| File name: | Twitch_Bots-1.rar |
| Full analysis: | https://app.any.run/tasks/2c0bb48d-bdaf-4a43-b9f6-82691d186652 |
| Verdict: | Malicious activity |
| Analysis date: | November 29, 2020, 20:40:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | FCE7F6708727C612E65AAFE80D34425A |
| SHA1: | 74CF0FB3C2876A46A9DDC450E7CFF4F53DB3687C |
| SHA256: | C22E594C012DC7BC7E2A6EB6AF328808AA3ECFE0E1760F1CD670E07A2A36117B |
| SSDEEP: | 49152:KpKMdViPqw3TbcEGfyuty2C9sCrWd4O4Z2DiIpGUKgNAMoEA2vxCUXtusZ53aMVU:MQqHE/j2C9RW6dAkUKrM4AxLFRmN |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2416 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Follow Bot\dottwitch.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Follow Bot\dottwitch.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: dotTwitch Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2672 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Twitch_Bots-1.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Twitch_Bots-1.rar | |||
| (PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Chat Bot\ATWITCHBC.pdb | pdb | |
MD5:A2C8093CA7B1D937234A259203D20C78 | SHA256:D8507596F0E02A0817A0F38282DA7487EF0156D25966A38CE8D7D9CE629450DC | |||
| 2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Follow Bot\Colorful.Console.dll | executable | |
MD5:5F3D2CFBC21591B8FEEF1EFA3E59A4D0 | SHA256:F31D4FD7E729FC6CF4ECAB972B6B1EE897918A325B1CA572030966F831E768FB | |||
| 2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\msg.txt | text | |
MD5:BBC7D61E0E526A3A198EFB96F5499713 | SHA256:46179AC2FCFB395845D7103BF76E7744ADBDD515E081EB3550C8C322FD275683 | |||
| 2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Chat Bot\ATWITCHBC.exe.config | xml | |
MD5:EF0181DE18EF3951806C0AD63B897BA4 | SHA256:E8DECC96235B5494880083EB79C22C84C6D9EF312828BAF9490BEE7782C350EC | |||
| 2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Chat Bot\WebSocket4Net.dll | executable | |
MD5:A9347266E1679E90C5DA2B3C1E5A45EE | SHA256:AD2E17F110CDE9BC5609589CD89B4BF3A1D0249E3075597862B8A358D7E15EB2 | |||
| 2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Follow Bot\dottwitch.exe | executable | |
MD5:7E06F89C370AE02A6E88EB5DCAEC7CAB | SHA256:5338757B851CE35E52A6ADFC46087249A8DDFD53947E6FFC7CA5F271BDE6DC00 | |||
| 2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Follow Bot\Figgle.dll | executable | |
MD5:ED1AEDEA86660974B02CB8DFDFB80DCB | SHA256:AC1A8E26E4369D4CCB8BAC78B4F3D69C48EDC7B3761984DDE834C3B4A99C5C95 | |||
| 2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Follow Bot\follow.txt | text | |
MD5:2C10EDD71749D6AABB64C7CA8A1D1AFE | SHA256:7D24113CC3D4756DDA9FAFEA3A983A2108B3E015924895C1591D43E86C20BB79 | |||
| 2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Follow Bot\KoiVM.Runtime.dll | executable | |
MD5:F70CEAAA1AC1509C76C6635C92E6B5C2 | SHA256:EBBF490E21B1E64F5EF63EB777766055D94DB1382D3877ED40EAD8EBDF8CA82E | |||
| 2672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2672.28925\Twitch Bots\Twitch Chat Bot\Newtonsoft.Json.dll | executable | |
MD5:F33CBE589B769956284868104686CC2D | SHA256:973FD70CE48E5AC433A101B42871680C51E2FEBA2AEEC3D400DEA4115AF3A278 | |||