File name:

Youtube Bot.exe

Full analysis: https://app.any.run/tasks/f4ba68fc-f1bf-4de8-a77d-b78fa242c2db
Verdict: Malicious activity
Analysis date: September 01, 2024, 11:44:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

1E7178EF935673DE04BEB1EAD6F0B0B7

SHA1:

23401BA36DCB4EBA9985BBEA10A31F577369FA67

SHA256:

78C4EC6FE019CF13F910FCFE2EFBA1495C54D195B10B86DF9556B65718419C70

SSDEEP:

98304:DpVIVrkUBasBpVb3UeDT4WO9kLvPMCaqfV81hJUNN5aUud2epJc2PPLktcj5Y4bz:KT+dhj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Youtube Bot.exe (PID: 5732)
    • Reads security settings of Internet Explorer

      • YoutubeCommenterAndRater.exe (PID: 3328)
    • Executable content was dropped or overwritten

      • Youtube Bot.exe (PID: 5732)
    • The process drops C-runtime libraries

      • Youtube Bot.exe (PID: 5732)
    • Creates a software uninstall entry

      • Youtube Bot.exe (PID: 5732)
    • There is functionality for communication over UDP network (YARA)

      • YoutubeCommenterAndRater.exe (PID: 3328)
    • Drops the executable file immediately after the start

      • Youtube Bot.exe (PID: 5732)
    • There is functionality for taking screenshot (YARA)

      • YoutubeCommenterAndRater.exe (PID: 3328)
  • INFO

    • Create files in a temporary directory

      • Youtube Bot.exe (PID: 5732)
    • Checks supported languages

      • Youtube Bot.exe (PID: 5732)
      • YoutubeCommenterAndRater.exe (PID: 3328)
    • Creates files in the program directory

      • Youtube Bot.exe (PID: 5732)
      • YoutubeCommenterAndRater.exe (PID: 3328)
    • Creates files or folders in the user directory

      • Youtube Bot.exe (PID: 5732)
    • Reads the computer name

      • YoutubeCommenterAndRater.exe (PID: 3328)
      • Youtube Bot.exe (PID: 5732)
    • Checks proxy server information

      • YoutubeCommenterAndRater.exe (PID: 3328)
    • Reads the software policy settings

      • slui.exe (PID: 2112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (91.9)
.exe | Win32 Executable MS Visual C++ (generic) (3.3)
.exe | Win64 Executable (generic) (3)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2008:08:16 20:26:20+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 23552
InitializedDataSize: 164864
UninitializedDataSize: 1024
EntryPoint: 0x30e3
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start youtube bot.exe sppextcomobj.exe no specs slui.exe THREAT youtubecommenterandrater.exe slui.exe no specs youtube bot.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2112"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3328"C:\Program Files (x86)\Captcha-Hacker Youtube Rater and Commenter\YoutubeCommenterAndRater.exe"C:\Program Files (x86)\Captcha-Hacker Youtube Rater and Commenter\YoutubeCommenterAndRater.exe
Youtube Bot.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\program files (x86)\captcha-hacker youtube rater and commenter\youtubecommenterandrater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4980"C:\Users\admin\AppData\Local\Temp\Youtube Bot.exe" C:\Users\admin\AppData\Local\Temp\Youtube Bot.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\youtube bot.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5112C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5732"C:\Users\admin\AppData\Local\Temp\Youtube Bot.exe" C:\Users\admin\AppData\Local\Temp\Youtube Bot.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\youtube bot.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6484C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
4 676
Read events
4 666
Write events
10
Delete events
0

Modification events

(PID) Process:(5732) Youtube Bot.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Captcha-Hacker Youtube Rater and Commenter
Operation:writeName:DisplayName
Value:
Captcha-Hacker Youtube Rater and Commenter
(PID) Process:(5732) Youtube Bot.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Captcha-Hacker Youtube Rater and Commenter
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\Captcha-Hacker Youtube Rater and Commenter\uninstall.exe"
(PID) Process:(3328) YoutubeCommenterAndRater.exeKey:HKEY_CURRENT_USER\SOFTWARE\captchahacker\chytcndr\Updates
Operation:writeName:UseProxy
Value:
0
(PID) Process:(3328) YoutubeCommenterAndRater.exeKey:HKEY_CURRENT_USER\SOFTWARE\captchahacker\chytcndr\Updates
Operation:writeName:ProxyType
Value:
0
(PID) Process:(3328) YoutubeCommenterAndRater.exeKey:HKEY_CURRENT_USER\SOFTWARE\captchahacker\chytcndr\Updates
Operation:writeName:ProxyAddr
Value:
(PID) Process:(3328) YoutubeCommenterAndRater.exeKey:HKEY_CURRENT_USER\SOFTWARE\captchahacker\chytcndr\Updates
Operation:writeName:ProxyPort
Value:
0
(PID) Process:(3328) YoutubeCommenterAndRater.exeKey:HKEY_CURRENT_USER\SOFTWARE\captchahacker\chytcndr\Updates
Operation:writeName:ProxyUser
Value:
(PID) Process:(3328) YoutubeCommenterAndRater.exeKey:HKEY_CURRENT_USER\SOFTWARE\captchahacker\chytcndr\Updates
Operation:writeName:ProxyPass
Value:
(PID) Process:(3328) YoutubeCommenterAndRater.exeKey:HKEY_CURRENT_USER\SOFTWARE\captchahacker\chytcndr\Updates
Operation:writeName:UpdateType
Value:
0
(PID) Process:(3328) YoutubeCommenterAndRater.exeKey:HKEY_CURRENT_USER\SOFTWARE\captchahacker\chytcndr\Updates
Operation:writeName:UpdateDays
Value:
1
Executable files
10
Suspicious files
5
Text files
14
Unknown types
0

Dropped files

PID
Process
Filename
Type
5732Youtube Bot.exeC:\Program Files (x86)\Captcha-Hacker Youtube Rater and Commenter\Subjects.txttext
MD5:DCCF7E9454B11AA7C5B4CA672D326578
SHA256:445C305768BAF733FE990A2BCEF9647B5F646E15223B1BF2E0D885DFAFD1A1E4
5732Youtube Bot.exeC:\Program Files (x86)\Captcha-Hacker Youtube Rater and Commenter\contires_html.txttext
MD5:9A9DE856A207D8D5E744145D4602DE85
SHA256:6284034D6E0A514E7CFEFD3263C9ECC77751E699A011EE11BE9EAB84FF378FF2
5732Youtube Bot.exeC:\Program Files (x86)\Captcha-Hacker Youtube Rater and Commenter\ib_util.dllexecutable
MD5:95DD5A0AADC156571F675FB3E101C7BB
SHA256:EEE725A6F7A1DDC80A4B1218709676609D1368C66BA3C2A0CB69E3A8BE222A47
5732Youtube Bot.exeC:\Program Files (x86)\Captcha-Hacker Youtube Rater and Commenter\icudt30.dllexecutable
MD5:C9B5E4AD62B47867CB345B4761D5F0D4
SHA256:69696D5ED77BAA76A6E2319391E3C1A53B9088039E7E131976217899CB9D1632
5732Youtube Bot.exeC:\Program Files (x86)\Captcha-Hacker Youtube Rater and Commenter\icuuc30.dllexecutable
MD5:392EAA0A0B128C829A5A127DA4B57645
SHA256:A66E66A42FF21E9AE19D52212BF668E3796EF0A35307DD84313357B2D53128DF
5732Youtube Bot.exeC:\Program Files (x86)\Captcha-Hacker Youtube Rater and Commenter\yt_categories.txttext
MD5:FF8C3D48D061B1415AD67937AF839FA3
SHA256:5FB39A598B1EF733174EDF2D9DBAC04DD18BD2FCE46186D4D604E65359BBBF82
5732Youtube Bot.exeC:\Program Files (x86)\Captcha-Hacker Youtube Rater and Commenter\updater.exeexecutable
MD5:D8CB1A4B1C319D1D8BC2FEE5BFF21A09
SHA256:CB680AC5D3C1678BB4EEC185C93D48032EF6FBA4071EA20E906640DE34D80C61
5732Youtube Bot.exeC:\Program Files (x86)\Captcha-Hacker Youtube Rater and Commenter\msvcp80.dllexecutable
MD5:2BC650257FB0867ABD54FD460EC2BAFC
SHA256:9FC2E85BA84CF0459AAB0DC2EFAC734AD7B5B4C99BA19871FE8F6E35D0191838
5732Youtube Bot.exeC:\Program Files (x86)\Captcha-Hacker Youtube Rater and Commenter\useragents.txttext
MD5:8A6A2C5EF6B2B1AC68E11E8885FA5156
SHA256:AD3410A09EF51099D18956CE95E7A223CE37F97D5CEDF8BE464EB295EBB3B197
5732Youtube Bot.exeC:\Program Files (x86)\Captcha-Hacker Youtube Rater and Commenter\Keys\%key%.txttext
MD5:23AB09FB0B822A4D8D37295E7F26E87A
SHA256:A8B80D0BDBE3E787867B63CF5E5DABEEAC199555D1FDEC0BB5E581299E379A4E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
27
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2400
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3328
YoutubeCommenterAndRater.exe
GET
200
13.248.169.48:80
http://www.foocs.com/chytcndr/update.xml
unknown
whitelisted
1764
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2400
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6192
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6252
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1764
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1764
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2400
SIHClient.exe
40.127.169.103:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2400
SIHClient.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.142
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
login.live.com
  • 20.190.159.23
  • 20.190.159.0
  • 20.190.159.2
  • 20.190.159.4
  • 20.190.159.75
  • 40.126.31.67
  • 20.190.159.64
  • 40.126.31.73
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 40.127.169.103
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.166.126.56
whitelisted
www.foocs.com
  • 13.248.169.48
  • 76.223.54.146
unknown
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info