File name: | Growtopia spamb bot V1.1.rar |
Full analysis: | https://app.any.run/tasks/3d76ed11-a473-496c-89b3-d2058e02f930 |
Verdict: | Malicious activity |
Analysis date: | January 17, 2020, 18:39:53 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | image/jpeg |
File info: | JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], progressive, precision 8, 520x340, frames 3 |
MD5: | 06A248F6A18C82839F510542B85569C2 |
SHA1: | 2E0F07C164EF3080696614E4AA4454480F66D768 |
SHA256: | A9F1B1118F956802251D60FD7E26B1792383FDE08DD1DD8A1A8C5072D53132FF |
SSDEEP: | 384:bbhVi+bNSNXMlZ/lKB1sk/F967ZRpCetibJDhskDJ5M7VDdxKb7hUnGj:bbrns87/lIyeF87Hp/cHLMBObCGj |
.jpg | | | JFIF-EXIF JPEG Bitmap (55.5) |
---|---|---|
.jpg | | | JPEG bitmap (33.3) |
.mp3 | | | MP3 audio (11.1) |
Quality: | 60% |
---|
DCTEncodeVersion: | 100 |
---|---|
APP14Flags0: | [14], Encoded with Blend=1 downsampling |
APP14Flags1: | (none) |
ColorTransform: | YCbCr |
ImageSize: | 520x340 |
---|---|
Megapixels: | 0.177 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2480 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Growtopia spamb bot V1.1.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 | ||||
2660 | "C:\Users\admin\Desktop\Growtopia spam bot V1.1.exe" | C:\Users\admin\Desktop\Growtopia spam bot V1.1.exe | explorer.exe | |
User: admin Integrity Level: MEDIUM Description: growtopia spammer Exit code: 0 Version: 1.0.0.0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2480 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2480.41793\Growtopia spam bot V1.1.exe | executable | |
MD5:755B898800B2285D899B7DDF2E50B5B7 | SHA256:3C2658F919DFF21A0EC98CCBE077BB7405E4B3F49C2D060762792F7F33EAC4AA |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2660 | Growtopia spam bot V1.1.exe | 173.194.76.109:587 | smtp.gmail.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
smtp.gmail.com |
| shared |
PID | Process | Class | Message |
---|---|---|---|
2660 | Growtopia spam bot V1.1.exe | Generic Protocol Command Decode | SURICATA Applayer Detect protocol only one direction |