URL:

https://anonfiles.com/Z6mbp0X3ne/Discord_Nitro_Sniper_zip

Full analysis: https://app.any.run/tasks/89405d2c-2413-46c0-8905-acf26fb8a7a7
Verdict: Malicious activity
Threats:

AZORult can steal banking information, including passwords and credit card details, as well as cryptocurrency. This constantly updated information stealer malware should not be taken lightly, as it continues to be an active threat.

Analysis date: June 12, 2020, 19:45:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
rat
azorult
Indicators:
MD5:

5C2F6865BDF7A941C1CF7FD360BD7A6E

SHA1:

D554F16A0F39D2B1D254CA5A706A109FBEF36616

SHA256:

34CB49E094B07DBCA1334700CB2349BCD194F447D9FBBDB12367025D7EF2A5B3

SSDEEP:

3:N8M2b6GDMxKd1:2M2uG1d1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3444)
      • NitroSniper by bnja2.exe (PID: 2948)
    • Application was dropped or rewritten from another process

      • NitroSniper by bnja2.exe (PID: 2256)
      • NitroSniper by bnja2.exe (PID: 2948)
      • NitroSniper by bnja2.exe (PID: 1244)
    • Connects to CnC server

      • NitroSniper by bnja2.exe (PID: 1244)
    • AZORULT was detected

      • NitroSniper by bnja2.exe (PID: 1244)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1364)
    • Creates files in the program directory

      • firefox.exe (PID: 3116)
    • Reads Internet Cache Settings

      • NitroSniper by bnja2.exe (PID: 1244)
    • Application launched itself

      • NitroSniper by bnja2.exe (PID: 2256)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 3116)
      • firefox.exe (PID: 2284)
    • Reads CPU info

      • firefox.exe (PID: 3116)
    • Reads Internet Cache Settings

      • firefox.exe (PID: 3116)
    • Manual execution by user

      • NitroSniper by bnja2.exe (PID: 2256)
    • Reads settings of System Certificates

      • NitroSniper by bnja2.exe (PID: 2948)
    • Creates files in the user directory

      • firefox.exe (PID: 3116)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
12
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe firefox.exe winrar.exe searchprotocolhost.exe no specs nitrosniper by bnja2.exe no specs nitrosniper by bnja2.exe #AZORULT nitrosniper by bnja2.exe

Process information

PID
CMD
Path
Indicators
Parent process
1028"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3116.0.1622076851\1892156332" -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3116 "\\.\pipe\gecko-crash-server-pipe.3116" 1208 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
1244"C:\Users\admin\Desktop\Discord Nitro Sniper\NitroSniper by bnja2.exe"C:\Users\admin\Desktop\Discord Nitro Sniper\NitroSniper by bnja2.exe
NitroSniper by bnja2.exe
User:
admin
Company:
Discord Nitro Sniper
Integrity Level:
MEDIUM
Description:
Discord Nitro Sniper
Exit code:
0
Version:
5.7.10.12
Modules
Images
c:\users\admin\desktop\discord nitro sniper\nitrosniper by bnja2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1364"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Discord Nitro Sniper.zip"C:\Program Files\WinRAR\WinRAR.exe
firefox.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2136"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3116.20.1633086787\672927356" -childID 3 -isForBrowser -prefsHandle 3628 -prefMapHandle 3640 -prefsLen 6718 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3116 "\\.\pipe\gecko-crash-server-pipe.3116" 3652 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
2256"C:\Users\admin\Desktop\Discord Nitro Sniper\NitroSniper by bnja2.exe" C:\Users\admin\Desktop\Discord Nitro Sniper\NitroSniper by bnja2.exeexplorer.exe
User:
admin
Company:
Discord Nitro Sniper
Integrity Level:
MEDIUM
Description:
Discord Nitro Sniper
Exit code:
0
Version:
5.7.10.12
Modules
Images
c:\users\admin\desktop\discord nitro sniper\nitrosniper by bnja2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2284"C:\Program Files\Mozilla Firefox\firefox.exe" "https://anonfiles.com/Z6mbp0X3ne/Discord_Nitro_Sniper_zip"C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
2780"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3116.27.1820223766\603196881" -childID 4 -isForBrowser -prefsHandle 3464 -prefMapHandle 3460 -prefsLen 7364 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3116 "\\.\pipe\gecko-crash-server-pipe.3116" 4256 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
2948"C:\Users\admin\Desktop\Discord Nitro Sniper\NitroSniper by bnja2.exe"C:\Users\admin\Desktop\Discord Nitro Sniper\NitroSniper by bnja2.exe
NitroSniper by bnja2.exe
User:
admin
Company:
Discord Nitro Sniper
Integrity Level:
MEDIUM
Description:
Discord Nitro Sniper
Exit code:
0
Version:
5.7.10.12
Modules
Images
c:\users\admin\desktop\discord nitro sniper\nitrosniper by bnja2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3116"C:\Program Files\Mozilla Firefox\firefox.exe" https://anonfiles.com/Z6mbp0X3ne/Discord_Nitro_Sniper_zipC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
68.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
3444"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 844
Read events
1 800
Write events
44
Delete events
0

Modification events

(PID) Process:(3116) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
F7FC5E0200000000
(PID) Process:(2284) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
F6FC5E0200000000
(PID) Process:(3116) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
1
(PID) Process:(3116) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3116) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(3116) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3116) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3116) firefox.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids
Operation:writeName:WinRAR.ZIP
Value:
(PID) Process:(1364) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1364) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
Executable files
7
Suspicious files
104
Text files
56
Unknown types
68

Dropped files

PID
Process
Filename
Type
3116firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
3116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js
MD5:
SHA256:
3116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp
MD5:
SHA256:
3116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
MD5:
SHA256:
3116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.tmp
MD5:
SHA256:
3116firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-child-current.binbinary
MD5:
SHA256:
3116firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.binbinary
MD5:
SHA256:
3116firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\base-track-digest256.sbstorebinary
MD5:
SHA256:
3116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:
SHA256:
3116firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4jsonlz4
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
47
DNS requests
108
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3116
firefox.exe
POST
200
95.101.72.154:80
http://ocsp.int-x3.letsencrypt.org/
unknown
der
527 b
whitelisted
3116
firefox.exe
POST
200
72.21.91.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3116
firefox.exe
POST
200
172.217.23.99:80
http://ocsp.pki.goog/gts1o1
US
der
471 b
whitelisted
1244
NitroSniper by bnja2.exe
POST
405
77.222.40.139:80
http://d2575423ur.temp.swtest.ru/index.php
RU
html
559 b
malicious
3116
firefox.exe
POST
200
95.101.72.154:80
http://ocsp.int-x3.letsencrypt.org/
unknown
der
527 b
whitelisted
3116
firefox.exe
POST
200
72.21.91.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3116
firefox.exe
POST
200
172.217.23.99:80
http://ocsp.pki.goog/gts1o1core
US
der
472 b
whitelisted
3116
firefox.exe
POST
200
95.101.72.154:80
http://ocsp.int-x3.letsencrypt.org/
unknown
der
527 b
whitelisted
3116
firefox.exe
POST
200
72.21.91.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3116
firefox.exe
POST
200
72.21.91.29:80
http://ocsp.digicert.com/
US
der
279 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3116
firefox.exe
172.67.219.188:443
anonfiles.com
US
unknown
3116
firefox.exe
2.16.107.40:80
detectportal.firefox.com
Akamai International B.V.
malicious
3116
firefox.exe
52.26.114.88:443
search.services.mozilla.com
Amazon.com, Inc.
US
unknown
3116
firefox.exe
216.58.207.74:443
safebrowsing.googleapis.com
Google Inc.
US
whitelisted
3116
firefox.exe
72.21.91.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3116
firefox.exe
172.217.23.99:80
ocsp.pki.goog
Google Inc.
US
whitelisted
3116
firefox.exe
13.35.253.58:443
djv99sxoqpv11.cloudfront.net
US
malicious
3116
firefox.exe
54.144.3.29:443
baconaces.pro
Amazon.com, Inc.
US
suspicious
3116
firefox.exe
95.101.72.154:80
ocsp.int-x3.letsencrypt.org
Akamai International B.V.
suspicious
3116
firefox.exe
2.16.107.33:443
shavar.services.mozilla.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 2.16.107.40
  • 2.16.107.58
whitelisted
anonfiles.com
  • 172.67.219.188
  • 104.31.92.18
  • 104.31.93.18
shared
a1089.dscd.akamai.net
  • 2.16.107.58
  • 2.16.107.40
whitelisted
search.services.mozilla.com
  • 52.26.114.88
  • 52.41.191.52
  • 34.211.106.52
whitelisted
search.r53-2.services.mozilla.com
  • 34.211.106.52
  • 52.41.191.52
  • 52.26.114.88
whitelisted
push.services.mozilla.com
  • 52.35.220.92
whitelisted
autopush.prod.mozaws.net
  • 52.35.220.92
whitelisted
tiles.services.mozilla.com
whitelisted
snippets.cdn.mozilla.net
  • 143.204.202.50
  • 143.204.202.128
  • 143.204.202.20
  • 143.204.202.48
whitelisted
d228z91au11ukj.cloudfront.net
  • 143.204.202.48
  • 143.204.202.20
  • 143.204.202.128
  • 143.204.202.50
whitelisted

Threats

PID
Process
Class
Message
1244
NitroSniper by bnja2.exe
A Network Trojan was detected
ET TROJAN AZORult Variant.4 Checkin M2
1244
NitroSniper by bnja2.exe
A Network Trojan was detected
ET TROJAN Win32/AZORult V3.2 Client Checkin M3
1244
NitroSniper by bnja2.exe
A Network Trojan was detected
AV TROJAN Azorult CnC Beacon
1244
NitroSniper by bnja2.exe
A Network Trojan was detected
AV TROJAN AZORult CnC Beacon
1244
NitroSniper by bnja2.exe
A Network Trojan was detected
STEALER [PTsecurity] AZORult
1244
NitroSniper by bnja2.exe
A Network Trojan was detected
STEALER [PTsecurity] AZORult v.3
1 ETPRO signatures available at the full report
No debug info