File name:

zapret2-youtube-discord-v1.0.8.exe

Full analysis: https://app.any.run/tasks/f2bd797e-dd6f-460d-a85d-4f287e18f389
Verdict: Malicious activity
Analysis date: April 04, 2026, 17:09:18
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
windivert-sys
mal-driver
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

C33EAFD69BFAD041B15DFE30EEC0102A

SHA1:

191ADDB07C7C9991D813F96E8FBBFF08619E54E2

SHA256:

4B050302E719FEB1AD9E368CC4586F65E73DDE5206CDB2F8732E2D74F4C402DC

SSDEEP:

98304:Jxf8GwIpQMTL9J3elCM2X7vLdbws1O2bJQVU5egU7MSFDQ+vGhhA5k05NP0l2xQp:l6K

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Detects Cygwin installation

      • zapret2-youtube-discord-v1.0.8.exe (PID: 6988)
    • Malicious driver has been detected

      • zapret2-youtube-discord-v1.0.8.exe (PID: 6988)
  • SUSPICIOUS

    • Drops 7-zip archiver for unpacking

      • zapret2-youtube-discord-v1.0.8.exe (PID: 6988)
    • Drops a system driver (possible attempt to evade defenses)

      • zapret2-youtube-discord-v1.0.8.exe (PID: 6988)
  • INFO

    • The sample compiled with english language support

      • zapret2-youtube-discord-v1.0.8.exe (PID: 6988)
    • Reads the computer name

      • zapret2-youtube-discord-v1.0.8.exe (PID: 6988)
    • Checks supported languages

      • zapret2-youtube-discord-v1.0.8.exe (PID: 6988)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2026:02:12 10:00:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 175104
InitializedDataSize: 60416
UninitializedDataSize: -
EntryPoint: 0x2864c
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 26.0.0.0
ProductVersionNumber: 26.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Igor Pavlov
FileDescription: 7z SFX
FileVersion: 26
InternalName: 7z.sfx
LegalCopyright: Copyright (c) 1999-2026 Igor Pavlov
OriginalFileName: 7z.sfx.exe
ProductName: 7-Zip
ProductVersion: 26
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT zapret2-youtube-discord-v1.0.8.exe zapret2-youtube-discord-v1.0.8.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4316"C:\Users\admin\Desktop\zapret2-youtube-discord-v1.0.8.exe" C:\Users\admin\Desktop\zapret2-youtube-discord-v1.0.8.exeexplorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7z SFX
Exit code:
3221226540
Version:
26.00
Modules
Images
c:\users\admin\desktop\zapret2-youtube-discord-v1.0.8.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6988"C:\Users\admin\Desktop\zapret2-youtube-discord-v1.0.8.exe" C:\Users\admin\Desktop\zapret2-youtube-discord-v1.0.8.exe
explorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7z SFX
Exit code:
0
Version:
26.00
Modules
Images
c:\users\admin\desktop\zapret2-youtube-discord-v1.0.8.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
Total events
29
Read events
29
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
275

Dropped files

PID
Process
Filename
Type
6988zapret2-youtube-discord-v1.0.8.exeC:\Users\admin\Desktop\bin\dht_get_peers.binbinary
MD5:D755F09EA9D03F842E1AD2693EBC4BBE
SHA256:B57F6584EB58689CCF81702B44103FA53EA31A5DBA00BE9C95B4059BAD602E77
6988zapret2-youtube-discord-v1.0.8.exeC:\Users\admin\Desktop\bin\4.binbinary
MD5:41E47557F16690DF1781F67C8712714E
SHA256:F966351AE376963DFFBCB5B94256872649B9CDAAB8C5175025936FA50E07DC19
6988zapret2-youtube-discord-v1.0.8.exeC:\Users\admin\Desktop\bin\dtls_clienthello_w3_org.binbinary
MD5:E091D8E448CB76D8842CA22643E12B82
SHA256:5BACD8CB6BD451F2374E55BC066B632E3C88FB852E3A44F19E6246C04D127BE5
6988zapret2-youtube-discord-v1.0.8.exeC:\Users\admin\Desktop\bin\3.binbinary
MD5:5299F24CF3EF34818300E204CF40C203
SHA256:D6D63C53BC0E1D97E913A43FC4DB34F6558BB807228BF6100E3B6863F0720404
6988zapret2-youtube-discord-v1.0.8.exeC:\Users\admin\Desktop\bin\fake_http_lichess.binbinary
MD5:C5464018C54821879CCEE0CD6742677C
SHA256:E4D094CF81B67649D0B46BD765EE6075EFD03C46110994AA92816D7A42EBC96E
6988zapret2-youtube-discord-v1.0.8.exeC:\Users\admin\Desktop\bin\fake_tls_4.binbinary
MD5:2BB61118B4B12CD70C846737054558D6
SHA256:A274651C7EE20C696B1454C25355F8C2A6C8116F7746B8686C932FF63893FDF8
6988zapret2-youtube-discord-v1.0.8.exeC:\Users\admin\Desktop\bin\fake_tls_2.binbinary
MD5:49A0F2096C9EC7D6C10865B5FC77EF2D
SHA256:B20530263CF4B4EF7BFD1ECF1D071DA8D74E839328BEA67410DD81696C989E4C
6988zapret2-youtube-discord-v1.0.8.exeC:\Users\admin\Desktop\bin\fake_http_winrar.binbinary
MD5:3C25CBAEF1F7E2808AEAAEF91E29A872
SHA256:019C2134C1698247A522A0F0120716513F24687FE0DD292107E52D77BA92647E
6988zapret2-youtube-discord-v1.0.8.exeC:\Users\admin\Desktop\bin\fake_quic_1.binbinary
MD5:2F31316397D7356CAB92FBD83DEE74F3
SHA256:A7341421E156184678F11B293FD8037FBC0A2DC46EF4168B4C976F754B1F85FB
6988zapret2-youtube-discord-v1.0.8.exeC:\Users\admin\Desktop\bin\fake_quic_3.binbinary
MD5:F85423FE32AC4E25765FCA995234DC5B
SHA256:4A6F8A103646793BAC9CDCFFF9B0ED9F23EF3B43E588AC870C835D3F23FE6E28
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
18
DNS requests
14
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
NL
binary
312 b
whitelisted
5316
svchost.exe
POST
400
20.190.159.129:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
binary
203 b
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
959 b
whitelisted
5316
svchost.exe
POST
400
20.190.159.129:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
binary
203 b
whitelisted
5316
svchost.exe
POST
400
20.190.159.129:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
binary
203 b
whitelisted
8044
svchost.exe
GET
200
23.216.77.38:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
5316
svchost.exe
POST
200
20.190.159.129:443
https://login.live.com/RST2.srf
US
binary
1.24 Kb
whitelisted
5316
svchost.exe
POST
400
20.190.159.129:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
binary
203 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
8044
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
92.123.104.66:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
23.11.41.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3428
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 51.104.136.2
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
www.bing.com
  • 92.123.104.66
  • 92.123.104.65
  • 92.123.104.18
  • 92.123.104.5
  • 92.123.104.61
  • 92.123.104.12
  • 92.123.104.62
  • 92.123.104.9
  • 92.123.104.13
whitelisted
ocsp.digicert.com
  • 23.11.41.157
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
google.com
  • 142.251.110.101
  • 142.251.110.100
  • 142.251.110.102
  • 142.251.110.138
  • 142.251.110.139
  • 142.251.110.113
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.129
  • 40.126.31.0
  • 20.190.159.23
  • 40.126.31.2
  • 20.190.159.68
  • 20.190.159.2
  • 40.126.31.129
  • 20.190.159.128
whitelisted
crl.microsoft.com
  • 23.216.77.38
  • 23.216.77.22
  • 23.216.77.8
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.52.181.212
whitelisted

Threats

PID
Process
Class
Message
8044
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info