| URL: | https://anonfiles.com/Z6mbp0X3ne/Discord_Nitro_Sniper_zip |
| Full analysis: | https://app.any.run/tasks/89405d2c-2413-46c0-8905-acf26fb8a7a7 |
| Verdict: | Malicious activity |
| Threats: | AZORult can steal banking information, including passwords and credit card details, as well as cryptocurrency. This constantly updated information stealer malware should not be taken lightly, as it continues to be an active threat. |
| Analysis date: | June 12, 2020, 19:45:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 5C2F6865BDF7A941C1CF7FD360BD7A6E |
| SHA1: | D554F16A0F39D2B1D254CA5A706A109FBEF36616 |
| SHA256: | 34CB49E094B07DBCA1334700CB2349BCD194F447D9FBBDB12367025D7EF2A5B3 |
| SSDEEP: | 3:N8M2b6GDMxKd1:2M2uG1d1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1028 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3116.0.1622076851\1892156332" -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3116 "\\.\pipe\gecko-crash-server-pipe.3116" 1208 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 1244 | "C:\Users\admin\Desktop\Discord Nitro Sniper\NitroSniper by bnja2.exe" | C:\Users\admin\Desktop\Discord Nitro Sniper\NitroSniper by bnja2.exe | NitroSniper by bnja2.exe | ||||||||||||
User: admin Company: Discord Nitro Sniper Integrity Level: MEDIUM Description: Discord Nitro Sniper Exit code: 0 Version: 5.7.10.12 Modules
| |||||||||||||||
| 1364 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Discord Nitro Sniper.zip" | C:\Program Files\WinRAR\WinRAR.exe | firefox.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2136 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3116.20.1633086787\672927356" -childID 3 -isForBrowser -prefsHandle 3628 -prefMapHandle 3640 -prefsLen 6718 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3116 "\\.\pipe\gecko-crash-server-pipe.3116" 3652 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2256 | "C:\Users\admin\Desktop\Discord Nitro Sniper\NitroSniper by bnja2.exe" | C:\Users\admin\Desktop\Discord Nitro Sniper\NitroSniper by bnja2.exe | — | explorer.exe | |||||||||||
User: admin Company: Discord Nitro Sniper Integrity Level: MEDIUM Description: Discord Nitro Sniper Exit code: 0 Version: 5.7.10.12 Modules
| |||||||||||||||
| 2284 | "C:\Program Files\Mozilla Firefox\firefox.exe" "https://anonfiles.com/Z6mbp0X3ne/Discord_Nitro_Sniper_zip" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2780 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3116.27.1820223766\603196881" -childID 4 -isForBrowser -prefsHandle 3464 -prefMapHandle 3460 -prefsLen 7364 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3116 "\\.\pipe\gecko-crash-server-pipe.3116" 4256 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2948 | "C:\Users\admin\Desktop\Discord Nitro Sniper\NitroSniper by bnja2.exe" | C:\Users\admin\Desktop\Discord Nitro Sniper\NitroSniper by bnja2.exe | NitroSniper by bnja2.exe | ||||||||||||
User: admin Company: Discord Nitro Sniper Integrity Level: MEDIUM Description: Discord Nitro Sniper Exit code: 0 Version: 5.7.10.12 Modules
| |||||||||||||||
| 3116 | "C:\Program Files\Mozilla Firefox\firefox.exe" https://anonfiles.com/Z6mbp0X3ne/Discord_Nitro_Sniper_zip | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 3444 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3116) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: F7FC5E0200000000 | |||
| (PID) Process: | (2284) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: F6FC5E0200000000 | |||
| (PID) Process: | (3116) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 1 | |||
| (PID) Process: | (3116) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3116) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3116) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3116) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3116) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids |
| Operation: | write | Name: | WinRAR.ZIP |
Value: | |||
| (PID) Process: | (1364) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1364) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3116 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 3116 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js | — | |
MD5:— | SHA256:— | |||
| 3116 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp | — | |
MD5:— | SHA256:— | |||
| 3116 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm | — | |
MD5:— | SHA256:— | |||
| 3116 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp | — | |
MD5:— | SHA256:— | |||
| 3116 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-current.bin | binary | |
MD5:— | SHA256:— | |||
| 3116 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:— | SHA256:— | |||
| 3116 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.sbstore | binary | |
MD5:— | SHA256:— | |||
| 3116 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:— | SHA256:— | |||
| 3116 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4 | jsonlz4 | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3116 | firefox.exe | POST | 200 | 95.101.72.154:80 | http://ocsp.int-x3.letsencrypt.org/ | unknown | der | 527 b | whitelisted |
3116 | firefox.exe | POST | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3116 | firefox.exe | POST | 200 | 172.217.23.99:80 | http://ocsp.pki.goog/gts1o1 | US | der | 471 b | whitelisted |
1244 | NitroSniper by bnja2.exe | POST | 405 | 77.222.40.139:80 | http://d2575423ur.temp.swtest.ru/index.php | RU | html | 559 b | malicious |
3116 | firefox.exe | POST | 200 | 95.101.72.154:80 | http://ocsp.int-x3.letsencrypt.org/ | unknown | der | 527 b | whitelisted |
3116 | firefox.exe | POST | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3116 | firefox.exe | POST | 200 | 172.217.23.99:80 | http://ocsp.pki.goog/gts1o1core | US | der | 472 b | whitelisted |
3116 | firefox.exe | POST | 200 | 95.101.72.154:80 | http://ocsp.int-x3.letsencrypt.org/ | unknown | der | 527 b | whitelisted |
3116 | firefox.exe | POST | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
3116 | firefox.exe | POST | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/ | US | der | 279 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3116 | firefox.exe | 172.67.219.188:443 | anonfiles.com | — | US | unknown |
3116 | firefox.exe | 2.16.107.40:80 | detectportal.firefox.com | Akamai International B.V. | — | malicious |
3116 | firefox.exe | 52.26.114.88:443 | search.services.mozilla.com | Amazon.com, Inc. | US | unknown |
3116 | firefox.exe | 216.58.207.74:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
3116 | firefox.exe | 72.21.91.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3116 | firefox.exe | 172.217.23.99:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
3116 | firefox.exe | 13.35.253.58:443 | djv99sxoqpv11.cloudfront.net | — | US | malicious |
3116 | firefox.exe | 54.144.3.29:443 | baconaces.pro | Amazon.com, Inc. | US | suspicious |
3116 | firefox.exe | 95.101.72.154:80 | ocsp.int-x3.letsencrypt.org | Akamai International B.V. | — | suspicious |
3116 | firefox.exe | 2.16.107.33:443 | shavar.services.mozilla.com | Akamai International B.V. | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
anonfiles.com |
| shared |
a1089.dscd.akamai.net |
| whitelisted |
search.services.mozilla.com |
| whitelisted |
search.r53-2.services.mozilla.com |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
autopush.prod.mozaws.net |
| whitelisted |
tiles.services.mozilla.com |
| whitelisted |
snippets.cdn.mozilla.net |
| whitelisted |
d228z91au11ukj.cloudfront.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1244 | NitroSniper by bnja2.exe | A Network Trojan was detected | ET TROJAN AZORult Variant.4 Checkin M2 |
1244 | NitroSniper by bnja2.exe | A Network Trojan was detected | ET TROJAN Win32/AZORult V3.2 Client Checkin M3 |
1244 | NitroSniper by bnja2.exe | A Network Trojan was detected | AV TROJAN Azorult CnC Beacon |
1244 | NitroSniper by bnja2.exe | A Network Trojan was detected | AV TROJAN AZORult CnC Beacon |
1244 | NitroSniper by bnja2.exe | A Network Trojan was detected | STEALER [PTsecurity] AZORult |
1244 | NitroSniper by bnja2.exe | A Network Trojan was detected | STEALER [PTsecurity] AZORult v.3 |