File name:

(infected) discord nitro generator and checker.rar

Full analysis: https://app.any.run/tasks/54a36bed-4aae-471e-b95f-40d3f5b27983
Verdict: Malicious activity
Analysis date: June 29, 2019, 12:41:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

24DA4F41E157010937A24C060350FF39

SHA1:

8C203D04C5F5607C2BD0FE147FB9DB385F11F922

SHA256:

E8A3C194633CFBD294CD397EA6ECF1A22A64BE5C5079CDB49942159F1D7CA792

SSDEEP:

3072:4ynqfOEPL1usnrzLXCm3d1VC07tjTgmwmjxoeg/USi:Fq2E7nrzLyGoITgJAc/pi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • DiscordDestroyer Reworked.exe (PID: 1724)
      • DiscordDestroyer Reworked.exe (PID: 344)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3328)
  • INFO

    • Application was crashed

      • DiscordDestroyer Reworked.exe (PID: 1724)
      • DiscordDestroyer Reworked.exe (PID: 344)
    • Manual execution by user

      • DiscordDestroyer Reworked.exe (PID: 344)
      • DiscordDestroyer Reworked.exe (PID: 1724)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe discorddestroyer reworked.exe discorddestroyer reworked.exe

Process information

PID
CMD
Path
Indicators
Parent process
344"C:\Users\admin\Desktop\(infected) discord nitro generator and checker\DiscordDestroyer Reworked.exe" C:\Users\admin\Desktop\(infected) discord nitro generator and checker\DiscordDestroyer Reworked.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
DiscordDestroyer Reworked
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\(infected) discord nitro generator and checker\discorddestroyer reworked.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1724"C:\Users\admin\Desktop\(infected) discord nitro generator and checker\DiscordDestroyer Reworked.exe" C:\Users\admin\Desktop\(infected) discord nitro generator and checker\DiscordDestroyer Reworked.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
DiscordDestroyer Reworked
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\(infected) discord nitro generator and checker\discorddestroyer reworked.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3328"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\(infected) discord nitro generator and checker.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
447
Read events
439
Write events
8
Delete events
0

Modification events

(PID) Process:(3328) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3328) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3328) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3328) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\(infected) discord nitro generator and checker.rar
(PID) Process:(3328) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3328) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3328) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3328) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
1
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3328WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3328.13176\(infected) discord nitro generator and checker\DiscordDestroyer Reworked.exeexecutable
MD5:304530E634678A9076823AC13952C245
SHA256:6A7A114F8D5048387FE496FAE2288CA7490F8ADDE999F34A06733F995E0AF93B
3328WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3328.13176\(infected) discord nitro generator and checker\vipsocks.txttext
MD5:35CB3DF14950B2C9F9B1AA3D150775CE
SHA256:3BF4EA3A68DE3CC84F3F79854644B68C370862856F715FA6D99E079D3C1A1C28
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info