File name:

Discord_Nitro_Checker_Final.rar

Full analysis: https://app.any.run/tasks/81200a02-e5ab-4558-aa16-a379d9febe66
Verdict: Malicious activity
Threats:

Orcus is a modular Remote Access Trojan with some unusual functions. This RAT enables attackers to create plugins using a custom development library and offers a robust core feature set that makes it one of the most dangerous malicious programs in its class.

Analysis date: March 01, 2020, 21:24:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
orcus
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

163400CCD763FC83F2D753E582C8FA50

SHA1:

0F66A5C69AF8615A5C849B1E37FE4C3AC9CCBE43

SHA256:

25672D3A92DE5B75A5B2533401C4D5C542D20DD027BB1542ECEF15E42DCA1EF0

SSDEEP:

12288:khTgKmEC33x9Z8chGujb5aeRNGis+v4VawhhHkixfW1kTC6Olb141O5vMOyO4TGv:CTgKmN6cEuRaeRNGPvDfH+L141O503LU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts Visual C# compiler

      • DISCORD NITRO CHEKER.EXE (PID: 2084)
      • DISCORD NITRO CHEKER.EXE (PID: 780)
    • Application was dropped or rewritten from another process

      • DISCORD NITRO CHEKER.EXE (PID: 780)
      • Discord nitro checker.exe (PID: 1760)
      • WindowsInput.exe (PID: 820)
      • DISCORD NITRO CHECKER.EXE (PID: 3508)
      • DISCORD NITRO CHEKER.EXE (PID: 2084)
      • WindowsInput.exe (PID: 340)
      • minecraft.exe (PID: 2800)
      • minecraft.exe (PID: 4064)
      • svchost.exe (PID: 3012)
      • svchost.exe (PID: 3852)
    • ORCUS was detected

      • DISCORD NITRO CHEKER.EXE (PID: 2084)
      • DISCORD NITRO CHEKER.EXE (PID: 780)
      • minecraft.exe (PID: 2800)
      • minecraft.exe (PID: 4064)
      • svchost.exe (PID: 3852)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3548)
      • DISCORD NITRO CHECKER.EXE (PID: 3508)
    • Changes the autorun value in the registry

      • minecraft.exe (PID: 2800)
    • Loads the Task Scheduler COM API

      • minecraft.exe (PID: 2800)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Discord nitro checker.exe (PID: 1760)
      • WinRAR.exe (PID: 3052)
      • DISCORD NITRO CHEKER.EXE (PID: 780)
      • minecraft.exe (PID: 2800)
    • Creates files in the Windows directory

      • DISCORD NITRO CHEKER.EXE (PID: 780)
      • WindowsInput.exe (PID: 340)
    • Application launched itself

      • DISCORD NITRO CHEKER.EXE (PID: 2084)
    • Executed as Windows Service

      • WindowsInput.exe (PID: 820)
    • Creates files in the user directory

      • DISCORD NITRO CHEKER.EXE (PID: 780)
      • minecraft.exe (PID: 2800)
    • Executed via Task Scheduler

      • minecraft.exe (PID: 4064)
    • Connects to unusual port

      • minecraft.exe (PID: 2800)
      • DISCORD NITRO CHECKER.EXE (PID: 3508)
    • Starts itself from another location

      • DISCORD NITRO CHEKER.EXE (PID: 780)
    • Creates executable files which already exist in Windows

      • minecraft.exe (PID: 2800)
  • INFO

    • Manual execution by user

      • Discord nitro checker.exe (PID: 1760)
      • NOTEPAD.EXE (PID: 2312)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
17
Malicious processes
8
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start winrar.exe searchprotocolhost.exe no specs discord nitro checker.exe discord nitro checker.exe #ORCUS discord nitro cheker.exe no specs csc.exe no specs cvtres.exe no specs #ORCUS discord nitro cheker.exe csc.exe no specs cvtres.exe no specs windowsinput.exe no specs windowsinput.exe no specs #ORCUS minecraft.exe #ORCUS minecraft.exe no specs #ORCUS svchost.exe no specs svchost.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
340"C:\Windows\system32\WindowsInput.exe" --installC:\Windows\system32\WindowsInput.exeDISCORD NITRO CHEKER.EXE
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Windows Input
Exit code:
0
Version:
0.1.0
Modules
Images
c:\windows\system32\windowsinput.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
564C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESA590.tmp" "c:\Users\admin\AppData\Local\Temp\CSCA58F.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.4940 (Win7SP1.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
780"C:\Users\admin\AppData\Local\Temp\DISCORD NITRO CHEKER.EXE" /waitC:\Users\admin\AppData\Local\Temp\DISCORD NITRO CHEKER.EXE
DISCORD NITRO CHEKER.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.2.14393.0
Modules
Images
c:\users\admin\appdata\local\temp\discord nitro cheker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
820"C:\Windows\system32\WindowsInput.exe"C:\Windows\system32\WindowsInput.exeservices.exe
User:
SYSTEM
Company:
Microsoft
Integrity Level:
SYSTEM
Description:
Windows Input
Exit code:
0
Version:
0.1.0
Modules
Images
c:\windows\system32\windowsinput.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1760"C:\Users\admin\Desktop\Discord nitro checker.exe" C:\Users\admin\Desktop\Discord nitro checker.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\discord nitro checker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2084"C:\Users\admin\AppData\Local\Temp\DISCORD NITRO CHEKER.EXE" C:\Users\admin\AppData\Local\Temp\DISCORD NITRO CHEKER.EXE
Discord nitro checker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.2.14393.0
Modules
Images
c:\users\admin\appdata\local\temp\discord nitro cheker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2312"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\proxies.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2640C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESAD8F.tmp" "c:\Users\admin\AppData\Local\Temp\CSCAD8E.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.4940 (Win7SP1.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
2800"C:\Users\admin\AppData\Roaming\svchost\minecraft.exe" C:\Users\admin\AppData\Roaming\svchost\minecraft.exe
DISCORD NITRO CHEKER.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.2.14393.0
Modules
Images
c:\users\admin\appdata\roaming\svchost\minecraft.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2836"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\jhkkmi9s.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exeDISCORD NITRO CHEKER.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.4927 (NetFXspW7.050727-4900)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
2 289
Read events
2 246
Write events
43
Delete events
0

Modification events

(PID) Process:(3052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3052) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Discord_Nitro_Checker_Final.rar
(PID) Process:(3052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3548) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
10
Suspicious files
0
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
4020csc.exeC:\Users\admin\AppData\Local\Temp\CSCA58F.tmp
MD5:
SHA256:
564cvtres.exeC:\Users\admin\AppData\Local\Temp\RESA590.tmp
MD5:
SHA256:
4020csc.exeC:\Users\admin\AppData\Local\Temp\hsvhrnug.dll
MD5:
SHA256:
4020csc.exeC:\Users\admin\AppData\Local\Temp\hsvhrnug.out
MD5:
SHA256:
780DISCORD NITRO CHEKER.EXEC:\Users\admin\AppData\Local\Temp\jhkkmi9s.0.cs
MD5:
SHA256:
780DISCORD NITRO CHEKER.EXEC:\Users\admin\AppData\Local\Temp\jhkkmi9s.cmdline
MD5:
SHA256:
2836csc.exeC:\Users\admin\AppData\Local\Temp\CSCAD8E.tmp
MD5:
SHA256:
2640cvtres.exeC:\Users\admin\AppData\Local\Temp\RESAD8F.tmp
MD5:
SHA256:
2836csc.exeC:\Users\admin\AppData\Local\Temp\jhkkmi9s.dll
MD5:
SHA256:
2836csc.exeC:\Users\admin\AppData\Local\Temp\jhkkmi9s.out
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
43
DNS requests
7
Threats
41

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3508
DISCORD NITRO CHECKER.EXE
176.9.117.112:3128
Hetzner Online GmbH
DE
suspicious
2800
minecraft.exe
188.40.15.52:28165
Hetzner Online GmbH
DE
unknown
3508
DISCORD NITRO CHECKER.EXE
178.128.99.120:44321
Forthnet
GR
suspicious
3508
DISCORD NITRO CHECKER.EXE
159.89.170.118:3128
US
unknown
3508
DISCORD NITRO CHECKER.EXE
159.203.91.6:8080
Digital Ocean, Inc.
US
suspicious
3508
DISCORD NITRO CHECKER.EXE
24.197.108.55:3128
Charter Communications
US
suspicious
3508
DISCORD NITRO CHECKER.EXE
91.126.239.175:8080
Adamo Telecom Iberia S.A.
ES
suspicious
3508
DISCORD NITRO CHECKER.EXE
110.78.136.237:8080
CAT TELECOM Public Company Ltd,CAT
TH
suspicious
3508
DISCORD NITRO CHECKER.EXE
200.24.17.54:8080
Level 3 Communications, Inc.
CO
suspicious
3508
DISCORD NITRO CHECKER.EXE
162.243.107.120:8080
Digital Ocean, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
discordapp.com
  • 162.159.134.233
  • 162.159.129.233
  • 162.159.130.233
  • 162.159.135.233
  • 162.159.133.233
whitelisted

Threats

PID
Process
Class
Message
3508
DISCORD NITRO CHECKER.EXE
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3508
DISCORD NITRO CHECKER.EXE
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3508
DISCORD NITRO CHECKER.EXE
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3508
DISCORD NITRO CHECKER.EXE
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3508
DISCORD NITRO CHECKER.EXE
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3508
DISCORD NITRO CHECKER.EXE
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3508
DISCORD NITRO CHECKER.EXE
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3508
DISCORD NITRO CHECKER.EXE
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3508
DISCORD NITRO CHECKER.EXE
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3508
DISCORD NITRO CHECKER.EXE
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
Process
Message
Discord nitro checker.exe
C:\Users\admin\AppData\Local\Temp\COLORFUL.CONSOLE.DLL
Discord nitro checker.exe
C:\Users\admin\AppData\Local\Temp\DISCORD NITRO CHECKER.EXE
Discord nitro checker.exe
C:\Users\admin\AppData\Local\Temp\DISCORD NITRO CHEKER.EXE
Discord nitro checker.exe
C:\Users\admin\AppData\Local\Temp\XNET-AMELIORATED.DLL