File name:

twitch_chat_bot.rar

Full analysis: https://app.any.run/tasks/5ef52f55-49b8-4b33-8c96-3bbc89c85af7
Verdict: Malicious activity
Analysis date: January 17, 2022, 17:17:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

17AB1A241EC1593F7643509EFEB334FA

SHA1:

66202065F120D5086FC3E9936F09C3774ECE7DF0

SHA256:

B684DE3A6126E1B09337E8F2BE3F19CCA347081D6A4E1B7481639C3BACBC869F

SSDEEP:

12288:+jb7GVkyFhYHdyfXrr4QZViBocIl0APzxbwJ:+bybFKHYPCBFIBPzE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ATWITCHBC.exe (PID: 3420)
    • Loads dropped or rewritten executable

      • ATWITCHBC.exe (PID: 3420)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 1256)
      • ATWITCHBC.exe (PID: 3420)
    • Checks supported languages

      • WinRAR.exe (PID: 1256)
      • ATWITCHBC.exe (PID: 3420)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 1256)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1256)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1256)
  • INFO

    • Checks supported languages

      • WISPTIS.EXE (PID: 3244)
    • Reads the computer name

      • WISPTIS.EXE (PID: 3244)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
4
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start winrar.exe atwitchbc.exe no specs wisptis.exe no specs wisptis.exe

Process information

PID
CMD
Path
Indicators
Parent process
1256"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\twitch_chat_bot.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3244"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXE
ATWITCHBC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3420"C:\Users\admin\AppData\Local\Temp\Rar$EXa1256.3380\twitch chat bot\ATWITCHBC.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1256.3380\twitch chat bot\ATWITCHBC.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
ATWITCHBC
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1256.3380\twitch chat bot\atwitchbc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3440"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXEATWITCHBC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\wisptis.exe
Total events
1 424
Read events
1 358
Write events
66
Delete events
0

Modification events

(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1256) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\twitch_chat_bot.rar
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1256) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
5
Suspicious files
0
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
1256WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1256.3380\twitch chat bot\ATWITCHBC.exeexecutable
MD5:E723EE7C3A84C44FA4646111A3B2FB82
SHA256:9962E85530591CE5AF72F705F810F5C8F4D825F908056AC060BF812E662610B9
1256WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1256.3380\twitch chat bot\ATWITCHBC.pdbpdb
MD5:A2C8093CA7B1D937234A259203D20C78
SHA256:D8507596F0E02A0817A0F38282DA7487EF0156D25966A38CE8D7D9CE629450DC
1256WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1256.3380\twitch chat bot\WebSocket4Net.dllexecutable
MD5:A9347266E1679E90C5DA2B3C1E5A45EE
SHA256:AD2E17F110CDE9BC5609589CD89B4BF3A1D0249E3075597862B8A358D7E15EB2
1256WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1256.3380\twitch chat bot\ATWITCHBC.exe.configxml
MD5:EF0181DE18EF3951806C0AD63B897BA4
SHA256:E8DECC96235B5494880083EB79C22C84C6D9EF312828BAF9490BEE7782C350EC
1256WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1256.3380\twitch chat bot\SuperSocket.ClientEngine.dllexecutable
MD5:BCA39F02EA86AB13E44B17A2028CDAF0
SHA256:30C619D93D05612253901F829977196D803AB68C04B19EC87358ADC2C572E683
1256WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1256.3380\twitch chat bot\Newtonsoft.Json.dllexecutable
MD5:F33CBE589B769956284868104686CC2D
SHA256:973FD70CE48E5AC433A101B42871680C51E2FEBA2AEEC3D400DEA4115AF3A278
1256WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1256.3380\twitch chat bot\TwitchLib.dllexecutable
MD5:A405D3838F5228964514C4F30471CAAC
SHA256:8BDED35BC773E693898F4B13664CB81A4DB799F25ACD73B4DF13019B31EB1FCE
1256WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1256.3380\twitch chat bot\Newtonsoft.Json.xmlxml
MD5:2866A8E5449957C9B303AD800E55BF04
SHA256:42A557F912E050E91F255942C6E6948F6AE3AE5928000AD1DCEF88666BB77A2F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info