| File name: | Chat R with Chat Scripts.rar |
| Full analysis: | https://app.any.run/tasks/1f9a0443-25d2-487d-8549-beb87e3d6ed3 |
| Verdict: | Malicious activity |
| Analysis date: | November 12, 2018, 03:45:41 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 023097462F10CBA40BDAADE69A837294 |
| SHA1: | 6E42926EF43FD743C6612B7054ECBBB813E9A966 |
| SHA256: | 5C0CC612CBE9EB64D1CA2965410B750F058952CE907EA30D84D5CAE02B9302F8 |
| SSDEEP: | 196608:ZwD5xjTklxPgM9xFQU9YChF6G8wgVEjdgqkbVdaJOkf/0Ui8:ZAvjTsgM9xRz6/2jdJkbVd2Okn0Ui8 |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 6062 |
|---|---|
| UncompressedSize: | 12800 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2014:11:29 13:01:15 |
| PackingMethod: | Normal |
| ArchivedFileName: | mime\core.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 628 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Chat R with Chat Scripts.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 1540 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\chatr.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\chatr.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Shadiku Izayoi & Emma Skye Integrity Level: MEDIUM Description: streamsuite | chatr Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 3556 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\Server\node.exe" "C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\Server\chat.js" | C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\Server\node.exe | chatr.exe | ||||||||||||
User: admin Company: Joyent, Inc Integrity Level: MEDIUM Description: Evented I/O for V8 JavaScript Exit code: 0 Version: 0.10.26 Modules
| |||||||||||||||
| (PID) Process: | (628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (628) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Chat R with Chat Scripts.rar | |||
| (PID) Process: | (628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (628) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap15.dat | image | |
MD5:— | SHA256:— | |||
| 628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap16.dat | image | |
MD5:— | SHA256:— | |||
| 628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap10.dat | image | |
MD5:— | SHA256:— | |||
| 628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap14.dat | image | |
MD5:7EBBF44F4172618993A396900B722E00 | SHA256:BBAEEA0192A5B98F2E2C9B43E4536DC8F392E4A37479C972249CAAB575338841 | |||
| 628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap2.dat | ogg | |
MD5:FC2A595F574B1EAD82A6DCF06492C985 | SHA256:EE9A4903A8DF90EFF4C5B65A8073E564A3581CF73772A72EB82396E69932E769 | |||
| 628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap17.dat | image | |
MD5:42492684E24356A4081134894EABEB9E | SHA256:D04ECFC93FF86C44F6FC39E35945E3D8A7648BA8FCD97A2635920DF2E88893B3 | |||
| 628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap13.dat | image | |
MD5:B1947165F71CDEE1597118AF58C7AA5C | SHA256:F7EFB0EFAB796EE54016B4C4BC7E0260E9728A0BD387A1E38067AE63722FA672 | |||
| 628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap18.dat | image | |
MD5:9BEB56FDC5D0056EE3F6C3AC7E9852E8 | SHA256:DC80146D74B99F4FE90D7C88262333F2265851D9547A124360B27396D55F9490 | |||
| 628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap20.dat | image | |
MD5:E9932A88C8BA497BBFD48787A4F94A29 | SHA256:AFA2516A4BEC08F55A1B537F57AD0381D3AC5CAFE70CDE272A77C5BD20A49110 | |||
| 628 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap12.dat | image | |
MD5:5CFAEE34212E627EB18F10B0CD6D6653 | SHA256:870113FED72D41D0EC736FC8DD4D0F6B496BD417C1669D1BD45B3FCA41060029 | |||
Domain | IP | Reputation |
|---|---|---|
irc.twitch.tv |
| unknown |