49273\libeay32.dllexecutable
MD5:F9ECF79E96560B14FF941DBC9CEE5C0C
SHA256:B3BD997E176870C5E68DB8BA5C0024B80CE93C356C1868C2FBBB83B2CFD5AC4F
3612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3612.49273\msvcr110.dllexecutable
MD5:7C3B449F661D99A9B1033A14033D2987
SHA256:AE996EDB9B050677C4F82D56092EFDC75F0ADDC97A14E2C46753E2DB3F6BD732
3612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3612.49273\Qt5WebSockets.dllexecutable
MD5:1DA5331607DAB754ED766E299A0D05A8
SHA256:3D413D1FD28BDE9260FC1FA3F82B7ACE1F3644B8ED98F82C7F4D10D30F12E0EB
3612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3612.49273\Licence-English.txttext
MD5:B550164F724F1FF24D10D79B8DF4945E
SHA256:F5E6016BD08EC116F6A62B4AA0739E1541B3A80CFEA56A60E12EE84194F7E708
3612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3612.49273\Twitch God 2018 v1.1 (Vip Pro Edition).exeexecutable
MD5:A86A9B66D20FE9A4A8FE941A6DE03EB2
SHA256:C95DEBE690104C6B6D6FF94F36354B1A12E903CBD3A93E9E75020E1271EBDFB9
3612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3612.382\libeay32.dllexecutable
MD5:F9ECF79E96560B14FF941DBC9CEE5C0C
SHA256:B3BD997E176870C5E68DB8BA5C0024B80CE93C356C1868C2FBBB83B2CFD5AC4F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
21
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2664
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
200
173.254.28.147:80
http://www.babatools.com/pool.txt
US
text
4 b
malicious
2164
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
200
173.254.28.147:80
http://www.babatools.com/pool.txt
US
text
4 b
malicious
252
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
200
173.254.28.147:80
http://www.babatools.com/pool.txt
US
text
4 b
malicious
2584
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
200
173.254.28.147:80
http://www.babatools.com/pool.txt
US
text
4 b
malicious
3928
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
200
173.254.28.147:80
http://www.babatools.com/pool.txt
US
text
4 b
malicious
1028
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
200
173.254.28.147:80
http://www.babatools.com/pool.txt
US
text
4 b
malicious
3124
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
200
173.254.28.147:80
http://www.babatools.com/pool.txt
US
text
4 b
malicious
3236
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
200
173.254.28.147:80
http://www.babatools.com/pool.txt
US
text
4 b
malicious
2412
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
200
173.254.28.147:80
http://www.babatools.com/pool.txt
US
text
4 b
malicious
3948
Twitch God 2018 v1.1 (Vip Pro Edition).exe
GET
200
173.254.28.147:80
http://www.babatools.com/pool.txt
US
text
4 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3256
Twitch God 2018 v1.1 (Vip Pro Edition).exe
173.254.28.147:80
www.babatools.com
Unified Layer
US
malicious
3432
Twitch God 2018 v1.1 (Vip Pro Edition).exe
173.254.28.147:80
www.babatools.com
Unified Layer
US
malicious
252
Twitch God 2018 v1.1 (Vip Pro Edition).exe
173.254.28.147:80
www.babatools.com
Unified Layer
US
malicious
2664
Twitch God 2018 v1.1 (Vip Pro Edition).exe
173.254.28.147:80
www.babatools.com
Unified Layer
US
malicious
324
Twitch God 2018 v1.1 (Vip Pro Edition).exe
173.254.28.147:80
www.babatools.com
Unified Layer
US
malicious
1336
Twitch God 2018 v1.1 (Vip Pro Edition).exe
173.254.28.147:80
www.babatools.com
Unified Layer
US
malicious
3928
Twitch God 2018 v1.1 (Vip Pro Edition).exe
173.254.28.147:80
www.babatools.com
Unified Layer
US
malicious
1028
Twitch God 2018 v1.1 (Vip Pro Edition).exe
173.254.28.147:80
www.babatools.com
Unified Layer
US
malicious
3236
Twitch God 2018 v1.1 (Vip Pro Edition).exe
173.254.28.147:80
www.babatools.com
Unified Layer
US
malicious
2584
Twitch God 2018 v1.1 (Vip Pro Edition).exe
173.254.28.147:80
www.babatools.com
Unified Layer
US
malicious

DNS requests

Domain
IP
Reputation
www.babatools.com
  • 173.254.28.147
unknown

Threats

No threats detected
No debug info