File name: | Discord Tokens Generator.zip |
Full analysis: | https://app.any.run/tasks/eac30e21-4d38-4798-bb9b-608c1e419cb3 |
Verdict: | Malicious activity |
Analysis date: | October 20, 2020, 03:05:40 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | B1B310BB23492228FEC2352927E3B6EE |
SHA1: | 14E28A28A5D67562B145EB34012A98769D69F654 |
SHA256: | 95E4FF61B8BD20F5FB6B4A445F59503447926B30BB886C6335FE3339002AE1A1 |
SSDEEP: | 393216:Xz6wDVoaHjC9xH2/qX3e4dt4BQDP6Ew/1p21vys:Xz6wDnHm9xWUpHAkU/1p+ |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 20 |
---|---|
ZipBitFlag: | - |
ZipCompression: | Deflated |
ZipModifyDate: | 2020:10:05 10:29:01 |
ZipCRC: | 0xfe490d13 |
ZipCompressedSize: | 15573797 |
ZipUncompressedSize: | 15862039 |
ZipFileName: | Discord Tokens Generator.exe |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2432 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Discord Tokens Generator.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 | ||||
576 | "C:\Users\admin\Desktop\Discord Tokens Generator.exe" | C:\Users\admin\Desktop\Discord Tokens Generator.exe | explorer.exe | |
User: admin Integrity Level: MEDIUM Exit code: 4294967295 | ||||
1908 | "C:\Users\admin\Desktop\Discord Tokens Generator.exe" | C:\Users\admin\Desktop\Discord Tokens Generator.exe | Discord Tokens Generator.exe | |
User: admin Integrity Level: MEDIUM Exit code: 4294967295 | ||||
2684 | C:\Windows\system32\cmd.exe /c title ThisEsteb - Discord Tokens Generator - 0 Tokens | C:\Windows\system32\cmd.exe | — | Discord Tokens Generator.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2772 | "C:\Users\admin\Desktop\Discord Tokens Generator.exe" | C:\Users\admin\Desktop\Discord Tokens Generator.exe | explorer.exe | |
User: admin Integrity Level: MEDIUM Exit code: 4294967295 | ||||
2268 | "C:\Users\admin\Desktop\Discord Tokens Generator.exe" | C:\Users\admin\Desktop\Discord Tokens Generator.exe | Discord Tokens Generator.exe | |
User: admin Integrity Level: MEDIUM Exit code: 4294967295 | ||||
3340 | C:\Windows\system32\cmd.exe /c title ThisEsteb - Discord Tokens Generator - 0 Tokens | C:\Windows\system32\cmd.exe | — | Discord Tokens Generator.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2328 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\system32\taskmgr.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3192 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Windows\System32\ieapfltr.dat | C:\Windows\system32\rundll32.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2596 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Windows\System32\dxtrans.dll | C:\Windows\system32\rundll32.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2432.215\Discord Tokens Generator.exe | — | |
MD5:— | SHA256:— | |||
576 | Discord Tokens Generator.exe | C:\Users\admin\AppData\Local\Temp\_MEI5762\Crypto\Cipher\_ARC4.cp38-win32.pyd | executable | |
MD5:FC1EF85BCF1D44DB6D32192EDAF931F4 | SHA256:DB4284303E94A682101C2C5FB73DD35405EB04AA7392E34429263547CF5B83B2 | |||
576 | Discord Tokens Generator.exe | C:\Users\admin\AppData\Local\Temp\_MEI5762\Crypto\Cipher\_raw_ctr.cp38-win32.pyd | executable | |
MD5:37424FF388C6236FEE06022A44FD3BF9 | SHA256:FCE59443A5468B292100E19C30D093DB33F1DB5C032A265AF0944DF388DC62AD | |||
576 | Discord Tokens Generator.exe | C:\Users\admin\AppData\Local\Temp\_MEI5762\Crypto\Cipher\_raw_des3.cp38-win32.pyd | executable | |
MD5:9E782D4950C2BB6D3C187EC17C3B9E4C | SHA256:58085B581F2BE8761ABF22163B0F06C06AD285F6F8C383C1BB980F61C13DD37B | |||
576 | Discord Tokens Generator.exe | C:\Users\admin\AppData\Local\Temp\_MEI5762\Crypto\Cipher\_raw_aesni.cp38-win32.pyd | executable | |
MD5:5D5C1BC6C74C7C83F27BA9C8C6638863 | SHA256:53D8A935D07BC307692EB1AF1369C62E7AA051224178344270C6A2003394B67B | |||
576 | Discord Tokens Generator.exe | C:\Users\admin\AppData\Local\Temp\_MEI5762\Crypto\Cipher\_raw_blowfish.cp38-win32.pyd | executable | |
MD5:9B219BBC67D899C608718FB267B9E786 | SHA256:90E8448B0BAD3AC2AF599488D9BA4E43C93FF83193B3E8F37D43C8F2D13A63EE | |||
576 | Discord Tokens Generator.exe | C:\Users\admin\AppData\Local\Temp\_MEI5762\Crypto\Cipher\_raw_eksblowfish.cp38-win32.pyd | executable | |
MD5:7229F3B936ED26D2FB36F5E748109CA2 | SHA256:FF6081A2735B603CC9F984CC67E0A0A02EF5F9F8BE9F5CB3550557619230818D | |||
576 | Discord Tokens Generator.exe | C:\Users\admin\AppData\Local\Temp\_MEI5762\Crypto\Cipher\_chacha20.cp38-win32.pyd | executable | |
MD5:100BE873039DF2C8A2DA4F9554BAEEA3 | SHA256:4861F5CA729112D56C4CD6B3301AACB2803DAF6371BD3992D4339E4BAE968AF5 | |||
576 | Discord Tokens Generator.exe | C:\Users\admin\AppData\Local\Temp\_MEI5762\Crypto\Cipher\_raw_aes.cp38-win32.pyd | executable | |
MD5:662BF265439BB6C3A009EE41DBC4F6E4 | SHA256:E73E54B991A1D5BDDD2E8497AEA1598D2A14602D3A12108F84FB685C34EFC239 | |||
576 | Discord Tokens Generator.exe | C:\Users\admin\AppData\Local\Temp\_MEI5762\Crypto\Cipher\_raw_ofb.cp38-win32.pyd | executable | |
MD5:2716F30AAE6E61C5728335E761B03E15 | SHA256:7CFEF91BC4AAE67AD950F47A1A8D1A8115F847CC46DC0EA56C10474D1D0DA526 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
1908 | Discord Tokens Generator.exe | 162.159.136.232:443 | discord.com | Cloudflare Inc | — | shared |
2268 | Discord Tokens Generator.exe | 162.159.136.232:443 | discord.com | Cloudflare Inc | — | shared |
Domain | IP | Reputation |
---|---|---|
discord.com |
| whitelisted |