File name:

Discord Nitro Gen+Check Pack By PROVADNIKE.zip

Full analysis: https://app.any.run/tasks/a8137ff9-ec7d-4c5d-9442-1c830a73a287
Verdict: Malicious activity
Analysis date: November 12, 2020, 17:48:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

2C97F1EEB2C86C9300A2A0A6C30836E0

SHA1:

14477B24F62E3F67CCFDD1A464858F73A238DC5C

SHA256:

556AEBF7D2CC46DB04F42031BEE6F2ECA89B75D1F633E1682440E761134E1FD7

SSDEEP:

196608:3Ae7R6FZmRna9ZTNHrZf7WuPP5ER3FRm8w8D4eNZbhy6V8MWzziIV1xORTjc:3AekmxanNHlDWcP5ER3Xm8P4OZwfiimQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3184)
      • Discord Hunter Checker By Weeever.exe (PID: 2924)
    • Application was dropped or rewritten from another process

      • Discord Hunter Checker By Weeever.exe (PID: 2924)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2184)
  • INFO

    • Manual execution by user

      • NOTEPAD.EXE (PID: 2912)
      • Discord Hunter Checker By Weeever.exe (PID: 2924)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:09:09 16:51:05
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Discord Nitro Gen+Check Pack By PROVADNIKE/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs notepad.exe no specs discord hunter checker by weeever.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2184"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Discord Nitro Gen+Check Pack By PROVADNIKE.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2912"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroGenByPROVADNIKE\ReadMe.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2924"C:\Users\admin\Desktop\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Discord Hunter Checker By Weeever.exe" C:\Users\admin\Desktop\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Discord Hunter Checker By Weeever.exeexplorer.exe
User:
admin
Company:
Breakstore
Integrity Level:
MEDIUM
Description:
NitroHunter Checker By Weeever
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\discord nitro gen+check pack by provadnike\nitrochecker\discord hunter checker by weeever.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3184"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
809
Read events
788
Write events
21
Delete events
0

Modification events

(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2184) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Discord Nitro Gen+Check Pack By PROVADNIKE.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3184) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3184) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
4
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.19434\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\xNet.dll
MD5:
SHA256:
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.19434\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroGenByPROVADNIKE\Nitro Generator.exe
MD5:
SHA256:
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.19434\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroGenByPROVADNIKE\ReadMe.txt
MD5:
SHA256:
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.19434\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Discord Hunter Checker By Weeever.exeexecutable
MD5:5B4FF415E917A4BD650DFA998741F31B
SHA256:7AD280D630CD23D8E1BF071323AC5CD35BC389F1FC3F7C5AAE147A3E5983D635
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.19434\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Leaf.xNet.dllexecutable
MD5:6A4FB68D5541898C2EC86D709C26FF86
SHA256:5C099E6C5985E413CDF8D81C84BF61977B80E1E6221E332C94490F6A72373A4A
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.19434\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Newtonsoft.Json.dllexecutable
MD5:6815034209687816D8CF401877EC8133
SHA256:7F912B28A07C226E0BE3ACFB2F57F050538ABA0100FA1F0BF2C39F1A1F1DA814
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.19434\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Colorful.Console.dllexecutable
MD5:AC4267B870699A799E05B2BE2D2956DA
SHA256:309C616209120EE751DF11612A8EADD06E8C86E68510D0B31BA21290782516FC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info