File name:

Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked .zip

Full analysis: https://app.any.run/tasks/b54fe42d-113e-45fb-b1a5-33b9bacf7bab
Verdict: Malicious activity
Analysis date: January 05, 2022, 08:36:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

F1791887ADB542920DC9C8C82E76CAB1

SHA1:

16482A3074028317EFDAC7E3FF13C93364E5F706

SHA256:

D1EA8553C28E247E0587D6ECAB0C6B41D57DC289184440152A456F5C660D6B67

SSDEEP:

12288:HK68xQT9VGhV4ONuER98PuBL7eUlrkD8kr:HK6TRVYXBnFkD8K

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe (PID: 600)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2824)
    • Reads the computer name

      • WinRAR.exe (PID: 2824)
      • Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe (PID: 600)
    • Checks supported languages

      • WinRAR.exe (PID: 2824)
      • Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe (PID: 600)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2824)
    • Reads Environment values

      • Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe (PID: 600)
  • INFO

    • Reads settings of System Certificates

      • Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe (PID: 600)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: [In4.Bz] Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz]/Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
ZipUncompressedSize: 691712
ZipCompressedSize: 241675
ZipCRC: 0x6f97988c
ZipModifyDate: 2021:06:29 10:05:05
ZipCompression: Deflated
ZipBitFlag: 0x0008
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe final twitch god 2021 v1.2 (vip pro edition) cracked [in4.bz].exe

Process information

PID
CMD
Path
Indicators
Parent process
600"C:\Users\admin\AppData\Local\Temp\Rar$EXa2824.45687\[In4.Bz] Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz]\Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2824.45687\[In4.Bz] Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz]\Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
WinRAR.exe
User:
admin
Company:
Pooria Sharaffodin www.BabaTools.com
Integrity Level:
MEDIUM
Description:
Final Twitch God 2021 v1.2 (Vip Pro Edition)
Exit code:
0
Version:
1.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2824.45687\[in4.bz] final twitch god 2021 v1.2 (vip pro edition) cracked [in4.bz]\final twitch god 2021 v1.2 (vip pro edition) cracked [in4.bz].exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2824"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked .zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
5 527
Read events
5 482
Write events
45
Delete events
0

Modification events

(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2824) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked .zip
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2824) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
2
Suspicious files
3
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
2824WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2824.45687\[In4.Bz] Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz]\Newtonsoft.Json.dllexecutable
MD5:CBD6029ABAA8E977D3B7435C6F70DD0E
SHA256:0EDFAC6BE11732DDD99DB66821EE47408C2DC1E9BED68E5EF9A8E130C565B79B
600Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:
SHA256:
2824WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2824.45687\[In4.Bz] Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz]\readme.txttext
MD5:30C23A2F33F1CBD4332658880680576F
SHA256:7C4794996515EE2C8644F9CA6189ED33DA65D0D6A6A948B682016F61736F249E
600Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:ACAEDA60C79C6BCAC925EEB3653F45E0
SHA256:6B0CECCF0103AFD89844761417C1D23ACC41F8AEBF3B7230765209B61EEE5658
600Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exeC:\Users\admin\AppData\Local\Temp\Tar13B6.tmpcat
MD5:D99661D0893A52A0700B8AE68457351A
SHA256:BDD5111162A6FA25682E18FA74E37E676D49CAFCB5B7207E98E5256D1EF0D003
600Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exeC:\Users\admin\AppData\Local\Temp\Cab13B5.tmpcompressed
MD5:ACAEDA60C79C6BCAC925EEB3653F45E0
SHA256:6B0CECCF0103AFD89844761417C1D23ACC41F8AEBF3B7230765209B61EEE5658
2824WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2824.45687\[In4.Bz] Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz]\Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exeexecutable
MD5:C38151E14E72C13054AE16636BEC5E0D
SHA256:F6236859A2510BFECF82DCE6D83D07F5CACEB021D187E4A5418366878002C4F8
2824WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2824.45687\[In4.Bz] Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz]\settings.txttext
MD5:A443A76E6B6604A39BC6BC706E73DD08
SHA256:BC548B362DFAF123863AFCF72D50E66429FE844FD6DF6D62E5BB2570FEA45872
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
444
TCP/UDP connections
841
DNS requests
8
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
CONNECT
200
141.0.11.250:80
http://video-weaver.vie02.hls.ttvnw.netvideo-weaver.vie02.hls.ttvnw.net:443
unknown
suspicious
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
CONNECT
118.136.145.225:8080
http://video-weaver.vie02.hls.ttvnw.net:8080video-weaver.vie02.hls.ttvnw.net:443
ID
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
CONNECT
117.58.241.70:8080
http://video-weaver.vie02.hls.ttvnw.net:8080video-weaver.vie02.hls.ttvnw.net:443
BD
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
CONNECT
110.36.228.168:8080
http://video-weaver.vie02.hls.ttvnw.net:8080video-weaver.vie02.hls.ttvnw.net:443
PK
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
CONNECT
109.200.187.45:8080
http://video-weaver.vie02.hls.ttvnw.net:8080video-weaver.vie02.hls.ttvnw.net:443
YE
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
CONNECT
179.125.31.202:8080
http://video-weaver.vie02.hls.ttvnw.net:8080video-weaver.vie02.hls.ttvnw.net:443
BR
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
CONNECT
117.58.241.70:8080
http://video-weaver.vie02.hls.ttvnw.net:8080video-weaver.vie02.hls.ttvnw.net:443
BD
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
CONNECT
117.58.241.70:8080
http://video-weaver.vie02.hls.ttvnw.net:8080video-weaver.vie02.hls.ttvnw.net:443
BD
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
CONNECT
179.125.31.202:8080
http://video-weaver.vie02.hls.ttvnw.net:8080video-weaver.vie02.hls.ttvnw.net:443
BR
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
CONNECT
200
141.0.11.250:80
http://video-weaver.vie02.hls.ttvnw.netvideo-weaver.vie02.hls.ttvnw.net:443
unknown
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
2.16.186.81:80
ctldl.windowsupdate.com
Akamai International B.V.
whitelisted
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
199.232.138.214:443
api.twitch.tv
US
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
23.160.0.254:443
usher.ttvnw.net
Twitch Interactive Inc.
US
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
141.0.11.250:80
Opera Software AS
suspicious
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
202.147.207.253:38646
PT.Infokom Elektrindo
ID
suspicious
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
143.204.202.229:443
static-cdn.jtvnw.net
US
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
71.138.16.17:30421
AT&T Services, Inc.
US
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
117.58.241.70:8080
AlwaysOn Network Bangladesh Ltd
BD
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
118.136.145.225:8080
Linknet-Fastnet ASN
ID
unknown
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
195.154.55.232:5836
Online S.a.s.
FR
unknown

DNS requests

Domain
IP
Reputation
www.babatools.com
  • 144.217.240.24
unknown
ctldl.windowsupdate.com
  • 2.16.186.81
  • 2.16.186.56
whitelisted
www.babaproxy.com
  • 144.217.240.24
suspicious
api.twitch.tv
  • 199.232.138.214
whitelisted
gql.twitch.tv
  • 151.101.14.167
whitelisted
usher.ttvnw.net
  • 23.160.0.254
  • 192.108.239.254
whitelisted
static-cdn.jtvnw.net
  • 143.204.202.229
whitelisted

Threats

PID
Process
Class
Message
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
Generic Protocol Command Decode
SURICATA Applayer Mismatch protocol both directions
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
Potentially Bad Traffic
ET POLICY HTTP traffic on port 443 (CONNECT)
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
Potentially Bad Traffic
ET POLICY HTTP traffic on port 443 (CONNECT)
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
Generic Protocol Command Decode
SURICATA Applayer Detect protocol only one direction
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
Generic Protocol Command Decode
SURICATA STREAM 3way handshake SYNACK with wrong ack
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
Generic Protocol Command Decode
SURICATA STREAM Packet with invalid ack
600
Final Twitch God 2021 v1.2 (Vip Pro Edition) Cracked [In4.Bz].exe
Generic Protocol Command Decode
SURICATA STREAM SHUTDOWN RST invalid ack
No debug info