File name: | Twitch_Bots-1.rar |
Full analysis: | https://app.any.run/tasks/6360366d-a71e-47ee-a29f-91796884a82f |
Verdict: | Malicious activity |
Analysis date: | November 29, 2020, 20:41:53 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v5 |
MD5: | FCE7F6708727C612E65AAFE80D34425A |
SHA1: | 74CF0FB3C2876A46A9DDC450E7CFF4F53DB3687C |
SHA256: | C22E594C012DC7BC7E2A6EB6AF328808AA3ECFE0E1760F1CD670E07A2A36117B |
SSDEEP: | 49152:KpKMdViPqw3TbcEGfyuty2C9sCrWd4O4Z2DiIpGUKgNAMoEA2vxCUXtusZ53aMVU:MQqHE/j2C9RW6dAkUKrM4AxLFRmN |
.rar | | | RAR compressed archive (v5.0) (61.5) |
---|---|---|
.rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2936 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Twitch_Bots-1.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
2108 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.39265\Twitch Bots\Twitch Follow Bot\dottwitch.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.39265\Twitch Bots\Twitch Follow Bot\dottwitch.exe | — | WinRAR.exe |
User: admin Integrity Level: MEDIUM Description: dotTwitch Version: 1.0.0.0 |
(PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Twitch_Bots-1.rar | |||
(PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.39265\Twitch Bots\msg.txt | text | |
MD5:BBC7D61E0E526A3A198EFB96F5499713 | SHA256:46179AC2FCFB395845D7103BF76E7744ADBDD515E081EB3550C8C322FD275683 | |||
2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.39265\Twitch Bots\Twitch Chat Bot\Newtonsoft.Json.xml | xml | |
MD5:2866A8E5449957C9B303AD800E55BF04 | SHA256:42A557F912E050E91F255942C6E6948F6AE3AE5928000AD1DCEF88666BB77A2F | |||
2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.39265\Twitch Bots\Twitch Chat Bot\ATWITCHBC.exe | executable | |
MD5:E723EE7C3A84C44FA4646111A3B2FB82 | SHA256:9962E85530591CE5AF72F705F810F5C8F4D825F908056AC060BF812E662610B9 | |||
2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.39265\Twitch Bots\Twitch Chat Bot\TwitchLib.dll | executable | |
MD5:A405D3838F5228964514C4F30471CAAC | SHA256:8BDED35BC773E693898F4B13664CB81A4DB799F25ACD73B4DF13019B31EB1FCE | |||
2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.39265\Twitch Bots\Twitch Follow Bot\Figgle.dll | executable | |
MD5:ED1AEDEA86660974B02CB8DFDFB80DCB | SHA256:AC1A8E26E4369D4CCB8BAC78B4F3D69C48EDC7B3761984DDE834C3B4A99C5C95 | |||
2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.39265\Twitch Bots\Twitch Follow Bot\follow.txt | text | |
MD5:2C10EDD71749D6AABB64C7CA8A1D1AFE | SHA256:7D24113CC3D4756DDA9FAFEA3A983A2108B3E015924895C1591D43E86C20BB79 | |||
2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.39265\Twitch Bots\Twitch Chat Bot\WebSocket4Net.dll | executable | |
MD5:A9347266E1679E90C5DA2B3C1E5A45EE | SHA256:AD2E17F110CDE9BC5609589CD89B4BF3A1D0249E3075597862B8A358D7E15EB2 | |||
2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.39265\Twitch Bots\Twitch Follow Bot\Colorful.Console.dll | executable | |
MD5:5F3D2CFBC21591B8FEEF1EFA3E59A4D0 | SHA256:F31D4FD7E729FC6CF4ECAB972B6B1EE897918A325B1CA572030966F831E768FB | |||
2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.39265\Twitch Bots\Twitch Chat Bot\ATWITCHBC.exe.config | xml | |
MD5:EF0181DE18EF3951806C0AD63B897BA4 | SHA256:E8DECC96235B5494880083EB79C22C84C6D9EF312828BAF9490BEE7782C350EC | |||
2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.39265\Twitch Bots\Twitch Follow Bot\Newtonsoft.Json.dll | executable | |
MD5:D827DD8A8C4B2A2CFA23C7F90F3CCE95 | SHA256:B66749B81E1489FCD8D754B2AD39EBE0DB681344E392A3F49DC9235643BDBD06 |