File name:

Discord Nitro Gen+Check Pack By PROVADNIKE.zip

Full analysis: https://app.any.run/tasks/49b6682e-4ced-421a-919e-3b21d857f960
Verdict: Malicious activity
Analysis date: October 23, 2024, 10:52:27
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
pyinstaller
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

2E56D907169980BC490AC1998B9C1630

SHA1:

F556E2033F01AC23D5A259B53BD2CA58AD578BCC

SHA256:

C150E6A45BCEF8224033D55A785C8F9A80D30AEE938126B6F317DFF77F3A3875

SSDEEP:

196608:6Zvk0voOOUnQ3HUq5fAQ7R6FZmRna9ZTNHrZf7WuPP5ER3FRm8w8D4eNZbhy6V8n:6FbxnQlAQkmxanNHlDWcP5ER3Xm8P4Os

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 5952)
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • Nitro Generator.exe (PID: 2376)
      • Nitro Generator.exe (PID: 2784)
      • Nitro Generator.exe (PID: 4340)
    • Connects to unusual port

      • Discord Hunter Checker By Weeever.exe (PID: 6680)
    • Executable content was dropped or overwritten

      • Nitro Generator.exe (PID: 2376)
      • Nitro Generator.exe (PID: 2784)
      • Nitro Generator.exe (PID: 4340)
    • Process drops legitimate windows executable

      • Nitro Generator.exe (PID: 2376)
      • Nitro Generator.exe (PID: 2784)
      • Nitro Generator.exe (PID: 4340)
    • Process drops python dynamic module

      • Nitro Generator.exe (PID: 2376)
      • Nitro Generator.exe (PID: 2784)
      • Nitro Generator.exe (PID: 4340)
    • Application launched itself

      • Nitro Generator.exe (PID: 4340)
  • INFO

    • Manual execution by a user

      • Nitro Generator.exe (PID: 2376)
      • Discord Hunter Checker By Weeever.exe (PID: 6680)
      • notepad++.exe (PID: 5784)
      • Nitro Generator.exe (PID: 2784)
      • cmd.exe (PID: 4408)
      • notepad.exe (PID: 3104)
      • notepad.exe (PID: 5700)
      • Discord Hunter Checker By Weeever.exe (PID: 884)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5952)
    • PyInstaller has been detected (YARA)

      • Nitro Generator.exe (PID: 6272)
      • Nitro Generator.exe (PID: 4340)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:09:09 16:51:10
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Discord Nitro Gen+Check Pack By PROVADNIKE/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
17
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs nitro generator.exe conhost.exe no specs discord hunter checker by weeever.exe conhost.exe no specs notepad++.exe nitro generator.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs THREAT nitro generator.exe THREAT nitro generator.exe no specs notepad.exe no specs notepad.exe no specs discord hunter checker by weeever.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
884"C:\Users\admin\Desktop\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Discord Hunter Checker By Weeever.exe" C:\Users\admin\Desktop\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Discord Hunter Checker By Weeever.exeexplorer.exe
User:
admin
Company:
Breakstore
Integrity Level:
MEDIUM
Description:
NitroHunter Checker By Weeever
Version:
1.0.0.0
1568C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
1576\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeDiscord Hunter Checker By Weeever.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
2376"C:\Users\admin\Desktop\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroGenByPROVADNIKE\Nitro Generator.exe" C:\Users\admin\Desktop\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroGenByPROVADNIKE\Nitro Generator.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\desktop\discord nitro gen+check pack by provadnike\nitrogenbyprovadnike\nitro generator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2780\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeNitro Generator.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2784"C:\Users\admin\Desktop\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroGenByPROVADNIKE\Nitro Generator.exe" C:\Users\admin\Desktop\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroGenByPROVADNIKE\Nitro Generator.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\desktop\discord nitro gen+check pack by provadnike\nitrogenbyprovadnike\nitro generator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
3104\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeNitro Generator.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3104"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroGenByPROVADNIKE\Nitro Codes.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
4340"Nitro Generator.exe"C:\Users\admin\Desktop\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroGenByPROVADNIKE\Nitro Generator.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\desktop\discord nitro gen+check pack by provadnike\nitrogenbyprovadnike\nitro generator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
4408"C:\Windows\System32\cmd.exe" C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3221225786
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\wldp.dll
Total events
2 318
Read events
2 302
Write events
16
Delete events
0

Modification events

(PID) Process:(5952) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(5952) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Discord Nitro Gen+Check Pack By PROVADNIKE.zip
(PID) Process:(5952) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5952) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5952) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5952) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(5952) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C00000000000000010000000083FFFF0083FFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(5952) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(5952) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5952) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
Executable files
78
Suspicious files
11
Text files
2 110
Unknown types
0

Dropped files

PID
Process
Filename
Type
5952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5952.7562\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\combo.txt
MD5:
SHA256:
5952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5952.7562\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\xNet.dllexecutable
MD5:3DF8D87A482EFAD957D83819ADB3020F
SHA256:2AC175B4D44245EE8E7AEE9CC36DF86925EF903D8516F20A2C51D84E35F23DA4
5952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5952.7562\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\proxies.txttext
MD5:3A5A055CC1E507C0B7723ECE697E89DA
SHA256:59B46D9591B7AE27B8389C4C8E08FD3C2FD43A30B221BCC153EBD33554D47BE3
5952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5952.7562\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroGenByPROVADNIKE\ReadMe.txttext
MD5:E3894E57F5B0351D1C233D43F16C71C1
SHA256:02897A6B80113B601636CEDBA382F08F53377A709BB2D612F48A0DFD48EC45C7
5952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5952.7562\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroGenByPROVADNIKE\Nitro Generator.exeexecutable
MD5:1F9C211139F2C434FD94BDC490FCE46B
SHA256:BFA2A93A619EDEB81C57453670EE4772C08DA5101888FC27ACCA74DBEDEECEBD
5952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5952.7562\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Newtonsoft.Json.dllexecutable
MD5:6815034209687816D8CF401877EC8133
SHA256:7F912B28A07C226E0BE3ACFB2F57F050538ABA0100FA1F0BF2C39F1A1F1DA814
5952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5952.7562\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Colorful.Console.dllexecutable
MD5:AC4267B870699A799E05B2BE2D2956DA
SHA256:309C616209120EE751DF11612A8EADD06E8C86E68510D0B31BA21290782516FC
5952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5952.7562\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Leaf.xNet.dllexecutable
MD5:6A4FB68D5541898C2EC86D709C26FF86
SHA256:5C099E6C5985E413CDF8D81C84BF61977B80E1E6221E332C94490F6A72373A4A
5952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5952.7562\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Discord Hunter Checker By Weeever.exeexecutable
MD5:5B4FF415E917A4BD650DFA998741F31B
SHA256:7AD280D630CD23D8E1BF071323AC5CD35BC389F1FC3F7C5AAE147A3E5983D635
5952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5952.7562\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroGenByPROVADNIKE\unp.pytext
MD5:3B16207A83BDF1EAF0F825E4226D6049
SHA256:216F4BDE379372558DC90C8282E08BD6E5850E9F16C2F33979F74E43AAB9ABD8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
198
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
696
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6680
Discord Hunter Checker By Weeever.exe
CONNECT
174.77.111.197:4145
http://discordapp.com:4145discordapp.com:443
unknown
unknown
6408
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6992
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6408
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
7056
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6944
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
104.126.37.168:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
696
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.186.110
whitelisted
www.bing.com
  • 104.126.37.168
  • 104.126.37.153
  • 104.126.37.171
  • 104.126.37.163
  • 104.126.37.162
  • 104.126.37.161
  • 104.126.37.170
  • 104.126.37.155
  • 104.126.37.160
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.133
  • 40.126.32.74
  • 40.126.32.136
  • 40.126.32.72
  • 20.190.160.14
  • 40.126.32.134
  • 40.126.32.76
whitelisted
th.bing.com
  • 104.126.37.128
  • 104.126.37.152
  • 104.126.37.130
  • 104.126.37.139
  • 104.126.37.136
  • 104.126.37.131
  • 104.126.37.186
  • 104.126.37.137
  • 104.126.37.153
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted

Threats

No threats detected
Process
Message
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: error while getting certificate informations