File name: | Twitch_Bots-1.rar |
Full analysis: | https://app.any.run/tasks/a361cdba-2dcd-4f6b-b06f-49f0cf173dc7 |
Verdict: | Malicious activity |
Analysis date: | November 29, 2020, 20:38:10 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v5 |
MD5: | FCE7F6708727C612E65AAFE80D34425A |
SHA1: | 74CF0FB3C2876A46A9DDC450E7CFF4F53DB3687C |
SHA256: | C22E594C012DC7BC7E2A6EB6AF328808AA3ECFE0E1760F1CD670E07A2A36117B |
SSDEEP: | 49152:KpKMdViPqw3TbcEGfyuty2C9sCrWd4O4Z2DiIpGUKgNAMoEA2vxCUXtusZ53aMVU:MQqHE/j2C9RW6dAkUKrM4AxLFRmN |
.rar | | | RAR compressed archive (v5.0) (61.5) |
---|---|---|
.rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2744 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Twitch_Bots-1.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
1492 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2744.15492\Twitch Bots\Twitch Follow Bot\dottwitch.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2744.15492\Twitch Bots\Twitch Follow Bot\dottwitch.exe | WinRAR.exe | |
User: admin Integrity Level: MEDIUM Description: dotTwitch Version: 1.0.0.0 |
(PID) Process: | (2744) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (2744) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (2744) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2744) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Twitch_Bots-1.rar | |||
(PID) Process: | (2744) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2744) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2744) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2744) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2744) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (2744) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2744 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2744.15492\Twitch Bots\Twitch Chat Bot\ATWITCHBC.exe | executable | |
MD5:E723EE7C3A84C44FA4646111A3B2FB82 | SHA256:9962E85530591CE5AF72F705F810F5C8F4D825F908056AC060BF812E662610B9 | |||
2744 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2744.15492\Twitch Bots\Twitch Chat Bot\TwitchLib.dll | executable | |
MD5:A405D3838F5228964514C4F30471CAAC | SHA256:8BDED35BC773E693898F4B13664CB81A4DB799F25ACD73B4DF13019B31EB1FCE | |||
2744 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2744.15492\Twitch Bots\Twitch Chat Bot\Newtonsoft.Json.xml | xml | |
MD5:2866A8E5449957C9B303AD800E55BF04 | SHA256:42A557F912E050E91F255942C6E6948F6AE3AE5928000AD1DCEF88666BB77A2F | |||
2744 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2744.15492\Twitch Bots\Twitch Follow Bot\Newtonsoft.Json.dll | executable | |
MD5:D827DD8A8C4B2A2CFA23C7F90F3CCE95 | SHA256:B66749B81E1489FCD8D754B2AD39EBE0DB681344E392A3F49DC9235643BDBD06 | |||
2744 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2744.15492\Twitch Bots\Twitch Follow Bot\dottwitch.exe | executable | |
MD5:7E06F89C370AE02A6E88EB5DCAEC7CAB | SHA256:5338757B851CE35E52A6ADFC46087249A8DDFD53947E6FFC7CA5F271BDE6DC00 | |||
2744 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2744.15492\Twitch Bots\Twitch Chat Bot\WebSocket4Net.dll | executable | |
MD5:A9347266E1679E90C5DA2B3C1E5A45EE | SHA256:AD2E17F110CDE9BC5609589CD89B4BF3A1D0249E3075597862B8A358D7E15EB2 | |||
2744 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2744.15492\Twitch Bots\Twitch Follow Bot\Leaf.xNet.dll | executable | |
MD5:B5CB88DE9FE40B6645496F9543CE8E26 | SHA256:A91293829D0A4A0F2F34787FC1BA13B9D3AA4F640D0FCA652B24A88F464BC343 | |||
2744 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2744.15492\Twitch Bots\Twitch Chat Bot\ATWITCHBC.exe.config | xml | |
MD5:EF0181DE18EF3951806C0AD63B897BA4 | SHA256:E8DECC96235B5494880083EB79C22C84C6D9EF312828BAF9490BEE7782C350EC | |||
2744 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2744.15492\Twitch Bots\Twitch Chat Bot\Newtonsoft.Json.dll | executable | |
MD5:F33CBE589B769956284868104686CC2D | SHA256:973FD70CE48E5AC433A101B42871680C51E2FEBA2AEEC3D400DEA4115AF3A278 | |||
2744 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2744.15492\Twitch Bots\Twitch Follow Bot\Figgle.dll | executable | |
MD5:ED1AEDEA86660974B02CB8DFDFB80DCB | SHA256:AC1A8E26E4369D4CCB8BAC78B4F3D69C48EDC7B3761984DDE834C3B4A99C5C95 |