| File name: | (infected) discord nitro generator and checker.rar |
| Full analysis: | https://app.any.run/tasks/d852378f-a5ec-4a06-86a8-2fd5b90c3bcb |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | June 29, 2019, 12:35:15 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 23E54288F7A76D448B503BE31A4CF78E |
| SHA1: | 59DB06404A49FBFDB6F19CABEEB5197BDF54EC24 |
| SHA256: | 4DFCE7F7BAEE2A75BA7FEA5DA440C1436E2782B3EB57FC865174F2B8A08A1F7B |
| SSDEEP: | 49152:K+pIspS4gG6gIreqcbMLO40+Se1Qrq2B6/6g:K+LDBI7safhoVg |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1212 | "C:\Users\admin\Desktop\(infected) discord nitro generator and checker\DISCORD DESTROYER.exe" | C:\Users\admin\Desktop\(infected) discord nitro generator and checker\DISCORD DESTROYER.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: DISCORD DESTROYER Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2480 | "C:\Users\admin\AppData\Local\Temp\DiscordDestroyer Reworked.exe" | C:\Users\admin\AppData\Local\Temp\DiscordDestroyer Reworked.exe | DISCORD DESTROYER.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: DiscordDestroyer Reworked Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2508 | "C:\Users\admin\AppData\Local\Temp\DLLSupport.exe" | C:\Users\admin\AppData\Local\Temp\DLLSupport.exe | DISCORD DESTROYER.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: DebuggerStepThroughAttribute Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3612 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\(infected) discord nitro generator and checker.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (3612) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3612) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3612) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3612) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\(infected) discord nitro generator and checker.rar | |||
| (PID) Process: | (3612) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3612) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3612) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3612) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1212) DISCORD DESTROYER.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1212) DISCORD DESTROYER.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2480 | DiscordDestroyer Reworked.exe | C:\Users\admin\AppData\Local\Temp\tmp8A9F.tmp | — | |
MD5:— | SHA256:— | |||
| 2480 | DiscordDestroyer Reworked.exe | C:\Users\admin\AppData\Local\Temp\CabE37E.tmp | — | |
MD5:— | SHA256:— | |||
| 2480 | DiscordDestroyer Reworked.exe | C:\Users\admin\AppData\Local\Temp\TarE37F.tmp | — | |
MD5:— | SHA256:— | |||
| 2480 | DiscordDestroyer Reworked.exe | C:\Users\admin\AppData\Local\Temp\CabE3AF.tmp | — | |
MD5:— | SHA256:— | |||
| 2480 | DiscordDestroyer Reworked.exe | C:\Users\admin\AppData\Local\Temp\TarE3B0.tmp | — | |
MD5:— | SHA256:— | |||
| 2480 | DiscordDestroyer Reworked.exe | C:\Users\admin\AppData\Local\Temp\Cab1E59.tmp | — | |
MD5:— | SHA256:— | |||
| 2480 | DiscordDestroyer Reworked.exe | C:\Users\admin\AppData\Local\Temp\Tar1E5A.tmp | — | |
MD5:— | SHA256:— | |||
| 2480 | DiscordDestroyer Reworked.exe | C:\Users\admin\AppData\Local\Temp\CabCD0A.tmp | — | |
MD5:— | SHA256:— | |||
| 2480 | DiscordDestroyer Reworked.exe | C:\Users\admin\AppData\Local\Temp\TarCD0B.tmp | — | |
MD5:— | SHA256:— | |||
| 2480 | DiscordDestroyer Reworked.exe | C:\Users\admin\AppData\Local\Temp\CabCD1B.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2508 | DLLSupport.exe | GET | 200 | 54.38.92.92:80 | http://ip-api.com/json/ | FR | text | 272 b | malicious |
2480 | DiscordDestroyer Reworked.exe | GET | 200 | 95.101.0.105:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | unknown | compressed | 56.2 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2508 | DLLSupport.exe | 162.159.129.233:443 | discordapp.com | Cloudflare Inc | — | shared |
2508 | DLLSupport.exe | 54.38.92.92:80 | ip-api.com | OVH SAS | FR | malicious |
2480 | DiscordDestroyer Reworked.exe | 46.175.128.21:32686 | — | LTD Objedinennaja Setevaja Kompanija | RU | suspicious |
2480 | DiscordDestroyer Reworked.exe | 185.47.184.253:45463 | — | MVM NET Zrt. | HU | suspicious |
2480 | DiscordDestroyer Reworked.exe | 202.164.211.116:64312 | — | MetroNet Bangladesh Limited, Fiber Optic Based Metropolitan Data | BD | suspicious |
2480 | DiscordDestroyer Reworked.exe | 103.240.161.108:6667 | — | Gujarat Telelink Pvt Ltd | IN | suspicious |
2480 | DiscordDestroyer Reworked.exe | 85.172.98.94:4145 | — | PJSC Rostelecom | RU | suspicious |
2480 | DiscordDestroyer Reworked.exe | 144.172.216.109:38752 | — | Videotron Telecom Ltee | CA | suspicious |
2480 | DiscordDestroyer Reworked.exe | 119.42.118.214:4145 | — | CAT TELECOM Public Company Ltd,CAT | TH | suspicious |
2480 | DiscordDestroyer Reworked.exe | 195.117.193.1:4145 | — | Orange Polska Spolka Akcyjna | PL | suspicious |
Domain | IP | Reputation |
|---|---|---|
ip-api.com |
| malicious |
discordapp.com |
| whitelisted |
www.download.windowsupdate.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2508 | DLLSupport.exe | Potential Corporate Privacy Violation | ET POLICY External IP Lookup ip-api.com |
2508 | DLLSupport.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
2480 | DiscordDestroyer Reworked.exe | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
2480 | DiscordDestroyer Reworked.exe | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
2480 | DiscordDestroyer Reworked.exe | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
2480 | DiscordDestroyer Reworked.exe | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
2480 | DiscordDestroyer Reworked.exe | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
2480 | DiscordDestroyer Reworked.exe | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
2480 | DiscordDestroyer Reworked.exe | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
2480 | DiscordDestroyer Reworked.exe | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |