| URL: | https://setup4pc.ru/ru/land/discord/?utm_source=direct&utm_medium=cpc&utm_campaign=discord-cis&utm_content=0&utm_term=discord%20приложение&yclid=1466531582404230964 |
| Full analysis: | https://app.any.run/tasks/6e850d2b-1e19-4f93-a3dd-b65de607024c |
| Verdict: | Malicious activity |
| Analysis date: | March 25, 2021, 18:03:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 253668767D00731971481DA05BDD3BD8 |
| SHA1: | 96C98CD38483FCD4322F94798B7A138F80D68D76 |
| SHA256: | CC22617DA74AA0318A5455FB60EB05C7A6709027CD3627F82780CBE849B2F5E9 |
| SSDEEP: | 3:N8NCMAKNNXHW6Mu6jRIYORHTomkGMolAL+psmXoGg1a0lq15dXhGJMBHII:2IaNhW64ShcmqEsm4l1a0lO5dxGJMtv |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 540 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1000,5922209532170056843,131925092742100944,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=9063579428566806959 --mojo-platform-channel-handle=1016 --ignored=" --type=renderer " /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 632 | C:\Windows\System32\reg.exe add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Discord /d C:\Users\admin\AppData\Local\Discord\app-0.0.295\Discord.exe /f | C:\Windows\System32\reg.exe | Discord.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 872 | "C:\Users\admin\AppData\Local\Discord\app-0.0.295\Discord.exe" | C:\Users\admin\AppData\Local\Discord\app-0.0.295\Discord.exe | — | Update.exe | |||||||||||
User: admin Company: Hammer & Chisel, Inc. Integrity Level: MEDIUM Description: Discord Exit code: 0 Version: 0.0.295 Modules
| |||||||||||||||
| 1012 | C:\Windows\System32\reg.exe add HKCU\Software\Classes\Discord\DefaultIcon /ve /d "\"C:\Users\admin\AppData\Local\Discord\app-0.0.295\Discord.exe\",-1" /f | C:\Windows\System32\reg.exe | — | Discord.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1144 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1000,5922209532170056843,131925092742100944,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=3865418882713292140 --mojo-platform-channel-handle=2044 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1436 | "C:\Users\admin\AppData\Local\Discord\Update.exe" --processStart Discord.exe | C:\Users\admin\AppData\Local\Discord\Update.exe | — | explorer.exe | |||||||||||
User: admin Company: GitHub Integrity Level: MEDIUM Description: Update Exit code: 0 Version: 1.1.1.0 Modules
| |||||||||||||||
| 1844 | "C:\Users\admin\AppData\Local\Temp\is-4BLL4.tmp\Soft\discord.exe" | C:\Users\admin\AppData\Local\Temp\is-4BLL4.tmp\Soft\discord.exe | explorer.exe | ||||||||||||
User: admin Company: Hammer & Chisel, Inc. Integrity Level: MEDIUM Description: Discord - https://discordapp.com/ Exit code: 0 Version: 0.0.295 Modules
| |||||||||||||||
| 1896 | C:\Users\admin\AppData\Local\Discord\Update.exe --update https://discordapp.com/api/updates/stable | C:\Users\admin\AppData\Local\Discord\Update.exe | Discord.exe | ||||||||||||
User: admin Company: GitHub Integrity Level: MEDIUM Description: Update Exit code: 0 Version: 1.1.1.0 Modules
| |||||||||||||||
| 1916 | "C:\Users\admin\AppData\Local\Temp\is-4JIV9.tmp\discord-cis.g5255.tmp" /SL5="$30170,62225062,491520,C:\Users\admin\Downloads\discord-cis.g5255.exe" /SPAWNWND=$20172 /NOTIFYWND=$5012A | C:\Users\admin\AppData\Local\Temp\is-4JIV9.tmp\discord-cis.g5255.tmp | discord-cis.g5255.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1928 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1000,5922209532170056843,131925092742100944,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=8291230855490286599 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2076 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| (PID) Process: | (2240) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2240) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2240) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2240) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2240) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2548) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | write | Name: | 2240-13261169016693125 |
Value: 259 | |||
| (PID) Process: | (2240) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2240) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
| (PID) Process: | (2240) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes |
| Operation: | delete value | Name: | 3252-13245750958665039 |
Value: 0 | |||
| (PID) Process: | (2240) chrome.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96} |
| Operation: | write | Name: | usagestats |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2240 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-605CD079-8C0.pma | — | |
MD5:— | SHA256:— | |||
| 2240 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2240 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\67be3d7f-ad85-4784-a7dc-9023ac2538fb.tmp | — | |
MD5:— | SHA256:— | |||
| 2240 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp | — | |
MD5:— | SHA256:— | |||
| 2240 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2240 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF12ccfd.TMP | text | |
MD5:— | SHA256:— | |||
| 2240 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2240 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old | text | |
MD5:— | SHA256:— | |||
| 2240 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2240 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF12d029.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1896 | Update.exe | GET | — | 162.159.134.232:80 | http://dl.discordapp.net/apps/win/Discord-0.0.309-full.nupkg | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1916 | discord-cis.g5255.tmp | 35.217.27.166:443 | reqapi.ru | — | US | suspicious |
1916 | discord-cis.g5255.tmp | 142.250.74.200:443 | ssl.google-analytics.com | Google Inc. | US | suspicious |
2568 | chrome.exe | 172.67.137.39:443 | setup4pc.ru | — | US | unknown |
2568 | chrome.exe | 172.217.20.8:443 | www.googletagmanager.com | Google Inc. | US | suspicious |
2568 | chrome.exe | 151.101.130.109:443 | cdn.jsdelivr.net | Fastly | US | unknown |
2568 | chrome.exe | 142.250.74.142:443 | www.google-analytics.com | Google Inc. | US | whitelisted |
2568 | chrome.exe | 93.158.134.119:443 | mc.yandex.ru | YANDEX LLC | RU | whitelisted |
2568 | chrome.exe | 172.217.20.3:443 | ssl.gstatic.com | Google Inc. | US | whitelisted |
2568 | chrome.exe | 87.250.251.119:443 | mc.yandex.ru | YANDEX LLC | RU | whitelisted |
2568 | chrome.exe | 35.190.80.1:443 | a.nel.cloudflare.com | Google Inc. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
setup4pc.ru |
| unknown |
accounts.google.com |
| shared |
www.googletagmanager.com |
| whitelisted |
cdn.jsdelivr.net |
| whitelisted |
www.google-analytics.com |
| whitelisted |
mc.yandex.ru |
| whitelisted |
ssl.gstatic.com |
| whitelisted |
inst.setup4pc.ru |
| unknown |
a.nel.cloudflare.com |
| whitelisted |
sb-ssl.google.com |
| whitelisted |
Process | Message |
|---|---|
discord.exe | Start up installer: |
discord.exe | Elevated process: ?s?
|
discord.exe | Want machine install |
discord.exe | we are UAC elevated, so restart C:\Users\admin\AppData\Local\Temp\is-4BLL4.tmp\Soft\discord.exe,
|
discord.exe | Start up installer: |
discord.exe | Elevated process: ?
|
discord.exe | Want standard install |
Discord.exe | [2652:3848:0325/180548:VERBOSE1:crash_service_main.cc(76)] Session start. cmdline is [--reporter-url=http://crash.discordapp.com:1127/post --application-name=Discord --v=1 --submit-backlog]
|
Discord.exe | [2652:3848:0325/180548:VERBOSE1:crash_service.cc(172)] window handle is 000201BA
|
Discord.exe | [2652:3848:0325/180548:VERBOSE1:crash_service.cc(318)] pipe name is \\.\pipe\Discord Crash Service
dumps at C:\Users\admin\AppData\Local\Temp\Discord Crashes
|