File name: | Discord Checker by xPolish.rar |
Full analysis: | https://app.any.run/tasks/62e68883-c5c7-4c78-882f-75e7333a01ce |
Verdict: | Malicious activity |
Analysis date: | January 24, 2022, 17:34:24 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v5 |
MD5: | FF22249350E055478DA436E3EB9E0EDC |
SHA1: | 01AB2281B86B61EA42D5C50B10C3FFAD3893640D |
SHA256: | 1FC79A9CB2DC0FB8E2014C0D89BCAE129FC2B403A32A5604A5FDBDD033C63BA8 |
SSDEEP: | 12288:Cv2XHfRvImhFH2uuJLuYiw2uWL+vXNfgq8M6U8lc:CvCwSH2RLuYiqD9NLH |
.rar | | | RAR compressed archive (v5.0) (61.5) |
---|---|---|
.rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
1044 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Discord Checker by xPolish.rar" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 | ||||
2140 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1044.33086\Discord Checker by xPolish\DiscordChecker.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1044.33086\Discord Checker by xPolish\DiscordChecker.exe | — | WinRAR.exe |
User: admin Integrity Level: MEDIUM Description: Launcher Exit code: 0 Version: 1.0.0.0 | ||||
2940 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1044.33086\Discord Checker by xPolish\system\Launcher.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1044.33086\Discord Checker by xPolish\system\Launcher.exe | DiscordChecker.exe | |
User: admin Integrity Level: HIGH Description: Launcher Exit code: 0 Version: 1.0.0.0 | ||||
1348 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" add-mppreference -exclusionpath C:\Windows\IMF\ | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | Launcher.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) | ||||
1260 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1044.33086\Discord Checker by xPolish\system\bindc.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1044.33086\Discord Checker by xPolish\system\bindc.exe | DiscordChecker.exe | |
User: admin Integrity Level: HIGH Description: DiscordChecker Exit code: 0 Version: 1.0.0.0 | ||||
1144 | "C:\Windows\IMF\Windows Services.exe" {Arguments If Needed} | C:\Windows\IMF\Windows Services.exe | — | Launcher.exe |
User: admin Integrity Level: HIGH Description: Windows Services Version: 1.0.0.0 | ||||
2168 | "C:\Windows\IMF\Secure System Shell.exe" | C:\Windows\IMF\Secure System Shell.exe | — | Windows Services.exe |
User: admin Integrity Level: HIGH Description: Secure System Shell Version: 1.0.0.0 | ||||
3132 | "C:\Windows\IMF\Runtime Explorer.exe" | C:\Windows\IMF\Runtime Explorer.exe | — | Windows Services.exe |
User: admin Company: Microsoft Windows Integrity Level: HIGH Exit code: 0 Version: 1.00 | ||||
3976 | "C:\Windows\IMF\Runtime Explorer.exe" | C:\Windows\IMF\Runtime Explorer.exe | — | Windows Services.exe |
User: admin Company: Microsoft Windows Integrity Level: HIGH Exit code: 0 Version: 1.00 | ||||
3820 | "C:\Windows\IMF\Runtime Explorer.exe" | C:\Windows\IMF\Runtime Explorer.exe | — | Windows Services.exe |
User: admin Company: Microsoft Windows Integrity Level: HIGH Version: 1.00 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1044.33086\Discord Checker by xPolish\xNet.dll | executable | |
MD5:BF1F76644BDDD20339548EBACF7A48EB | SHA256:5D9C2B1822BCAA71DDEAA5426D4312D8E174766AE8864C7ADD29D7F44CEA87F2 | |||
1348 | powershell.exe | C:\Users\admin\AppData\Local\Temp\rcdpu3ei.dsv.ps1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B | |||
2940 | Launcher.exe | C:\Windows\IMF\Windows Services.exe | executable | |
MD5:AD0CE1302147FBDFECAEC58480EB9CF9 | SHA256:2C339B52B82E73B4698A0110CDFE310C00C5C69078E9E1BD6FA1308652BF82A3 | |||
1044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1044.33086\Discord Checker by xPolish\Virus Total\desktop.ini | ini | |
MD5:C279803B27F13369AA54FC9B84B72468 | SHA256:D80758A34364CAB9DE42FF6ED57BCC753A0936DDDDF9952C5B4FB9FF0D7966C9 | |||
2940 | Launcher.exe | C:\Windows\IMF\Runtime Explorer.exe | executable | |
MD5:D42C2456EA9DE66A75A29DEA464A4E4D | SHA256:907E7F7E2EE47C955CF315747AB913B591E9046F51C0F3BA9A6EEF696346198E | |||
1044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1044.33086\Discord Checker by xPolish\DiscordChecker.exe | executable | |
MD5:2636325F4E80BD2E2E841A91AC47B514 | SHA256:2A9987F4B98D1C1E9351124FE5B8ECD2EEA8E42AF0B9E30097AC5BA34C68C2E5 | |||
1044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1044.33086\Discord Checker by xPolish\system\LICENCE.dat | compressed | |
MD5:F3014A18051F4E596AB95DA9138F6F6B | SHA256:1F84A00808D5ECA122FDE7F20708F272C349FAE1EAA1129B5C694750F2E047D6 | |||
1348 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | dbf | |
MD5:446DD1CF97EABA21CF14D03AEBC79F27 | SHA256:A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF | |||
1044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1044.33086\Discord Checker by xPolish\system\xNet.dll | executable | |
MD5:BF1F76644BDDD20339548EBACF7A48EB | SHA256:5D9C2B1822BCAA71DDEAA5426D4312D8E174766AE8864C7ADD29D7F44CEA87F2 | |||
2940 | Launcher.exe | C:\Windows\IMF\Secure System Shell.exe | executable | |
MD5:7D0C7359E5B2DAA5665D01AFDC98CC00 | SHA256:F1ABD5AB03189E82971513E6CA04BD372FCF234D670079888F01CF4ADDD49809 |