File name: | Twitch_Bots-1.rar |
Full analysis: | https://app.any.run/tasks/2c0bb48d-bdaf-4a43-b9f6-82691d186652 |
Verdict: | Malicious activity |
Analysis date: | November 29, 2020, 20:40:17 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v5 |
MD5: | FCE7F6708727C612E65AAFE80D34425A |
SHA1: | 74CF0FB3C2876A46A9DDC450E7CFF4F53DB3687C |
SHA256: | C22E594C012DC7BC7E2A6EB6AF328808AA3ECFE0E1760F1CD670E07A2A36117B |
SSDEEP: | 49152:KpKMdViPqw3TbcEGfyuty2C9sCrWd4O4Z2DiIpGUKgNAMoEA2vxCUXtusZ53aMVU:MQqHE/j2C9RW6dAkUKrM4AxLFRmN |
.rar | | | RAR compressed archive (v5.0) (61.5) |
---|---|---|
.rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2672 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Twitch_Bots-1.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
2416 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Follow Bot\dottwitch.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Follow Bot\dottwitch.exe | — | WinRAR.exe |
User: admin Integrity Level: MEDIUM Description: dotTwitch Version: 1.0.0.0 |
(PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Twitch_Bots-1.rar | |||
(PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Chat Bot\WebSocket4Net.dll | executable | |
MD5:A9347266E1679E90C5DA2B3C1E5A45EE | SHA256:AD2E17F110CDE9BC5609589CD89B4BF3A1D0249E3075597862B8A358D7E15EB2 | |||
2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Chat Bot\SuperSocket.ClientEngine.dll | executable | |
MD5:BCA39F02EA86AB13E44B17A2028CDAF0 | SHA256:30C619D93D05612253901F829977196D803AB68C04B19EC87358ADC2C572E683 | |||
2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Chat Bot\ATWITCHBC.pdb | pdb | |
MD5:A2C8093CA7B1D937234A259203D20C78 | SHA256:D8507596F0E02A0817A0F38282DA7487EF0156D25966A38CE8D7D9CE629450DC | |||
2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Chat Bot\ATWITCHBC.exe.config | xml | |
MD5:EF0181DE18EF3951806C0AD63B897BA4 | SHA256:E8DECC96235B5494880083EB79C22C84C6D9EF312828BAF9490BEE7782C350EC | |||
2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Follow Bot\dottwitch.exe | executable | |
MD5:7E06F89C370AE02A6E88EB5DCAEC7CAB | SHA256:5338757B851CE35E52A6ADFC46087249A8DDFD53947E6FFC7CA5F271BDE6DC00 | |||
2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Follow Bot\follow.txt | text | |
MD5:2C10EDD71749D6AABB64C7CA8A1D1AFE | SHA256:7D24113CC3D4756DDA9FAFEA3A983A2108B3E015924895C1591D43E86C20BB79 | |||
2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Chat Bot\Newtonsoft.Json.xml | xml | |
MD5:2866A8E5449957C9B303AD800E55BF04 | SHA256:42A557F912E050E91F255942C6E6948F6AE3AE5928000AD1DCEF88666BB77A2F | |||
2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Follow Bot\Colorful.Console.dll | executable | |
MD5:5F3D2CFBC21591B8FEEF1EFA3E59A4D0 | SHA256:F31D4FD7E729FC6CF4ECAB972B6B1EE897918A325B1CA572030966F831E768FB | |||
2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Chat Bot\Newtonsoft.Json.dll | executable | |
MD5:F33CBE589B769956284868104686CC2D | SHA256:973FD70CE48E5AC433A101B42871680C51E2FEBA2AEEC3D400DEA4115AF3A278 | |||
2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Follow Bot\Leaf.xNet.dll | executable | |
MD5:B5CB88DE9FE40B6645496F9543CE8E26 | SHA256:A91293829D0A4A0F2F34787FC1BA13B9D3AA4F640D0FCA652B24A88F464BC343 |