URL:

https://cdn.discordapp.com/attachments/718348990806229072/742467597915783231/Discord.Bot.Client.Setup.3.1.0.exe

Full analysis: https://app.any.run/tasks/c3fc3f7c-96a3-42ee-9a57-e4dfde3095e2
Verdict: Malicious activity
Analysis date: January 31, 2022, 08:01:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

35D19C0484C006237796FE9063F42B79

SHA1:

1F35D66F8C62EED5CC33E7AEC31C37F8B1365B4C

SHA256:

7E9484AA5BEDF88812273018E9AA2B930B9CE612396FDC4519279183A2F6C704

SSDEEP:

3:N8cCWdy6//ndXct/YmHUDBoQzAlL7OV0Cn:2cry6XnZ91oHR7FCn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Discord.Bot.Client.Setup.3.1.0.exe (PID: 452)
    • Drops executable file immediately after starts

      • Discord.Bot.Client.Setup.3.1.0.exe (PID: 452)
    • Loads dropped or rewritten executable

      • Discord.Bot.Client.Setup.3.1.0.exe (PID: 452)
      • Discord Bot Client.exe (PID: 2536)
      • Discord Bot Client.exe (PID: 2332)
      • Discord Bot Client.exe (PID: 3480)
      • Discord Bot Client.exe (PID: 2788)
      • Discord Bot Client.exe (PID: 3092)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 3340)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 3340)
      • Discord.Bot.Client.Setup.3.1.0.exe (PID: 452)
    • Checks supported languages

      • Discord.Bot.Client.Setup.3.1.0.exe (PID: 452)
      • Discord Bot Client.exe (PID: 2536)
      • Discord Bot Client.exe (PID: 3480)
      • Discord Bot Client.exe (PID: 2332)
      • Discord Bot Client.exe (PID: 2788)
      • Discord Bot Client.exe (PID: 3092)
    • Reads the computer name

      • Discord.Bot.Client.Setup.3.1.0.exe (PID: 452)
      • Discord Bot Client.exe (PID: 2536)
      • Discord Bot Client.exe (PID: 3480)
      • Discord Bot Client.exe (PID: 2332)
      • Discord Bot Client.exe (PID: 3092)
    • Drops a file with a compile date too recent

      • Discord.Bot.Client.Setup.3.1.0.exe (PID: 452)
    • Drops a file that was compiled in debug mode

      • Discord.Bot.Client.Setup.3.1.0.exe (PID: 452)
    • Creates a software uninstall entry

      • Discord.Bot.Client.Setup.3.1.0.exe (PID: 452)
    • Application launched itself

      • Discord Bot Client.exe (PID: 2536)
    • Creates files in the user directory

      • Discord Bot Client.exe (PID: 2536)
      • Discord.Bot.Client.Setup.3.1.0.exe (PID: 452)
      • Discord Bot Client.exe (PID: 2332)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 3912)
      • iexplore.exe (PID: 3340)
    • Changes internet zones settings

      • iexplore.exe (PID: 3912)
    • Application launched itself

      • iexplore.exe (PID: 3912)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 3912)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 3340)
      • iexplore.exe (PID: 3912)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3340)
      • iexplore.exe (PID: 3912)
      • Discord Bot Client.exe (PID: 2332)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 3912)
    • Creates files in the user directory

      • iexplore.exe (PID: 3912)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3912)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3912)
    • Reads the computer name

      • iexplore.exe (PID: 3912)
      • iexplore.exe (PID: 3340)
    • Manual execution by user

      • Discord Bot Client.exe (PID: 2536)
    • Reads the hosts file

      • Discord Bot Client.exe (PID: 2536)
      • Discord Bot Client.exe (PID: 2332)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
8
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
452"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Discord.Bot.Client.Setup.3.1.0.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Discord.Bot.Client.Setup.3.1.0.exe
iexplore.exe
User:
admin
Company:
Flam3rboy
Integrity Level:
MEDIUM
Description:
Discord Bot Client - login into discord with a bot token
Exit code:
0
Version:
3.1.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\discord.bot.client.setup.3.1.0.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2332"C:\Users\admin\AppData\Local\Programs\discord-bot-client\Discord Bot Client.exe" --type=utility --field-trial-handle=1016,9908960526569949963,6669808927339536197,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --lang=en-US --service-sandbox-type=network --mojo-platform-channel-handle=1668 /prefetch:8C:\Users\admin\AppData\Local\Programs\discord-bot-client\Discord Bot Client.exe
Discord Bot Client.exe
User:
admin
Company:
Flam3rboy
Integrity Level:
MEDIUM
Description:
Discord Bot Client
Exit code:
0
Version:
3.1.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\discord-bot-client\discord bot client.exe
c:\users\admin\appdata\local\programs\discord-bot-client\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2536"C:\Users\admin\AppData\Local\Programs\discord-bot-client\Discord Bot Client.exe" C:\Users\admin\AppData\Local\Programs\discord-bot-client\Discord Bot Client.exe
Explorer.EXE
User:
admin
Company:
Flam3rboy
Integrity Level:
MEDIUM
Description:
Discord Bot Client
Exit code:
0
Version:
3.1.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\discord-bot-client\discord bot client.exe
c:\users\admin\appdata\local\programs\discord-bot-client\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
2788"C:\Users\admin\AppData\Local\Programs\discord-bot-client\Discord Bot Client.exe" --type=renderer --field-trial-handle=1016,9908960526569949963,6669808927339536197,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --lang=en-US --app-path="C:\Users\admin\AppData\Local\Programs\discord-bot-client\resources\app.asar" --no-sandbox --no-zygote --context-isolation --background-color=#fff --enable-spellcheck --enable-websql --disable-electron-site-instance-overrides --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1884 /prefetch:1C:\Users\admin\AppData\Local\Programs\discord-bot-client\Discord Bot Client.exeDiscord Bot Client.exe
User:
admin
Company:
Flam3rboy
Integrity Level:
MEDIUM
Description:
Discord Bot Client
Exit code:
0
Version:
3.1.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\local\programs\discord-bot-client\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
3092"C:\Users\admin\AppData\Local\Programs\discord-bot-client\Discord Bot Client.exe" --type=gpu-process --field-trial-handle=1016,9908960526569949963,6669808927339536197,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --mojo-platform-channel-handle=1024 /prefetch:2C:\Users\admin\AppData\Local\Programs\discord-bot-client\Discord Bot Client.exeDiscord Bot Client.exe
User:
admin
Company:
Flam3rboy
Integrity Level:
LOW
Description:
Discord Bot Client
Exit code:
0
Version:
3.1.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\programs\discord-bot-client\discord bot client.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\discord-bot-client\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3340"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3912 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
3480"C:\Users\admin\AppData\Local\Programs\discord-bot-client\Discord Bot Client.exe" --type=gpu-process --field-trial-handle=1016,9908960526569949963,6669808927339536197,131072 --enable-features=WebComponentsV0Enabled --disable-features=SpareRendererForSitePerProcess --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --mojo-platform-channel-handle=1024 /prefetch:2C:\Users\admin\AppData\Local\Programs\discord-bot-client\Discord Bot Client.exeDiscord Bot Client.exe
User:
admin
Company:
Flam3rboy
Integrity Level:
LOW
Description:
Discord Bot Client
Exit code:
0
Version:
3.1.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\local\programs\discord-bot-client\discord bot client.exe
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\programs\discord-bot-client\ffmpeg.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
3912"C:\Program Files\Internet Explorer\iexplore.exe" "https://cdn.discordapp.com/attachments/718348990806229072/742467597915783231/Discord.Bot.Client.Setup.3.1.0.exe"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
21 096
Read events
20 959
Write events
134
Delete events
3

Modification events

(PID) Process:(3912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30938744
(PID) Process:(3912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30938744
(PID) Process:(3912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
17
Suspicious files
34
Text files
22
Unknown types
76

Dropped files

PID
Process
Filename
Type
3340iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27binary
MD5:2CCABD2A1E16D3D694CB0A85B3FF7BE3
SHA256:61F4618072B0A80A59956D31C294BABE43FA2BFD5E0F3A298A06EB3D55F5A581
3340iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:1CC916FA654E5EA098615341A41CADDB
SHA256:4A728DE79D682C52FCBBCF27FE1BFA90114CD568615FAE0EF3DE5D7673D7E116
3340iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27der
MD5:A70DA7CB267811CC7866259425AD5F4B
SHA256:8188CD5FA8A1CDD5CC38170304C6C9AB737A4881E753C65719733E5101E65043
3912iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63der
MD5:0D9FFFD6A770368EEE9D1A3717849DDE
SHA256:A4A23A379923FDB71FB35CFC3F46B9962CD630B59523DD89B74ACEF2456A7EF6
3912iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776der
MD5:77913080540CC7373C6757EFD172EBA7
SHA256:8BE7E5DD8EE384A264A5813E199EDDB7B8710B082D638294C72C6FB518257D16
3340iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\Discord.Bot.Client.Setup.3.1.0[1].exeexecutable
MD5:1256D85245665D065F478725D91DF99C
SHA256:D542C5C874C68A3206058487F50BF317C8CB7288B8482F438299FBB77016DF13
3912iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\NGN3425E.txttext
MD5:CFC0770DA8C2930C0D585B43375255E2
SHA256:8E808CFBE4E44A49D827110F76467539EBBA735216ACBB2C231716D9EFF60D19
3340iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Discord.Bot.Client.Setup.3.1.0.exe.5ulxiyb.partial
MD5:
SHA256:
3912iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:8D27E7C51C0C8F9BF0A9D146D80CAC3A
SHA256:02F59102EFBB49FAC8878EE8B25874C5EAF8014813F0B9055EA05675F4C2BE40
3912iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\34OUKTME.txttext
MD5:5278FB7085902D16456C38A808602A32
SHA256:AE48CA5CA72707217504668CAA346DC414AA9228E0F4A577A08A305CE12CE546
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
27
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2332
Discord Bot Client.exe
GET
200
178.79.242.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c236054c94f620a6
DE
compressed
59.9 Kb
whitelisted
3912
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
3340
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
3340
iexplore.exe
GET
200
13.107.4.50:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b7a4b1c4b9da941a
US
compressed
4.70 Kb
whitelisted
3912
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
US
der
471 b
whitelisted
3912
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3340
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3340
iexplore.exe
162.159.134.233:443
cdn.discordapp.com
Cloudflare Inc
shared
3912
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3912
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3912
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
3912
iexplore.exe
204.79.197.203:443
www.msn.com
Microsoft Corporation
US
malicious
3340
iexplore.exe
162.159.133.233:443
cdn.discordapp.com
Cloudflare Inc
shared
3912
iexplore.exe
40.83.186.94:443
query.prod.cms.msn.com
Microsoft Corporation
US
whitelisted
2332
Discord Bot Client.exe
142.250.186.174:443
redirector.gvt1.com
Google Inc.
US
whitelisted
2332
Discord Bot Client.exe
18.217.80.105:443
blank.org
Amazon.com, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
cdn.discordapp.com
  • 162.159.133.233
  • 162.159.134.233
  • 162.159.129.233
  • 162.159.130.233
  • 162.159.135.233
shared
ctldl.windowsupdate.com
  • 13.107.4.50
  • 178.79.242.0
  • 178.79.242.128
whitelisted
api.bing.com
  • 13.107.13.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted
go.microsoft.com
  • 104.89.38.104
whitelisted
www.msn.com
  • 204.79.197.203
whitelisted

Threats

No threats detected
No debug info