File name:

YouBotTube_Commenter_Free_Extracts_By_WinRAR.zip

Full analysis: https://app.any.run/tasks/a36e32b7-1af1-4cd9-a941-97658e00a664
Verdict: Malicious activity
Analysis date: March 25, 2020, 14:59:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.3
MD5:

DF7EB17F73F2D09DDFCEC3285E2A2A4A

SHA1:

64DD620071349E70AF8C5A8F693B4EB4627B17F1

SHA256:

7101167200D2C63D975391809FEB2AF60C466E639884A95C2BA63A79EA8250A8

SSDEEP:

196608:gSgj74kEqxJHc41jp5kTR9AFXlHvjab8A72mozaEU6zNb2:HgjTxJHl1F5gR2FXBLh3m+HUMNb2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • YouBotTube Commenter Free.exe (PID: 1536)
      • YouBotTubeDebug.exe (PID: 604)
      • YouBotTubeDebug.exe (PID: 3212)
    • Loads dropped or rewritten executable

      • YouBotTube Commenter Free.exe (PID: 1536)
      • YouBotTubeDebug.exe (PID: 3212)
      • YouBotTubeDebug.exe (PID: 604)
    • Starts Visual C# compiler

      • YouBotTube Commenter Free.exe (PID: 1536)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3756)
      • YouBotTube Commenter Free.exe (PID: 1536)
    • Creates files in the program directory

      • YouBotTube Commenter Free.exe (PID: 1536)
    • Reads Internet Cache Settings

      • YouBotTubeDebug.exe (PID: 3212)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (gen) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe youbottube commenter free.exe csc.exe no specs cvtres.exe no specs youbottubedebug.exe youbottubedebug.exe

Process information

PID
CMD
Path
Indicators
Parent process
604"C:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTubeDll\YouBotTubeDebug.exe" true||||||||||||C:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTubeDll\DebugFile\3dc46188e3b44c9ba3b7c1a8a59487eb.dat||||||C:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTubeDll\DebugFile\f607bc30a41943e6ab8aa86d04b532a0.txt||||||C:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTubeDll\CacheFiles\62ec2a093bca45d9bca33ce908aaa222C:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTubeDll\YouBotTubeDebug.exe
YouBotTube Commenter Free.exe
User:
admin
Company:
WhiteHatBox.com
Integrity Level:
MEDIUM
Description:
BotChiefDebug
Exit code:
1
Version:
4.7.8.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3756.24992\youbottubedll\youbottubedebug.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1536"C:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTube Commenter Free.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTube Commenter Free.exe
WinRAR.exe
User:
admin
Company:
WhiteHatBox.com
Integrity Level:
MEDIUM
Description:
ComplieCustom
Exit code:
0
Version:
4.7.8.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3756.24992\youbottube commenter free.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1712C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES256.tmp" "c:\Users\admin\AppData\Local\Temp\CSC245.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.4940 (Win7SP1.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
3212"C:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTubeDll\YouBotTubeDebug.exe" true||||||||||||C:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTubeDll\DebugFile\f1ac96909d2649d399ff7133f96af025.dat||||||C:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTubeDll\DebugFile\2c93779ac4804848845c3b1343c72480.txt||||||C:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTubeDll\CacheFiles\30cc86e42cea4c04b3b1abbb832de566C:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTubeDll\YouBotTubeDebug.exe
YouBotTube Commenter Free.exe
User:
admin
Company:
WhiteHatBox.com
Integrity Level:
MEDIUM
Description:
BotChiefDebug
Exit code:
1
Version:
4.7.8.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3756.24992\youbottubedll\youbottubedebug.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3740"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\yfpte20r.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exeYouBotTube Commenter Free.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.4927 (NetFXspW7.050727-4900)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3756"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\YouBotTube_Commenter_Free_Extracts_By_WinRAR.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
Total events
1 651
Read events
1 545
Write events
105
Delete events
1

Modification events

(PID) Process:(3756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3756) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\YouBotTube_Commenter_Free_Extracts_By_WinRAR.zip
(PID) Process:(3756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1536) YouBotTube Commenter Free.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
57
Suspicious files
30
Text files
16
Unknown types
14

Dropped files

PID
Process
Filename
Type
3756WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTube Commenter Free.exe.configxml
MD5:
SHA256:
3756WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\Update.exeexecutable
MD5:
SHA256:
3756WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\save\sinfo.inftext
MD5:
SHA256:
3756WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTube Commenter Free.exeexecutable
MD5:
SHA256:
3756WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTubeDll\YouBotTubeDebug.exeexecutable
MD5:
SHA256:
3756WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\7z1.dllexecutable
MD5:42EDF51C86E726F00379CCBDAD2BC796
SHA256:F7E6FB7F23AC191CCAE310DEAEA112D03A17D507755D3E041D4213C02AD7BE9D
3756WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\save\rinfo.datbinary
MD5:
SHA256:
3756WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\DevComponents.DotNetBar2.dllodttf
MD5:03741F3028D8B3BCD843D7B4DE357F3C
SHA256:DDC915C74D5E53253C71F2AE9A57A1466646742A3A3739E078EBACDDCD66397E
3756WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTubeDll\WhbPack.exeexecutable
MD5:864312B81B9E0E0C13837FE1E4886F91
SHA256:B295FCEC9A952DD57D980D71832164C110BEE37C5ADC912C2722BB1EFB7C2A69
3756WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3756.24992\YouBotTubeDll\MailBee.NET.dllexecutable
MD5:675D51B8B09BE135219AB861952F9FD4
SHA256:1BCC5E84D759107F058EA29742FF580008318F8F888D5F4CCE286BCF8262AF90
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
33
DNS requests
21
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1536
YouBotTube Commenter Free.exe
GET
200
104.28.14.20:80
http://www.botchief.com/IbotUpdate/browserinfo.txt
US
text
419 b
malicious
1536
YouBotTube Commenter Free.exe
GET
200
104.28.14.20:80
http://www.botchief.com/xulrunner29.0.zip
US
compressed
19.5 Mb
malicious
3212
YouBotTubeDebug.exe
POST
200
172.217.23.131:80
http://ocsp.pki.goog/gts1o1
US
der
472 b
whitelisted
3212
YouBotTubeDebug.exe
POST
200
172.217.23.131:80
http://ocsp.pki.goog/gts1o1
US
der
471 b
whitelisted
3212
YouBotTubeDebug.exe
POST
200
172.217.23.131:80
http://ocsp.pki.goog/gts1o1
US
der
472 b
whitelisted
3212
YouBotTubeDebug.exe
POST
200
172.217.23.131:80
http://ocsp.pki.goog/gts1o1
US
der
472 b
whitelisted
3212
YouBotTubeDebug.exe
POST
200
172.217.23.131:80
http://ocsp.pki.goog/gts1o1
US
der
472 b
whitelisted
3212
YouBotTubeDebug.exe
POST
200
172.217.23.131:80
http://ocsp.pki.goog/gts1o1
US
der
472 b
whitelisted
3212
YouBotTubeDebug.exe
POST
200
172.217.23.131:80
http://ocsp.pki.goog/gts1o1
US
der
471 b
whitelisted
3212
YouBotTubeDebug.exe
POST
200
172.217.23.131:80
http://ocsp.pki.goog/gts1o1
US
der
472 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1536
YouBotTube Commenter Free.exe
104.28.14.20:80
www.botchief.com
Cloudflare Inc
US
shared
3212
YouBotTubeDebug.exe
162.144.212.52:443
www.apps1store.com
Unified Layer
US
unknown
3212
YouBotTubeDebug.exe
104.17.64.4:443
cdnjs.cloudflare.com
Cloudflare Inc
US
unknown
3212
YouBotTubeDebug.exe
172.217.22.78:443
www.youtube.com
Google Inc.
US
whitelisted
3212
YouBotTubeDebug.exe
209.197.3.15:443
maxcdn.bootstrapcdn.com
Highwinds Network Group, Inc.
US
whitelisted
3212
YouBotTubeDebug.exe
172.217.23.106:443
ajax.googleapis.com
Google Inc.
US
whitelisted
3212
YouBotTubeDebug.exe
198.252.99.143:443
buyimdbvotes.com
Colo4, LLC
US
unknown
3212
YouBotTubeDebug.exe
172.217.18.163:443
www.gstatic.com
Google Inc.
US
whitelisted
3212
YouBotTubeDebug.exe
172.217.23.131:80
ocsp.pki.goog
Google Inc.
US
whitelisted
3212
YouBotTubeDebug.exe
216.58.208.34:443
googleads.g.doubleclick.net
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
www.botchief.com
  • 104.28.14.20
  • 104.28.15.20
malicious
www.apps1store.com
  • 162.144.212.52
unknown
cdnjs.cloudflare.com
  • 104.17.64.4
  • 104.17.65.4
whitelisted
ajax.googleapis.com
  • 172.217.23.106
whitelisted
maxcdn.bootstrapcdn.com
  • 209.197.3.15
whitelisted
www.youtube.com
  • 172.217.22.78
  • 172.217.23.110
  • 172.217.16.206
  • 216.58.207.78
  • 172.217.18.14
  • 172.217.18.110
  • 216.58.206.14
  • 172.217.22.14
  • 172.217.23.174
  • 172.217.21.238
  • 172.217.22.110
whitelisted
buyimdbvotes.com
  • 198.252.99.143
unknown
www.gstatic.com
  • 172.217.18.163
whitelisted
ocsp.pki.goog
  • 172.217.23.131
whitelisted
googleads.g.doubleclick.net
  • 216.58.208.34
whitelisted

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
Process
Message
YouBotTube Commenter Free.exe
Gecko.Xpcom.DirectoryServiceProvider.GetFile: not implemented: permissionDBPDir
YouBotTube Commenter Free.exe
Gecko.Xpcom.DirectoryServiceProvider.GetFile: not implemented: LclSt
YouBotTube Commenter Free.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
YouBotTube Commenter Free.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
YouBotTubeDebug.exe
Gecko.Xpcom.DirectoryServiceProvider.GetFile: not implemented: permissionDBPDir
YouBotTubeDebug.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
YouBotTubeDebug.exe
Gecko.Xpcom.DirectoryServiceProvider.GetFile: not implemented: LclSt
YouBotTubeDebug.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
YouBotTubeDebug.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
YouBotTubeDebug.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144