File name:

Chat R with Chat Scripts.rar

Full analysis: https://app.any.run/tasks/1f9a0443-25d2-487d-8549-beb87e3d6ed3
Verdict: Malicious activity
Analysis date: November 12, 2018, 03:45:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

023097462F10CBA40BDAADE69A837294

SHA1:

6E42926EF43FD743C6612B7054ECBBB813E9A966

SHA256:

5C0CC612CBE9EB64D1CA2965410B750F058952CE907EA30D84D5CAE02B9302F8

SSDEEP:

196608:ZwD5xjTklxPgM9xFQU9YChF6G8wgVEjdgqkbVdaJOkf/0Ui8:ZAvjTsgM9xRz6/2jdJkbVd2Okn0Ui8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • chatr.exe (PID: 1540)
    • Application was dropped or rewritten from another process

      • node.exe (PID: 3556)
      • chatr.exe (PID: 1540)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 628)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 6062
UncompressedSize: 12800
OperatingSystem: Win32
ModifyDate: 2014:11:29 13:01:15
PackingMethod: Normal
ArchivedFileName: mime\core.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe chatr.exe no specs node.exe

Process information

PID
CMD
Path
Indicators
Parent process
628"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Chat R with Chat Scripts.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1540"C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\chatr.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\chatr.exeWinRAR.exe
User:
admin
Company:
Shadiku Izayoi & Emma Skye
Integrity Level:
MEDIUM
Description:
streamsuite | chatr
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa628.38265\chatr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rar$exa628.38265\lua5.1.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3556"C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\Server\node.exe" "C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\Server\chat.js"C:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\Server\node.exe
chatr.exe
User:
admin
Company:
Joyent, Inc
Integrity Level:
MEDIUM
Description:
Evented I/O for V8 JavaScript
Exit code:
0
Version:
0.10.26
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa628.38265\server\node.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
484
Read events
469
Write events
15
Delete events
0

Modification events

(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(628) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Chat R with Chat Scripts.rar
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
26
Suspicious files
1
Text files
76
Unknown types
2

Dropped files

PID
Process
Filename
Type
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap10.datimage
MD5:
SHA256:
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap14.datimage
MD5:7EBBF44F4172618993A396900B722E00
SHA256:BBAEEA0192A5B98F2E2C9B43E4536DC8F392E4A37479C972249CAAB575338841
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap11.datimage
MD5:0AA5B2CBA78B529CA35EDF2A1315B753
SHA256:A84615F3D7A6649381F8CE26B9E1917E3C042D442DBB39EE5FAB0B763A9DB8CF
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap12.datimage
MD5:5CFAEE34212E627EB18F10B0CD6D6653
SHA256:870113FED72D41D0EC736FC8DD4D0F6B496BD417C1669D1BD45B3FCA41060029
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\mime\core.dllexecutable
MD5:69EAB91A34647D8EF0FF0152391160F2
SHA256:976B7B17F2663FEE38D4C4B1C251269F862785B17343F34479732BF9DDD29657
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap13.datimage
MD5:B1947165F71CDEE1597118AF58C7AA5C
SHA256:F7EFB0EFAB796EE54016B4C4BC7E0260E9728A0BD387A1E38067AE63722FA672
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap16.datimage
MD5:9D3A9C3F6A1453C45DF84E262E6DDF17
SHA256:B5F1BD87DBF4D1A20D49FD00715785AEA1376BDDD68C2A0E43C66EBB689BCB5B
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap27.datimage
MD5:
SHA256:
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap26.datimage
MD5:
SHA256:
628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa628.38265\resources\dat01\ap15.datimage
MD5:B3B95C3A569DBA792141ED2A62013E80
SHA256:03F6517F6D31929CAE671A6E365DDD29AD172C892287F4AA14FD4416A97AE029
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

Domain
IP
Reputation
irc.twitch.tv
  • 54.213.59.83
  • 54.213.125.211
  • 54.187.1.183
  • 52.39.2.72
  • 52.35.150.60
  • 54.68.215.124
unknown

Threats

No threats detected
No debug info