File name:

Chat R with Chat Scripts.rar

Full analysis: https://app.any.run/tasks/1f9a0443-25d2-487d-8549-beb87e3d6ed3
Verdict: Malicious activity
Analysis date: November 12, 2018, 03:45:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

023097462F10CBA40BDAADE69A837294

SHA1:

6E42926EF43FD743C6612B7054ECBBB813E9A966

SHA256:

5C0CC612CBE9EB64D1CA2965410B750F058952CE907EA30D84D5CAE02B9302F8

SSDEEP:

196608:ZwD5xjTklxPgM9xFQU9YChF6G8wgVEjdgqkbVdaJOkf/0Ui8:ZAvjTsgM9xRz6/2jdJkbVd2Okn0Ui8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • node.exe (PID: 3556)
      • chatr.exe (PID: 1540)
    • Loads dropped or rewritten executable

      • chatr.exe (PID: 1540)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 628)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 6062
UncompressedSize: 12800
OperatingSystem: Win32
ModifyDate: 2014:11:29 13:01:15
PackingMethod: Normal
ArchivedFileName: mime\core.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe chatr.exe no specs node.exe

Process information

PID
CMD
Path
Indicators
Parent process
628"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Chat R with Chat Scripts.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1540"C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\chatr.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\chatr.exeWinRAR.exe
User:
admin
Company:
Shadiku Izayoi & Emma Skye
Integrity Level:
MEDIUM
Description:
streamsuite | chatr
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa628.38265\chatr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rar$exa628.38265\lua5.1.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3556"C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\Server\node.exe" "C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\Server\chat.js"C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\Server\node.exe
chatr.exe
User:
admin
Company:
Joyent, Inc
Integrity Level:
MEDIUM
Description:
Evented I/O for V8 JavaScript
Exit code:
0
Version:
0.10.26
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa628.38265\server\node.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
484
Read events
469
Write events
15
Delete events
0

Modification events

(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(628) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Chat R with Chat Scripts.rar
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
26
Suspicious files
1
Text files
76
Unknown types
2

Dropped files

PID
Process
Filename
Type
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap15.datimage
MD5:
SHA256:
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap16.datimage
MD5:
SHA256:
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap10.datimage
MD5:
SHA256:
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap14.datimage
MD5:7EBBF44F4172618993A396900B722E00
SHA256:BBAEEA0192A5B98F2E2C9B43E4536DC8F392E4A37479C972249CAAB575338841
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap2.datogg
MD5:FC2A595F574B1EAD82A6DCF06492C985
SHA256:EE9A4903A8DF90EFF4C5B65A8073E564A3581CF73772A72EB82396E69932E769
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap17.datimage
MD5:42492684E24356A4081134894EABEB9E
SHA256:D04ECFC93FF86C44F6FC39E35945E3D8A7648BA8FCD97A2635920DF2E88893B3
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap13.datimage
MD5:B1947165F71CDEE1597118AF58C7AA5C
SHA256:F7EFB0EFAB796EE54016B4C4BC7E0260E9728A0BD387A1E38067AE63722FA672
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap18.datimage
MD5:9BEB56FDC5D0056EE3F6C3AC7E9852E8
SHA256:DC80146D74B99F4FE90D7C88262333F2265851D9547A124360B27396D55F9490
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap20.datimage
MD5:E9932A88C8BA497BBFD48787A4F94A29
SHA256:AFA2516A4BEC08F55A1B537F57AD0381D3AC5CAFE70CDE272A77C5BD20A49110
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap12.datimage
MD5:5CFAEE34212E627EB18F10B0CD6D6653
SHA256:870113FED72D41D0EC736FC8DD4D0F6B496BD417C1669D1BD45B3FCA41060029
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

Domain
IP
Reputation
irc.twitch.tv
  • 54.213.59.83
  • 54.213.125.211
  • 54.187.1.183
  • 52.39.2.72
  • 52.35.150.60
  • 54.68.215.124
unknown

Threats

No threats detected
No debug info