URL:

https://pinkiecraft.com

Full analysis: https://app.any.run/tasks/821a068d-bb09-459e-ba40-0ccb1de356d1
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: February 26, 2026, 16:32:37
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
discord
stealer
phishing
filename-lure
payload
electron-js
python
rust
nodejs
Indicators:
MD5:

F7E8AB35B5A789BD7355007BEEFB00B6

SHA1:

DC3DDC00406639771E9A1B3B368DB32327D64B0F

SHA256:

1A1725D8D58D6D36ABA3FF0F2ADF41624037622D16CED5C69F0A3B81C576B932

SSDEEP:

3:N8I6MA+Tn:2IHT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • Discord.exe (PID: 4776)
      • PinkieCraft.exe (PID: 7828)
      • _winhost.exe (PID: 9484)
    • Changes the autorun value in the registry

      • reg.exe (PID: 4552)
    • Executing a file with an untrusted certificate

      • DiscordSystemHelper.exe (PID: 5796)
      • DiscordSystemHelper.exe (PID: 2856)
      • DiscordSystemHelper.exe (PID: 7236)
      • DiscordSystemHelper.exe (PID: 7956)
      • DiscordSystemHelper.exe (PID: 5808)
      • DiscordSystemHelper.exe (PID: 3304)
      • DiscordSystemHelper.exe (PID: 8948)
      • DiscordSystemHelper.exe (PID: 4948)
    • Phishing lure filenames

      • Discord.exe (PID: 6476)
    • Steals credentials from Web Browsers

      • PinkieCraft.exe (PID: 7828)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Update.exe (PID: 1432)
      • DiscordSetup.exe (PID: 5808)
      • Discord.exe (PID: 4256)
      • DiscordSystemHelper.exe (PID: 2856)
      • PinkieCraft.exe (PID: 9492)
      • PinkieCraft.exe (PID: 7828)
      • _winhost.exe (PID: 10128)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 10020)
    • Application launched itself

      • Discord.exe (PID: 4776)
      • Discord.exe (PID: 4256)
      • DiscordSystemHelper.exe (PID: 5796)
      • PinkieCraft.exe (PID: 9820)
      • PinkieCraft.exe (PID: 7828)
      • _winhost.exe (PID: 9484)
    • Possible stealing of messenger data

      • Discord.exe (PID: 4776)
      • PinkieCraft.exe (PID: 7828)
    • Uses REG/REGEDIT.EXE to modify registry

      • Discord.exe (PID: 4776)
      • Discord.exe (PID: 4256)
    • Searches for installed software

      • Update.exe (PID: 1432)
    • Reads the date of Windows installation

      • DiscordSystemHelper.exe (PID: 5796)
    • Executes as Windows Service

      • DiscordSystemHelper.exe (PID: 3304)
      • DiscordSystemHelper.exe (PID: 8948)
    • Starts itself from another location

      • DiscordSystemHelper.exe (PID: 3304)
      • DiscordSystemHelper.exe (PID: 8948)
    • The process creates files with name similar to system file names

      • PinkieCraft.exe (PID: 9492)
      • PinkieCraft.exe (PID: 7828)
    • Discord domain found in command line (probably downloading payload)

      • msedge.exe (PID: 2212)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • PinkieCraft.exe (PID: 9492)
    • Starts CMD.EXE for commands execution

      • PinkieCraft.exe (PID: 9820)
      • PinkieCraft.exe (PID: 7828)
      • _winhost.exe (PID: 10128)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 5220)
      • _winhost.exe (PID: 10020)
      • _winhost.exe (PID: 9484)
    • Starts NET.EXE to display or manage information about active sessions

      • cmd.exe (PID: 9884)
      • net.exe (PID: 9940)
      • cmd.exe (PID: 3152)
      • net.exe (PID: 8720)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 10040)
      • cmd.exe (PID: 8364)
      • cmd.exe (PID: 7208)
      • cmd.exe (PID: 1512)
      • cmd.exe (PID: 4516)
      • cmd.exe (PID: 7980)
      • cmd.exe (PID: 9912)
      • cmd.exe (PID: 9928)
      • cmd.exe (PID: 9704)
      • cmd.exe (PID: 8068)
      • cmd.exe (PID: 4468)
      • cmd.exe (PID: 8668)
      • cmd.exe (PID: 10040)
      • cmd.exe (PID: 1128)
      • cmd.exe (PID: 7648)
      • cmd.exe (PID: 8584)
      • cmd.exe (PID: 1200)
      • cmd.exe (PID: 9344)
      • cmd.exe (PID: 5632)
      • cmd.exe (PID: 7620)
      • cmd.exe (PID: 5592)
      • cmd.exe (PID: 8736)
      • cmd.exe (PID: 2996)
      • cmd.exe (PID: 9400)
      • cmd.exe (PID: 9236)
      • cmd.exe (PID: 6324)
      • cmd.exe (PID: 7740)
      • cmd.exe (PID: 9728)
      • cmd.exe (PID: 9200)
      • cmd.exe (PID: 9944)
      • cmd.exe (PID: 8404)
      • cmd.exe (PID: 7304)
      • cmd.exe (PID: 5216)
      • cmd.exe (PID: 9448)
      • cmd.exe (PID: 8104)
      • cmd.exe (PID: 8888)
      • cmd.exe (PID: 7368)
      • cmd.exe (PID: 10128)
      • cmd.exe (PID: 9476)
      • cmd.exe (PID: 8312)
      • cmd.exe (PID: 8700)
      • cmd.exe (PID: 3212)
      • cmd.exe (PID: 9860)
      • cmd.exe (PID: 4500)
      • cmd.exe (PID: 9856)
      • cmd.exe (PID: 3304)
      • cmd.exe (PID: 10076)
      • cmd.exe (PID: 8176)
      • cmd.exe (PID: 7740)
      • cmd.exe (PID: 9448)
      • cmd.exe (PID: 9456)
      • cmd.exe (PID: 5200)
      • cmd.exe (PID: 1868)
      • cmd.exe (PID: 6296)
      • cmd.exe (PID: 10088)
      • cmd.exe (PID: 8364)
      • cmd.exe (PID: 8984)
      • cmd.exe (PID: 8652)
      • cmd.exe (PID: 2712)
      • cmd.exe (PID: 848)
      • cmd.exe (PID: 9408)
      • cmd.exe (PID: 9056)
      • cmd.exe (PID: 132)
      • cmd.exe (PID: 8088)
      • cmd.exe (PID: 7464)
      • cmd.exe (PID: 9296)
      • cmd.exe (PID: 2760)
      • cmd.exe (PID: 4304)
      • cmd.exe (PID: 6828)
      • cmd.exe (PID: 8436)
      • cmd.exe (PID: 1824)
      • cmd.exe (PID: 3180)
      • cmd.exe (PID: 9972)
      • cmd.exe (PID: 8052)
      • cmd.exe (PID: 9456)
      • cmd.exe (PID: 9980)
      • cmd.exe (PID: 6944)
      • cmd.exe (PID: 2452)
      • cmd.exe (PID: 8568)
      • cmd.exe (PID: 148)
      • cmd.exe (PID: 508)
      • cmd.exe (PID: 8324)
      • cmd.exe (PID: 6200)
      • cmd.exe (PID: 1520)
      • cmd.exe (PID: 7104)
      • cmd.exe (PID: 1868)
      • cmd.exe (PID: 2096)
      • cmd.exe (PID: 7976)
      • cmd.exe (PID: 4636)
      • cmd.exe (PID: 9492)
      • cmd.exe (PID: 1760)
      • cmd.exe (PID: 10188)
      • cmd.exe (PID: 10024)
      • cmd.exe (PID: 1368)
      • cmd.exe (PID: 4776)
      • cmd.exe (PID: 6096)
      • cmd.exe (PID: 9208)
      • cmd.exe (PID: 7748)
      • cmd.exe (PID: 8852)
      • cmd.exe (PID: 1044)
      • cmd.exe (PID: 8632)
      • cmd.exe (PID: 5752)
      • cmd.exe (PID: 6304)
      • cmd.exe (PID: 9368)
      • cmd.exe (PID: 796)
      • cmd.exe (PID: 1324)
      • cmd.exe (PID: 9736)
      • cmd.exe (PID: 2432)
      • cmd.exe (PID: 9988)
      • cmd.exe (PID: 8404)
      • cmd.exe (PID: 9936)
      • cmd.exe (PID: 9940)
      • cmd.exe (PID: 6472)
      • cmd.exe (PID: 10068)
      • cmd.exe (PID: 7988)
      • cmd.exe (PID: 2688)
      • cmd.exe (PID: 5216)
      • cmd.exe (PID: 1856)
      • cmd.exe (PID: 4292)
      • cmd.exe (PID: 7476)
      • cmd.exe (PID: 8608)
      • cmd.exe (PID: 1352)
      • cmd.exe (PID: 1176)
      • cmd.exe (PID: 9868)
      • cmd.exe (PID: 7768)
      • cmd.exe (PID: 4500)
      • cmd.exe (PID: 3276)
      • cmd.exe (PID: 4064)
      • cmd.exe (PID: 3588)
      • cmd.exe (PID: 3096)
      • cmd.exe (PID: 2376)
      • cmd.exe (PID: 1180)
      • cmd.exe (PID: 7772)
      • cmd.exe (PID: 3352)
      • cmd.exe (PID: 8060)
      • cmd.exe (PID: 2564)
      • cmd.exe (PID: 7464)
      • cmd.exe (PID: 9604)
      • cmd.exe (PID: 6504)
      • cmd.exe (PID: 4304)
      • cmd.exe (PID: 6552)
      • cmd.exe (PID: 7540)
      • cmd.exe (PID: 6324)
      • cmd.exe (PID: 9548)
      • cmd.exe (PID: 10196)
      • cmd.exe (PID: 1340)
      • cmd.exe (PID: 2680)
      • cmd.exe (PID: 8668)
      • cmd.exe (PID: 7812)
      • cmd.exe (PID: 5896)
      • cmd.exe (PID: 10148)
      • cmd.exe (PID: 2764)
      • cmd.exe (PID: 10040)
      • cmd.exe (PID: 6296)
      • cmd.exe (PID: 3212)
      • cmd.exe (PID: 4040)
      • cmd.exe (PID: 9312)
      • cmd.exe (PID: 9860)
      • cmd.exe (PID: 3624)
      • cmd.exe (PID: 10120)
      • cmd.exe (PID: 10132)
      • cmd.exe (PID: 8636)
      • cmd.exe (PID: 8308)
      • cmd.exe (PID: 4660)
      • cmd.exe (PID: 9268)
      • cmd.exe (PID: 2864)
      • cmd.exe (PID: 6424)
      • cmd.exe (PID: 7704)
      • cmd.exe (PID: 9600)
      • cmd.exe (PID: 7424)
      • cmd.exe (PID: 5472)
      • cmd.exe (PID: 7240)
      • cmd.exe (PID: 8328)
      • cmd.exe (PID: 2328)
      • cmd.exe (PID: 1768)
      • cmd.exe (PID: 2212)
      • cmd.exe (PID: 9080)
      • cmd.exe (PID: 10020)
      • cmd.exe (PID: 9796)
      • cmd.exe (PID: 9964)
      • cmd.exe (PID: 2688)
      • cmd.exe (PID: 1000)
      • cmd.exe (PID: 2016)
      • cmd.exe (PID: 8020)
      • cmd.exe (PID: 6904)
      • cmd.exe (PID: 9664)
      • cmd.exe (PID: 9292)
      • cmd.exe (PID: 10084)
      • cmd.exe (PID: 6172)
      • cmd.exe (PID: 3212)
      • cmd.exe (PID: 8608)
      • cmd.exe (PID: 4288)
      • cmd.exe (PID: 3624)
      • cmd.exe (PID: 7916)
      • cmd.exe (PID: 8456)
      • cmd.exe (PID: 8616)
      • cmd.exe (PID: 8012)
      • cmd.exe (PID: 9424)
      • cmd.exe (PID: 7424)
      • cmd.exe (PID: 5304)
      • cmd.exe (PID: 4660)
      • cmd.exe (PID: 9268)
      • cmd.exe (PID: 2864)
      • cmd.exe (PID: 404)
      • cmd.exe (PID: 3652)
      • cmd.exe (PID: 1820)
      • cmd.exe (PID: 6936)
      • cmd.exe (PID: 7284)
      • cmd.exe (PID: 5088)
      • cmd.exe (PID: 6240)
      • cmd.exe (PID: 1324)
      • cmd.exe (PID: 8616)
      • cmd.exe (PID: 9476)
      • cmd.exe (PID: 9788)
      • cmd.exe (PID: 1784)
      • cmd.exe (PID: 6880)
      • cmd.exe (PID: 10012)
      • cmd.exe (PID: 9896)
      • cmd.exe (PID: 5216)
      • cmd.exe (PID: 7204)
      • cmd.exe (PID: 9340)
      • cmd.exe (PID: 8100)
      • cmd.exe (PID: 8112)
      • cmd.exe (PID: 1352)
      • cmd.exe (PID: 8756)
      • cmd.exe (PID: 9616)
      • cmd.exe (PID: 4120)
      • cmd.exe (PID: 8348)
      • cmd.exe (PID: 6496)
      • cmd.exe (PID: 10108)
      • cmd.exe (PID: 10224)
      • cmd.exe (PID: 4472)
      • cmd.exe (PID: 3004)
      • cmd.exe (PID: 8308)
      • cmd.exe (PID: 8156)
      • cmd.exe (PID: 8460)
      • cmd.exe (PID: 9276)
      • cmd.exe (PID: 7420)
      • cmd.exe (PID: 6444)
      • cmd.exe (PID: 7832)
      • cmd.exe (PID: 6924)
      • cmd.exe (PID: 7164)
      • cmd.exe (PID: 1600)
      • cmd.exe (PID: 1068)
      • cmd.exe (PID: 9248)
      • cmd.exe (PID: 524)
      • cmd.exe (PID: 6552)
      • cmd.exe (PID: 6240)
      • cmd.exe (PID: 9448)
      • cmd.exe (PID: 9724)
      • cmd.exe (PID: 2232)
      • cmd.exe (PID: 9972)
      • cmd.exe (PID: 1136)
      • cmd.exe (PID: 6200)
      • cmd.exe (PID: 5896)
      • cmd.exe (PID: 9664)
      • cmd.exe (PID: 10084)
      • cmd.exe (PID: 9876)
      • cmd.exe (PID: 1400)
      • cmd.exe (PID: 10160)
      • cmd.exe (PID: 10172)
      • cmd.exe (PID: 7768)
      • cmd.exe (PID: 2788)
      • cmd.exe (PID: 8532)
      • cmd.exe (PID: 5204)
      • cmd.exe (PID: 6056)
      • cmd.exe (PID: 8636)
      • cmd.exe (PID: 2392)
      • cmd.exe (PID: 9296)
      • cmd.exe (PID: 3096)
      • cmd.exe (PID: 5504)
      • cmd.exe (PID: 7392)
      • cmd.exe (PID: 5184)
      • cmd.exe (PID: 6172)
      • cmd.exe (PID: 4040)
      • cmd.exe (PID: 5736)
      • cmd.exe (PID: 8660)
      • cmd.exe (PID: 5996)
      • cmd.exe (PID: 9464)
      • cmd.exe (PID: 8816)
      • cmd.exe (PID: 7448)
      • cmd.exe (PID: 9080)
      • cmd.exe (PID: 9884)
      • cmd.exe (PID: 9756)
      • cmd.exe (PID: 6804)
      • cmd.exe (PID: 4940)
      • cmd.exe (PID: 6788)
      • cmd.exe (PID: 7204)
      • cmd.exe (PID: 8380)
      • cmd.exe (PID: 3120)
      • cmd.exe (PID: 10140)
      • cmd.exe (PID: 8232)
      • cmd.exe (PID: 7104)
      • cmd.exe (PID: 6628)
      • cmd.exe (PID: 5600)
      • cmd.exe (PID: 10048)
      • cmd.exe (PID: 9332)
      • cmd.exe (PID: 7968)
      • cmd.exe (PID: 2140)
      • cmd.exe (PID: 7272)
      • cmd.exe (PID: 7856)
      • cmd.exe (PID: 10228)
      • cmd.exe (PID: 10096)
      • cmd.exe (PID: 2376)
      • cmd.exe (PID: 8012)
      • cmd.exe (PID: 9980)
      • cmd.exe (PID: 552)
      • cmd.exe (PID: 6704)
      • cmd.exe (PID: 9436)
      • cmd.exe (PID: 7660)
      • cmd.exe (PID: 4212)
      • cmd.exe (PID: 8168)
      • cmd.exe (PID: 468)
      • cmd.exe (PID: 1656)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 3588)
      • cmd.exe (PID: 3352)
    • The process executes VB scripts

      • wscript.exe (PID: 10076)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 10076)
    • Drops 7-zip archiver for unpacking

      • PinkieCraft.exe (PID: 9492)
    • Uses TASKKILL.EXE to kill Browsers

      • cmd.exe (PID: 9404)
      • cmd.exe (PID: 3152)
      • cmd.exe (PID: 3088)
    • Possible stealing from browsers

      • PinkieCraft.exe (PID: 7828)
    • Process drops python dynamic module

      • PinkieCraft.exe (PID: 7828)
      • _winhost.exe (PID: 10128)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 10020)
    • The process drops C-runtime libraries

      • PinkieCraft.exe (PID: 7828)
    • Loads Python modules

      • _winhost.exe (PID: 10128)
      • _winhost.exe (PID: 5220)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 9484)
      • _winhost.exe (PID: 10020)
    • Loads DLL from Mozilla Firefox

      • _winhost.exe (PID: 9484)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 8580)
      • msedge.exe (PID: 2212)
    • Attempting to use instant messaging service

      • chrome.exe (PID: 5872)
    • Create files in a temporary directory

      • DiscordSetup.exe (PID: 5808)
      • Update.exe (PID: 1432)
      • Discord.exe (PID: 4256)
      • PinkieCraft.exe (PID: 9492)
      • PinkieCraft.exe (PID: 9820)
      • PinkieCraft.exe (PID: 7828)
      • esentutl.exe (PID: 9788)
      • esentutl.exe (PID: 9900)
      • esentutl.exe (PID: 10016)
      • esentutl.exe (PID: 4472)
      • esentutl.exe (PID: 2688)
      • esentutl.exe (PID: 5524)
      • esentutl.exe (PID: 680)
      • esentutl.exe (PID: 7648)
      • esentutl.exe (PID: 7844)
      • esentutl.exe (PID: 7488)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 5220)
      • _winhost.exe (PID: 10128)
      • _winhost.exe (PID: 10020)
      • esentutl.exe (PID: 3628)
      • esentutl.exe (PID: 7692)
      • esentutl.exe (PID: 6720)
      • esentutl.exe (PID: 7204)
      • esentutl.exe (PID: 3436)
      • esentutl.exe (PID: 8496)
      • esentutl.exe (PID: 3500)
      • esentutl.exe (PID: 664)
      • _winhost.exe (PID: 9484)
    • Creates files or folders in the user directory

      • DiscordSetup.exe (PID: 5808)
      • Update.exe (PID: 1432)
      • Discord.exe (PID: 8028)
      • Update.exe (PID: 2352)
      • Discord.exe (PID: 4776)
      • Discord.exe (PID: 6784)
      • Discord.exe (PID: 272)
      • Discord.exe (PID: 4256)
      • Discord.exe (PID: 3508)
      • Discord.exe (PID: 6476)
      • DiscordSystemHelper.exe (PID: 5796)
      • PinkieCraft.exe (PID: 9492)
      • PinkieCraft.exe (PID: 9820)
      • PinkieCraft.exe (PID: 7828)
      • PinkieCraft.exe (PID: 9320)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 10128)
      • _winhost.exe (PID: 5220)
      • _winhost.exe (PID: 10020)
    • The sample compiled with english language support

      • Update.exe (PID: 1432)
      • PinkieCraft.exe (PID: 9492)
      • PinkieCraft.exe (PID: 7828)
      • _winhost.exe (PID: 1156)
    • Reads the machine GUID from the registry

      • Update.exe (PID: 1432)
      • Update.exe (PID: 2352)
      • Discord.exe (PID: 4776)
      • Discord.exe (PID: 4256)
      • DiscordSystemHelper.exe (PID: 3304)
      • DiscordSystemHelper.exe (PID: 5808)
      • DiscordSystemHelper.exe (PID: 8948)
      • DiscordSystemHelper.exe (PID: 4948)
      • Discord.exe (PID: 6476)
      • _winhost.exe (PID: 10128)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 5220)
      • _winhost.exe (PID: 9484)
      • _winhost.exe (PID: 10020)
    • Checks supported languages

      • Discord.exe (PID: 8028)
      • Discord.exe (PID: 4776)
      • DiscordSetup.exe (PID: 5808)
      • Update.exe (PID: 1432)
      • Discord.exe (PID: 6784)
      • Update.exe (PID: 2352)
      • Discord.exe (PID: 4256)
      • Discord.exe (PID: 272)
      • Discord.exe (PID: 3508)
      • Discord.exe (PID: 8520)
      • Discord.exe (PID: 7868)
      • Discord.exe (PID: 6360)
      • Discord.exe (PID: 6476)
      • Discord.exe (PID: 7696)
      • Discord.exe (PID: 8616)
      • gpu_encoder_helper.exe (PID: 492)
      • gpu_encoder_helper.exe (PID: 7240)
      • gpu_encoder_helper.exe (PID: 7568)
      • gpu_encoder_helper.exe (PID: 2748)
      • DiscordSystemHelper.exe (PID: 5796)
      • DiscordSystemHelper.exe (PID: 2856)
      • Discord.exe (PID: 5612)
      • DiscordSystemHelper.exe (PID: 7956)
      • DiscordSystemHelper.exe (PID: 7236)
      • DiscordSystemHelper.exe (PID: 3304)
      • DiscordSystemHelper.exe (PID: 8948)
      • DiscordSystemHelper.exe (PID: 5808)
      • PinkieCraft.exe (PID: 9492)
      • PinkieCraft.exe (PID: 9820)
      • PinkieCraft.exe (PID: 7768)
      • PinkieCraft.exe (PID: 8276)
      • PinkieCraft.exe (PID: 3208)
      • DiscordSystemHelper.exe (PID: 4948)
      • PinkieCraft.exe (PID: 7828)
      • PinkieCraft.exe (PID: 9320)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 10128)
      • _winhost.exe (PID: 5220)
      • PinkieCraft.exe (PID: 4540)
      • _winhost.exe (PID: 9484)
      • _winhost.exe (PID: 10020)
    • Reads the computer name

      • Discord.exe (PID: 4776)
      • Update.exe (PID: 1432)
      • Update.exe (PID: 2352)
      • Discord.exe (PID: 7868)
      • Discord.exe (PID: 6784)
      • Discord.exe (PID: 3508)
      • Discord.exe (PID: 8520)
      • Discord.exe (PID: 6476)
      • Discord.exe (PID: 8616)
      • Discord.exe (PID: 4256)
      • Discord.exe (PID: 5612)
      • gpu_encoder_helper.exe (PID: 2748)
      • gpu_encoder_helper.exe (PID: 7568)
      • gpu_encoder_helper.exe (PID: 492)
      • DiscordSystemHelper.exe (PID: 5796)
      • DiscordSystemHelper.exe (PID: 2856)
      • gpu_encoder_helper.exe (PID: 7240)
      • DiscordSystemHelper.exe (PID: 7236)
      • DiscordSystemHelper.exe (PID: 7956)
      • DiscordSystemHelper.exe (PID: 5808)
      • DiscordSystemHelper.exe (PID: 3304)
      • DiscordSystemHelper.exe (PID: 8948)
      • DiscordSystemHelper.exe (PID: 4948)
      • PinkieCraft.exe (PID: 9492)
      • PinkieCraft.exe (PID: 9820)
      • PinkieCraft.exe (PID: 7828)
      • PinkieCraft.exe (PID: 3208)
      • PinkieCraft.exe (PID: 9320)
      • _winhost.exe (PID: 5220)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 10128)
      • PinkieCraft.exe (PID: 4540)
      • _winhost.exe (PID: 10020)
      • _winhost.exe (PID: 9484)
    • Process checks computer location settings

      • Discord.exe (PID: 4776)
      • Discord.exe (PID: 4256)
      • Update.exe (PID: 1432)
      • Discord.exe (PID: 6360)
      • Discord.exe (PID: 6476)
      • Discord.exe (PID: 7696)
      • DiscordSystemHelper.exe (PID: 5796)
    • Reads Environment values

      • Discord.exe (PID: 4776)
      • Discord.exe (PID: 4256)
      • Discord.exe (PID: 6476)
      • PinkieCraft.exe (PID: 9820)
      • PinkieCraft.exe (PID: 7828)
    • Reads product name

      • Discord.exe (PID: 4776)
      • Discord.exe (PID: 4256)
      • Discord.exe (PID: 6476)
      • PinkieCraft.exe (PID: 9820)
      • PinkieCraft.exe (PID: 7828)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 8580)
    • Checks proxy server information

      • Discord.exe (PID: 4776)
      • Discord.exe (PID: 4256)
      • slui.exe (PID: 7100)
      • PinkieCraft.exe (PID: 9820)
      • PinkieCraft.exe (PID: 7828)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 10128)
      • _winhost.exe (PID: 5220)
      • _winhost.exe (PID: 10020)
    • Reads security settings of Internet Explorer

      • Update.exe (PID: 1432)
      • DiscordSystemHelper.exe (PID: 5796)
      • DiscordSystemHelper.exe (PID: 5808)
      • DiscordSystemHelper.exe (PID: 4948)
      • Discord.exe (PID: 6476)
      • PinkieCraft.exe (PID: 9492)
    • Creates a software uninstall entry

      • Update.exe (PID: 1432)
      • PinkieCraft.exe (PID: 9492)
    • Drops script file

      • Discord.exe (PID: 4256)
      • Discord.exe (PID: 6476)
      • PinkieCraft.exe (PID: 9492)
      • PinkieCraft.exe (PID: 9820)
      • wscript.exe (PID: 10076)
      • PinkieCraft.exe (PID: 7828)
      • _winhost.exe (PID: 5220)
      • _winhost.exe (PID: 10128)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 9484)
      • _winhost.exe (PID: 10020)
    • Reads CPU info

      • Discord.exe (PID: 6476)
    • Launching a file from a Registry key

      • reg.exe (PID: 4552)
    • Creates files in the program directory

      • DiscordSystemHelper.exe (PID: 2856)
    • Node.js compiler has been detected

      • Discord.exe (PID: 4256)
      • Discord.exe (PID: 272)
    • Manual execution by a user

      • PinkieCraft.exe (PID: 9492)
      • PinkieCraft.exe (PID: 9820)
    • Application based on Rust

      • Discord.exe (PID: 4256)
    • ELECTRON JS mutex has been found

      • PinkieCraft.exe (PID: 9820)
      • PinkieCraft.exe (PID: 7828)
    • Python executable

      • _winhost.exe (PID: 10128)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 5220)
      • _winhost.exe (PID: 9484)
      • _winhost.exe (PID: 10020)
    • Checks operating system version

      • _winhost.exe (PID: 5220)
      • _winhost.exe (PID: 10128)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 10020)
      • _winhost.exe (PID: 9484)
    • Drops encrypted JS script (Microsoft Script Encoder)

      • _winhost.exe (PID: 10128)
      • _winhost.exe (PID: 1156)
      • _winhost.exe (PID: 5220)
      • _winhost.exe (PID: 10020)
      • _winhost.exe (PID: 9484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
1 299
Monitored processes
1 134
Malicious processes
13
Suspicious processes
11

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs winrar.exe no specs chrome.exe no specs chrome.exe no specs slui.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs discordsetup.exe update.exe discord.exe discord.exe no specs update.exe no specs discord.exe no specs discord.exe no specs reg.exe no specs conhost.exe no specs reg.exe conhost.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs discord.exe discord.exe no specs discord.exe no specs discord.exe reg.exe no specs conhost.exe no specs discord.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs reg.exe no specs conhost.exe no specs discord.exe no specs #PHISHING discord.exe discord.exe no specs discord.exe no specs gpu_encoder_helper.exe no specs gpu_encoder_helper.exe no specs gpu_encoder_helper.exe no specs gpu_encoder_helper.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs discordsystemhelper.exe no specs discordsystemhelper.exe discordsystemhelper.exe no specs discordsystemhelper.exe no specs discordsystemhelper.exe no specs discordsystemhelper.exe no specs discordsystemhelper.exe no specs discordsystemhelper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs pinkiecraft.exe chrome.exe no specs pinkiecraft.exe no specs cmd.exe no specs conhost.exe no specs net.exe no specs net1.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wscript.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs pinkiecraft.exe no specs pinkiecraft.exe no specs pinkiecraft.exe cmd.exe no specs conhost.exe no specs net.exe no specs net1.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs pinkiecraft.exe no specs pinkiecraft.exe no specs comppkgsrv.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs chrome.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs esentutl.exe no specs cmd.exe no specs conhost.exe no specs esentutl.exe no specs cmd.exe no specs conhost.exe no specs esentutl.exe no specs cmd.exe no specs conhost.exe no specs esentutl.exe no specs cmd.exe no specs conhost.exe no specs esentutl.exe no specs cmd.exe no specs conhost.exe no specs esentutl.exe no specs cmd.exe no specs conhost.exe no specs esentutl.exe no specs cmd.exe no specs conhost.exe no specs esentutl.exe no specs cmd.exe no specs conhost.exe no specs esentutl.exe no specs cmd.exe no specs conhost.exe no specs esentutl.exe no specs _winhost.exe _winhost.exe conhost.exe no specs _winhost.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs pinkiecraft.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs _winhost.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs _winhost.exe cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs esentutl.exe no specs esentutl.exe no specs cmd.exe no specs esentutl.exe no specs conhost.exe no specs esentutl.exe no specs taskkill.exe no specs esentutl.exe no specs esentutl.exe no specs esentutl.exe no specs esentutl.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
132C:\WINDOWS\system32\cmd.exe /d /s /c "taskkill /F /IM taskmgr.exe"C:\Windows\System32\cmd.exePinkieCraft.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
148C:\WINDOWS\system32\cmd.exe /d /s /c "taskkill /F /IM taskmgr.exe"C:\Windows\System32\cmd.exePinkieCraft.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
148taskkill /F /IM taskmgr.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
224taskkill /F /IM taskmgr.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
224\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
272C:\Users\admin\AppData\Local\Discord\app-1.0.9225\Discord.exe --type=crashpad-handler --user-data-dir=C:\Users\admin\AppData\Roaming\discord /prefetch:4 --no-rate-limit --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Roaming\discord\Crashpad --url=https://f.a.k/e --annotation=_productName=discord --annotation=_version=1.0.9225 --annotation=plat=Win64 --annotation=prod=Electron --annotation=ver=37.6.0 --initial-client-data=0x50c,0x510,0x514,0x500,0x518,0x7ff6e04ab074,0x7ff6e04ab080,0x7ff6e04ab090C:\Users\admin\AppData\Local\Discord\app-1.0.9225\Discord.exeDiscord.exe
User:
admin
Company:
Discord Inc.
Integrity Level:
MEDIUM
Description:
Discord
Exit code:
1
Version:
1.0.9225
Modules
Images
c:\users\admin\appdata\local\discord\app-1.0.9225\discord.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
404C:\WINDOWS\system32\cmd.exe /d /s /c "taskkill /F /IM taskmgr.exe"C:\Windows\System32\cmd.exePinkieCraft.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
412taskkill /F /IM taskmgr.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
412\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
468taskkill /F /IM taskmgr.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
68 577
Read events
68 465
Write events
39
Delete events
73

Modification events

(PID) Process:(9032) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(9032) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(9032) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(9032) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\PinkieCraft.zip
(PID) Process:(9032) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(9032) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(9032) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(9032) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4776) Discord.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Spelling\Dictionaries
Operation:delete valueName:en-US
Value:
(PID) Process:(4776) Discord.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Spelling\Dictionaries
Operation:delete valueName:en
Value:
Executable files
237
Suspicious files
4 833
Text files
3 777
Unknown types
38

Dropped files

PID
Process
Filename
Type
8580chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old~RF1e4f95.TMP
MD5:
SHA256:
8580chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
8580chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF1e4f95.TMP
MD5:
SHA256:
8580chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
8580chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF1e4fb4.TMP
MD5:
SHA256:
8580chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
8580chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\LOG.old~RF1e4fc4.TMP
MD5:
SHA256:
8580chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF1e4fc4.TMP
MD5:
SHA256:
8580chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF1e4fc4.TMP
MD5:
SHA256:
8580chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
445
TCP/UDP connections
156
DNS requests
144
Threats
93

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5872
chrome.exe
GET
200
142.250.186.74:443
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE
US
binary
41 b
whitelisted
5872
chrome.exe
GET
200
104.21.89.19:443
https://pinkiecraft.com/assets/launcher-preview.png
US
binary
516 Kb
unknown
5872
chrome.exe
GET
200
104.21.89.19:443
https://pinkiecraft.com/3.4.17?plugins=forms,typography
US
binary
498 Kb
unknown
5872
chrome.exe
OPTIONS
200
35.190.80.1:443
https://a.nel.cloudflare.com/report/v4?s=oqxZJojAFveteaHdUeGYCrMG0wErV%2BDcgwVeO%2Fisuiltu%2BQsEFPGiTw398GwZ76evu49lNxu0iJY9wE7JbbvZbUZMkjO%2Fa6DAa7FMsDYgA%3D%3D
US
unknown
5872
chrome.exe
GET
200
104.21.89.19:443
https://pinkiecraft.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015
US
text
19.4 Kb
unknown
5872
chrome.exe
GET
206
104.21.89.19:443
https://pinkiecraft.com/assets/hero-smp.mp4
US
unknown
5872
chrome.exe
GET
104.21.89.19:443
https://pinkiecraft.com/assets/hero-smp.mp4
US
unknown
5872
chrome.exe
GET
404
104.21.89.19:443
https://pinkiecraft.com/assets/pixel-clouds.png
US
html
302 b
unknown
5872
chrome.exe
GET
104.21.89.19:443
https://pinkiecraft.com/assets/hero-smp.mp4
US
unknown
5872
chrome.exe
GET
200
142.251.127.113:80
http://clients2.google.com/time/1/current?cup2key=8:d4ppv-zPFiVvB-BOGeQvZeEtDaNWCDbWAXofwyrmBco&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
104 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
6768
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7428
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8756
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5872
chrome.exe
142.251.127.113:80
clients2.google.com
GOOGLE
US
whitelisted
5872
chrome.exe
142.250.186.74:443
safebrowsingohttpgateway.googleapis.com
GOOGLE
US
whitelisted
5872
chrome.exe
172.217.20.131:443
clientservices.googleapis.com
GOOGLE
US
whitelisted
5872
chrome.exe
104.21.89.19:443
pinkiecraft.com
CLOUDFLARENET
US
whitelisted
5872
chrome.exe
142.251.127.84:443
accounts.google.com
GOOGLE
US
whitelisted
5872
chrome.exe
35.190.80.1:443
a.nel.cloudflare.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted

DNS requests

Domain
IP
Reputation
self.events.data.microsoft.com
  • 20.42.65.85
  • 20.189.173.27
whitelisted
google.com
  • 142.251.208.14
whitelisted
clients2.google.com
  • 142.251.127.113
  • 142.251.127.102
  • 142.251.127.101
  • 142.251.127.138
  • 142.251.127.100
  • 142.251.127.139
whitelisted
safebrowsingohttpgateway.googleapis.com
  • 142.250.186.74
  • 142.251.141.138
  • 142.251.140.170
  • 142.250.201.74
  • 216.58.206.74
  • 142.250.201.170
  • 142.251.36.106
  • 142.251.127.95
  • 142.251.143.106
  • 142.251.141.74
  • 142.250.186.42
  • 142.251.208.10
  • 172.217.20.138
  • 172.217.16.170
  • 142.251.37.10
  • 142.251.141.106
whitelisted
clientservices.googleapis.com
  • 172.217.20.131
whitelisted
pinkiecraft.com
  • 104.21.89.19
  • 172.67.155.143
unknown
accounts.google.com
  • 142.251.127.84
whitelisted
a.nel.cloudflare.com
  • 35.190.80.1
whitelisted
update.googleapis.com
  • 142.251.208.163
whitelisted
www.google.com
  • 142.251.127.105
  • 142.251.127.99
  • 142.251.127.103
  • 142.251.127.104
  • 142.251.127.106
  • 142.251.127.147
whitelisted

Threats

PID
Process
Class
Message
5872
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
5872
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
5872
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
5872
chrome.exe
Misc activity
ET INFO Observed Discord Domain in DNS Lookup (discord .com)
5872
chrome.exe
Misc activity
ET INFO Discord Chat Service Domain in DNS Lookup (discord .com)
5872
chrome.exe
Misc activity
ET INFO Observed Discord Domain in DNS Lookup (discord .com)
5872
chrome.exe
Misc activity
ET INFO Observed Discord Domain (discord .com in TLS SNI)
5872
chrome.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
5872
chrome.exe
Misc activity
ET INFO Observed Discord Service Domain (discord .com) in TLS SNI
5872
chrome.exe
Misc activity
ET INFO Observed Discord Domain (discord .com in TLS SNI)
Process
Message
DiscordSetup.exe
Start up installer:
DiscordSetup.exe
Elevated process: ?
DiscordSetup.exe
Want standard install
Discord.exe
Error: 31
Discord.exe
Error: 31
Discord.exe
Error: 31
Discord.exe
Error: 31
Discord.exe
Error: 31
Discord.exe
Error: 31
Discord.exe
Error: 31