| File name: | Discord_Nitro_Generator.rar |
| Full analysis: | https://app.any.run/tasks/500467f5-fbc0-4c0e-84a5-65244c28cc1d |
| Verdict: | Malicious activity |
| Threats: | Orcus is a modular Remote Access Trojan with some unusual functions. This RAT enables attackers to create plugins using a custom development library and offers a robust core feature set that makes it one of the most dangerous malicious programs in its class. |
| Analysis date: | December 05, 2022, 16:51:45 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 03F0492594BF7789309D9195A4CC3226 |
| SHA1: | 267B46D62BD2EEC05AA664DF7BF262198A4F1836 |
| SHA256: | 3E7436D1BD67FD7EE53F9D537CF6C060233B90F5F1E1EF83406F185A0705ED0D |
| SSDEEP: | 12288:+ACcUcPjdAIrl5cjAvsX20UP8BQdkKUwCKiQGlNbFcd34geeFFVjrX:+5cUkRA8PcjW2zw9UPKilNbFo37eOFVP |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 312 | "C:\Users\admin\AppData\Roaming\updater.exe" /launchSelfAndExit "C:\Users\admin\AppData\Local\Discord\app-1.0.9007\resources\bootstrap\Discord.exe" 3460 /protectFile | C:\Users\admin\AppData\Roaming\updater.exe | — | Discord.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 2308 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1464 | "C:\Windows\system32\WindowsInput.exe" --install | C:\Windows\system32\WindowsInput.exe | — | Discord_Nitro_Generator.exe | |||||||||||
User: admin Company: Microsoft Integrity Level: HIGH Description: Windows Input Exit code: 0 Version: 0.1.0 Modules
| |||||||||||||||
| 1592 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Discord_Nitro_Generator.rar" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1756 | "C:\Users\admin\Desktop\Discord_Nitro_Generator.exe" | C:\Users\admin\Desktop\Discord_Nitro_Generator.exe | Explorer.EXE | ||||||||||||
User: admin Company: Discord Inc. Integrity Level: HIGH Description: Discord Exit code: 0 Version: 1.0.9007.0 Modules
| |||||||||||||||
| 2084 | "C:\Users\admin\Desktop\Discord_Nitro_Generator.exe" | C:\Users\admin\Desktop\Discord_Nitro_Generator.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Discord Inc. Integrity Level: MEDIUM Description: Discord Exit code: 3221226540 Version: 1.0.9007.0 Modules
| |||||||||||||||
| 2084 | "C:\Users\admin\AppData\Roaming\updater.exe" /watchProcess "C:\Users\admin\AppData\Local\Discord\app-1.0.9007\resources\bootstrap\Discord.exe" 3460 "/protectFile" | C:\Users\admin\AppData\Roaming\updater.exe | — | updater.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2308 | "C:\Users\admin\AppData\Roaming\updater.exe" /watchProcess "C:\Users\admin\AppData\Local\Discord\app-1.0.9007\resources\bootstrap\Discord.exe" 3460 "/protectFile" | C:\Users\admin\AppData\Roaming\updater.exe | — | updater.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2760 | "C:\Users\admin\Desktop\Discord_Nitro_Generator.exe" | C:\Users\admin\Desktop\Discord_Nitro_Generator.exe | Explorer.EXE | ||||||||||||
User: admin Company: Discord Inc. Integrity Level: HIGH Description: Discord Exit code: 0 Version: 1.0.9007.0 Modules
| |||||||||||||||
| 2796 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\xpvuljjv.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe | — | Discord_Nitro_Generator.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Visual C# Command Line Compiler Exit code: 0 Version: 8.0.50727.5483 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| 2932 | C:\Users\admin\AppData\Local\Discord\app-1.0.9007\resources\bootstrap\Discord.exe | C:\Users\admin\AppData\Local\Discord\app-1.0.9007\resources\bootstrap\Discord.exe | — | taskeng.exe | |||||||||||
User: admin Company: Discord Inc. Integrity Level: HIGH Description: Discord Exit code: 0 Version: 1.0.9007.0 Modules
| |||||||||||||||
| (PID) Process: | (1592) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1592) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1592) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1592) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (1592) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (1592) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Discord_Nitro_Generator.rar | |||
| (PID) Process: | (1592) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1592) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1592) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1592) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1592 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb1592.9886\Discord_Nitro_Generator.exe | executable | |
MD5:— | SHA256:— | |||
| 2760 | Discord_Nitro_Generator.exe | C:\Users\admin\AppData\Local\Temp\xpvuljjv.cmdline | text | |
MD5:— | SHA256:— | |||
| 2796 | csc.exe | C:\Users\admin\AppData\Local\Temp\xpvuljjv.dll | executable | |
MD5:— | SHA256:— | |||
| 2760 | Discord_Nitro_Generator.exe | C:\Users\admin\AppData\Local\Temp\xpvuljjv.0.cs | text | |
MD5:— | SHA256:— | |||
| 2796 | csc.exe | C:\Users\admin\AppData\Local\Temp\CSC5573.tmp | res | |
MD5:— | SHA256:— | |||
| 3132 | cvtres.exe | C:\Users\admin\AppData\Local\Temp\RES5574.tmp | o | |
MD5:— | SHA256:— | |||
| 2796 | csc.exe | C:\Users\admin\AppData\Local\Temp\xpvuljjv.out | text | |
MD5:— | SHA256:— | |||
| 1756 | Discord_Nitro_Generator.exe | C:\Users\admin\AppData\Local\Temp\eig9vgvb.cmdline | text | |
MD5:— | SHA256:— | |||
| 1756 | Discord_Nitro_Generator.exe | C:\Users\admin\AppData\Local\Temp\eig9vgvb.0.cs | text | |
MD5:— | SHA256:— | |||
| 2760 | Discord_Nitro_Generator.exe | C:\Users\admin\AppData\Local\Discord\app-1.0.9007\resources\bootstrap\Discord.exe | executable | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | HEAD | 200 | 23.205.225.13:80 | http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133147328405000000 | NL | — | — | whitelisted |
— | — | GET | 200 | 23.216.77.69:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?4e027e62305cb4c9 | US | compressed | 61.4 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 23.216.77.69:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | suspicious |
— | — | 79.137.202.126:10134 | — | — | RU | malicious |
3460 | Discord.exe | 79.137.202.126:10134 | — | — | RU | malicious |
— | — | 23.205.225.13:80 | query.prod.cms.rt.microsoft.com | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
query.prod.cms.rt.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |