| File name: | Discord Nitro Gen+Check Pack By PROVADNIKE.zip |
| Full analysis: | https://app.any.run/tasks/afaca020-5088-4672-85fd-508e5665ebf1 |
| Verdict: | Malicious activity |
| Threats: | Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links. |
| Analysis date: | June 21, 2021, 00:59:21 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 2E56D907169980BC490AC1998B9C1630 |
| SHA1: | F556E2033F01AC23D5A259B53BD2CA58AD578BCC |
| SHA256: | C150E6A45BCEF8224033D55A785C8F9A80D30AEE938126B6F317DFF77F3A3875 |
| SSDEEP: | 196608:6Zvk0voOOUnQ3HUq5fAQ7R6FZmRna9ZTNHrZf7WuPP5ER3FRm8w8D4eNZbhy6V8n:6FbxnQlAQkmxanNHlDWcP5ER3Xm8P4Os |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | Discord Nitro Gen+Check Pack By PROVADNIKE/ |
|---|---|
| ZipUncompressedSize: | - |
| ZipCompressedSize: | - |
| ZipCRC: | 0x00000000 |
| ZipModifyDate: | 2020:09:09 16:51:05 |
| ZipCompression: | None |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 10 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 304 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=820,16454982710601998133,5524998099506497726,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --extension-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2924 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 328 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=820,16454982710601998133,5524998099506497726,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=3004 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 872 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=820,16454982710601998133,5524998099506497726,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3124 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1032 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=820,16454982710601998133,5524998099506497726,131072 --enable-features=PasswordImport --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --mojo-platform-channel-handle=2828 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1112 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=820,16454982710601998133,5524998099506497726,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=3256 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1112 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=820,16454982710601998133,5524998099506497726,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=34 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3232 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1172 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=820,16454982710601998133,5524998099506497726,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2200 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1172 | "C:\Users\admin\Desktop\EzSploit.exe" | C:\Users\admin\Desktop\EzSploit.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 1240 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=820,16454982710601998133,5524998099506497726,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=3332 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| 1244 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=820,16454982710601998133,5524998099506497726,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2332 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 86.0.4240.198 Modules
| |||||||||||||||
| (PID) Process: | (3268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3268) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Discord Nitro Gen+Check Pack By PROVADNIKE.zip | |||
| (PID) Process: | (3268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3268) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3268) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\notepad.exe,-469 |
Value: Text Document | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3268.2634\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\combo.txt | — | |
MD5:— | SHA256:— | |||
| 3268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3268.3011\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\combo.txt | — | |
MD5:— | SHA256:— | |||
| 3268 | WinRAR.exe | C:\Users\admin\Desktop\NitroChecker\combo.txt | — | |
MD5:— | SHA256:— | |||
| 3268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3268.2634\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Discord Hunter Checker By Weeever.exe | executable | |
MD5:5B4FF415E917A4BD650DFA998741F31B | SHA256:7AD280D630CD23D8E1BF071323AC5CD35BC389F1FC3F7C5AAE147A3E5983D635 | |||
| 3268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3268.2634\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Colorful.Console.dll | executable | |
MD5:AC4267B870699A799E05B2BE2D2956DA | SHA256:309C616209120EE751DF11612A8EADD06E8C86E68510D0B31BA21290782516FC | |||
| 3268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3268.2634\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Newtonsoft.Json.dll | executable | |
MD5:6815034209687816D8CF401877EC8133 | SHA256:7F912B28A07C226E0BE3ACFB2F57F050538ABA0100FA1F0BF2C39F1A1F1DA814 | |||
| 3268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3268.3011\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\proxies.txt | text | |
MD5:3A5A055CC1E507C0B7723ECE697E89DA | SHA256:59B46D9591B7AE27B8389C4C8E08FD3C2FD43A30B221BCC153EBD33554D47BE3 | |||
| 3268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3268.2634\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroGenByPROVADNIKE\Nitro Generator.exe | executable | |
MD5:1F9C211139F2C434FD94BDC490FCE46B | SHA256:BFA2A93A619EDEB81C57453670EE4772C08DA5101888FC27ACCA74DBEDEECEBD | |||
| 3268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3268.3011\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\Discord Hunter Checker By Weeever.exe | executable | |
MD5:5B4FF415E917A4BD650DFA998741F31B | SHA256:7AD280D630CD23D8E1BF071323AC5CD35BC389F1FC3F7C5AAE147A3E5983D635 | |||
| 3268 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3268.2634\Discord Nitro Gen+Check Pack By PROVADNIKE\NitroChecker\proxies.txt | text | |
MD5:3A5A055CC1E507C0B7723ECE697E89DA | SHA256:59B46D9591B7AE27B8389C4C8E08FD3C2FD43A30B221BCC153EBD33554D47BE3 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4068 | Discord Hunter Checker By Weeever.exe | CONNECT | — | 184.185.2.103:4145 | http://discordapp.com:4145discordapp.com:443 | US | — | — | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | CONNECT | — | 173.254.222.162:1080 | http://discordapp.com:1080discordapp.com:443 | US | — | — | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | CONNECT | — | 72.195.34.42:4145 | http://discordapp.com:4145discordapp.com:443 | US | — | — | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | CONNECT | — | 173.254.222.162:1080 | http://discordapp.com:1080discordapp.com:443 | US | — | — | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | CONNECT | — | 173.254.222.162:1080 | http://discordapp.com:1080discordapp.com:443 | US | — | — | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | CONNECT | — | 173.254.222.162:1080 | http://discordapp.com:1080discordapp.com:443 | US | — | — | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | CONNECT | — | 98.162.96.52:4145 | http://discordapp.com:4145discordapp.com:443 | US | — | — | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | CONNECT | — | 24.249.199.12:4145 | http://discordapp.com:4145discordapp.com:443 | US | — | — | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | CONNECT | — | 24.249.199.4:4145 | http://discordapp.com:4145discordapp.com:443 | US | — | — | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | CONNECT | — | 173.254.222.162:1080 | http://discordapp.com:1080discordapp.com:443 | US | — | — | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4068 | Discord Hunter Checker By Weeever.exe | 121.42.9.57:8888 | — | Hangzhou Alibaba Advertising Co.,Ltd. | CN | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | 138.197.2.106:16413 | — | Digital Ocean, Inc. | US | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | 192.111.143.92:4145 | — | Total Server Solutions L.L.C. | US | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | 96.44.183.149:55225 | — | QuadraNet, Inc | US | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | 192.111.130.3:4145 | — | Total Server Solutions L.L.C. | US | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | 95.174.67.50:18080 | — | — | — | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | 46.151.150.11:9999 | — | Swift Trace ltd. | UA | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | 72.11.148.222:56533 | — | QuadraNet, Inc | US | suspicious |
4068 | Discord Hunter Checker By Weeever.exe | 104.248.63.15:30588 | — | — | US | suspicious |
2652 | chrome.exe | 172.217.16.99:443 | clientservices.googleapis.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
clients2.google.com |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| malicious |
encrypted-tbn0.gstatic.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
ogs.google.com |
| whitelisted |
apis.google.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1456 | EzSploit.exe | A Network Trojan was detected | AV TROJAN RedLine Stealer Config Download |
2284 | EzSploit.exe | A Network Trojan was detected | AV TROJAN RedLine Stealer Config Download |
3100 | EzSploit.exe | A Network Trojan was detected | AV TROJAN RedLine Stealer Config Download |
3220 | EzSploit.exe | A Network Trojan was detected | AV TROJAN RedLine Stealer Config Download |
2608 | EzSploit.exe | A Network Trojan was detected | AV TROJAN RedLine Stealer Config Download |