Source: Discordd.exe, type: SAMPLE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: Discordd.exe, type: SAMPLE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 2.0.Discordd.exe.10000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 2.0.Discordd.exe.10000.0.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 2.2.Discordd.exe.24fbd14.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 2.2.Discordd.exe.24fbd14.0.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 2.2.Discordd.exe.24fbd14.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 2.2.Discordd.exe.24fbd14.0.raw.unpack, type: UNPACKEDPE | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 00000009.00000002.2577392722.000000000306C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 00000002.00000002.1374889421.00000000024FB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 00000002.00000002.1374889421.00000000024FB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 00000002.00000002.1374889421.00000000023B1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: 00000002.00000000.1315180363.0000000000012000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: 00000002.00000000.1315180363.0000000000012000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: Process Memory Space: Discordd.exe PID: 6920, type: MEMORYSTR | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: Process Memory Space: Discord.exe PID: 7220, type: MEMORYSTR | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: C:\Users\user\AppData\Roaming\Discord.exe, type: DROPPED | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 Author: unknown |
Source: C:\Users\user\AppData\Roaming\Discord.exe, type: DROPPED | Matched rule: Detects file containing reversed ASEP Autorun registry keys Author: ditekSHen |
Source: Discordd.exe, type: SAMPLE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: Discordd.exe, type: SAMPLE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 2.0.Discordd.exe.10000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 2.0.Discordd.exe.10000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 2.2.Discordd.exe.24fbd14.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 2.2.Discordd.exe.24fbd14.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 2.2.Discordd.exe.24fbd14.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 2.2.Discordd.exe.24fbd14.0.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 00000009.00000002.2577392722.000000000306C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 00000002.00000002.1374889421.00000000024FB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 00000002.00000002.1374889421.00000000024FB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 00000002.00000002.1374889421.00000000023B1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: 00000002.00000000.1315180363.0000000000012000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: 00000002.00000000.1315180363.0000000000012000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: Process Memory Space: Discordd.exe PID: 6920, type: MEMORYSTR | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: Process Memory Space: Discord.exe PID: 7220, type: MEMORYSTR | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: C:\Users\user\AppData\Roaming\Discord.exe, type: DROPPED | Matched rule: Windows_Trojan_Asyncrat_11a11ba1 reference_sample = fe09cd1d13b87c5e970d3cbc1ebc02b1523c0a939f961fc02c1395707af1c6d1, os = windows, severity = x86, creation_date = 2021-08-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Asyncrat, fingerprint = 715ede969076cd413cebdfcf0cdda44e3a6feb5343558f18e656f740883b41b8, id = 11a11ba1-c178-4415-9c09-45030b500f50, last_modified = 2021-10-04 |
Source: C:\Users\user\AppData\Roaming\Discord.exe, type: DROPPED | Matched rule: INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse author = ditekSHen, description = Detects file containing reversed ASEP Autorun registry keys |
Source: Discordd.exe, EIZBVsWqABSiXu.cs | Base64 encoded string: 'Lp+t9jqQg8mxA+ujUfJQzmSlL8I1jsvbdNwJ/rCoYKHziWLKo2xZDCl0nydlBzBgpgbdAEwAyDsWC4vyT2CfgO17v0zf3UjC9UPVTPpOurk=', '/KDz9CuD0eYRTmHG7wbZCuuxt1VSz5KiKBCq+pHt1mToQhstBl4OuDid9tZDc5GqmiuKHJBqmvHiKPqZjHaCmA==', 'n1B1O4T5EIoi2fONT81CNRqEgjeSK/loNkUerSmphve1czVwWFZ7TG1jdwD88mg1ate1MO4DwWtIpvKmsOvbxg==', 'Ubo3dvRvcXm5CuVO1HFYzm8YQwKCLf4836rdxMLOVvntv9XO4F3XZL15daoVcuNBgqZIIIUUgqvSbfb9UtE7FyxPDFdthUErhb08x2uwD10dYeelqEzzguTYO6n5QH4TyDyJyVnBrG5pqkEaM9/25U0h3ZRVoT5Pw+z83yA7GkbVhLtK9CR+7lv+XQMGHr6WsXyGXTpnApuUlNC0HHKzEkZ7pNIHAWtfZFMd7lWLX7dzmDiNVl+6fK83oxI5rrLJvL8wN9oESiBeprodBNiTkPTxGy63KNOlUulFqvCS95gv5ZBFXBEy5hyjwYM/nr9q4lT7ELBmAd5XUcM9nvgeYzc1B24ExC+ALIh5sEuFet2kLk6qw/Z5cmXx/izQM4gAAhMbnU3Kcc/4oDSA1XDNganq6pE6RxznIuKlT7u5lbF9wbLhf66xiOqUTVYsJWBTOpwWk9hCqjdYJ6ZwTwjd3FPjjblfUiwtCHchzhdonOgLGhiRTSa78UAjttNywa+YRa6pRc0NroxqYtQ8A8kX7VaNUsaLFoi3gSGQNBVZbbMp7yLIgxgKghlU0GS9+osy+DmNzleuYK/YbHuKB3jdpWFO3flMVDBsbGgRedxelUlbBvP2rCxwosbyulp7Fmcjsd2cabdS8UpXTcRHS1ygfJj7diVQE7CptlJ8a/RAch86mxUI1YqJVZhAuvX7yk/uPRxYCgIBoz79B9ddrEdCc954IwoQnzZFPD2n564ESX/RZIVjvCBFmEbkYv/4UpcBXpfkPOraYaHPqMmyJk7RNkAvhs0MBgbY0vLk5AKvWt6hE2LZU7r7txBii5VHUKt5ZwEWJ4WQzBExeftXiBTx0l4GMO5eNnfiqWT/iIRwzJ6gnTC5pfrqCAY0aotFo8pAhYYvKM1+8tx1906gcMD0Z9h5JrDpOq41T1tcy7yJH/MGM3uzOkqingDrS91YEMMGyUJGRlIACy/OH8VrOnMvjw==', 'wA8UwiSQ/QHiX6VMjSXmTNm4iFOTehARjhZoG+L2FEdRWyJKISXKuI3S0sbwlCnEm1t38uMbT/aT6YuE9WTJhA==', 'oDgKNvr3p8PjVOQnL3sm89ZVmlAqpaonSJB8D4bSzJx2ogSw9pwbW/6UM4tIXyYAHKp9y1UUXWTt0AtspnV1TQ==', 'Lekp8q7V/ka1XVoKg8AfFG24tc77xD28ALOtNFjWYZSHG4gDnnUCghS6xTXJCH+O0KjDQcR7uCitkrOFMm4N6A==' |
Source: Discord.exe.2.dr, EIZBVsWqABSiXu.cs | Base64 encoded string: 'Lp+t9jqQg8mxA+ujUfJQzmSlL8I1jsvbdNwJ/rCoYKHziWLKo2xZDCl0nydlBzBgpgbdAEwAyDsWC4vyT2CfgO17v0zf3UjC9UPVTPpOurk=', '/KDz9CuD0eYRTmHG7wbZCuuxt1VSz5KiKBCq+pHt1mToQhstBl4OuDid9tZDc5GqmiuKHJBqmvHiKPqZjHaCmA==', 'n1B1O4T5EIoi2fONT81CNRqEgjeSK/loNkUerSmphve1czVwWFZ7TG1jdwD88mg1ate1MO4DwWtIpvKmsOvbxg==', 'Ubo3dvRvcXm5CuVO1HFYzm8YQwKCLf4836rdxMLOVvntv9XO4F3XZL15daoVcuNBgqZIIIUUgqvSbfb9UtE7FyxPDFdthUErhb08x2uwD10dYeelqEzzguTYO6n5QH4TyDyJyVnBrG5pqkEaM9/25U0h3ZRVoT5Pw+z83yA7GkbVhLtK9CR+7lv+XQMGHr6WsXyGXTpnApuUlNC0HHKzEkZ7pNIHAWtfZFMd7lWLX7dzmDiNVl+6fK83oxI5rrLJvL8wN9oESiBeprodBNiTkPTxGy63KNOlUulFqvCS95gv5ZBFXBEy5hyjwYM/nr9q4lT7ELBmAd5XUcM9nvgeYzc1B24ExC+ALIh5sEuFet2kLk6qw/Z5cmXx/izQM4gAAhMbnU3Kcc/4oDSA1XDNganq6pE6RxznIuKlT7u5lbF9wbLhf66xiOqUTVYsJWBTOpwWk9hCqjdYJ6ZwTwjd3FPjjblfUiwtCHchzhdonOgLGhiRTSa78UAjttNywa+YRa6pRc0NroxqYtQ8A8kX7VaNUsaLFoi3gSGQNBVZbbMp7yLIgxgKghlU0GS9+osy+DmNzleuYK/YbHuKB3jdpWFO3flMVDBsbGgRedxelUlbBvP2rCxwosbyulp7Fmcjsd2cabdS8UpXTcRHS1ygfJj7diVQE7CptlJ8a/RAch86mxUI1YqJVZhAuvX7yk/uPRxYCgIBoz79B9ddrEdCc954IwoQnzZFPD2n564ESX/RZIVjvCBFmEbkYv/4UpcBXpfkPOraYaHPqMmyJk7RNkAvhs0MBgbY0vLk5AKvWt6hE2LZU7r7txBii5VHUKt5ZwEWJ4WQzBExeftXiBTx0l4GMO5eNnfiqWT/iIRwzJ6gnTC5pfrqCAY0aotFo8pAhYYvKM1+8tx1906gcMD0Z9h5JrDpOq41T1tcy7yJH/MGM3uzOkqingDrS91YEMMGyUJGRlIACy/OH8VrOnMvjw==', 'wA8UwiSQ/QHiX6VMjSXmTNm4iFOTehARjhZoG+L2FEdRWyJKISXKuI3S0sbwlCnEm1t38uMbT/aT6YuE9WTJhA==', 'oDgKNvr3p8PjVOQnL3sm89ZVmlAqpaonSJB8D4bSzJx2ogSw9pwbW/6UM4tIXyYAHKp9y1UUXWTt0AtspnV1TQ==', 'Lekp8q7V/ka1XVoKg8AfFG24tc77xD28ALOtNFjWYZSHG4gDnnUCghS6xTXJCH+O0KjDQcR7uCitkrOFMm4N6A==' |
Source: 2.2.Discordd.exe.24fbd14.0.raw.unpack, EIZBVsWqABSiXu.cs | Base64 encoded string: 'Lp+t9jqQg8mxA+ujUfJQzmSlL8I1jsvbdNwJ/rCoYKHziWLKo2xZDCl0nydlBzBgpgbdAEwAyDsWC4vyT2CfgO17v0zf3UjC9UPVTPpOurk=', '/KDz9CuD0eYRTmHG7wbZCuuxt1VSz5KiKBCq+pHt1mToQhstBl4OuDid9tZDc5GqmiuKHJBqmvHiKPqZjHaCmA==', 'n1B1O4T5EIoi2fONT81CNRqEgjeSK/loNkUerSmphve1czVwWFZ7TG1jdwD88mg1ate1MO4DwWtIpvKmsOvbxg==', 'Ubo3dvRvcXm5CuVO1HFYzm8YQwKCLf4836rdxMLOVvntv9XO4F3XZL15daoVcuNBgqZIIIUUgqvSbfb9UtE7FyxPDFdthUErhb08x2uwD10dYeelqEzzguTYO6n5QH4TyDyJyVnBrG5pqkEaM9/25U0h3ZRVoT5Pw+z83yA7GkbVhLtK9CR+7lv+XQMGHr6WsXyGXTpnApuUlNC0HHKzEkZ7pNIHAWtfZFMd7lWLX7dzmDiNVl+6fK83oxI5rrLJvL8wN9oESiBeprodBNiTkPTxGy63KNOlUulFqvCS95gv5ZBFXBEy5hyjwYM/nr9q4lT7ELBmAd5XUcM9nvgeYzc1B24ExC+ALIh5sEuFet2kLk6qw/Z5cmXx/izQM4gAAhMbnU3Kcc/4oDSA1XDNganq6pE6RxznIuKlT7u5lbF9wbLhf66xiOqUTVYsJWBTOpwWk9hCqjdYJ6ZwTwjd3FPjjblfUiwtCHchzhdonOgLGhiRTSa78UAjttNywa+YRa6pRc0NroxqYtQ8A8kX7VaNUsaLFoi3gSGQNBVZbbMp7yLIgxgKghlU0GS9+osy+DmNzleuYK/YbHuKB3jdpWFO3flMVDBsbGgRedxelUlbBvP2rCxwosbyulp7Fmcjsd2cabdS8UpXTcRHS1ygfJj7diVQE7CptlJ8a/RAch86mxUI1YqJVZhAuvX7yk/uPRxYCgIBoz79B9ddrEdCc954IwoQnzZFPD2n564ESX/RZIVjvCBFmEbkYv/4UpcBXpfkPOraYaHPqMmyJk7RNkAvhs0MBgbY0vLk5AKvWt6hE2LZU7r7txBii5VHUKt5ZwEWJ4WQzBExeftXiBTx0l4GMO5eNnfiqWT/iIRwzJ6gnTC5pfrqCAY0aotFo8pAhYYvKM1+8tx1906gcMD0Z9h5JrDpOq41T1tcy7yJH/MGM3uzOkqingDrS91YEMMGyUJGRlIACy/OH8VrOnMvjw==', 'wA8UwiSQ/QHiX6VMjSXmTNm4iFOTehARjhZoG+L2FEdRWyJKISXKuI3S0sbwlCnEm1t38uMbT/aT6YuE9WTJhA==', 'oDgKNvr3p8PjVOQnL3sm89ZVmlAqpaonSJB8D4bSzJx2ogSw9pwbW/6UM4tIXyYAHKp9y1UUXWTt0AtspnV1TQ==', 'Lekp8q7V/ka1XVoKg8AfFG24tc77xD28ALOtNFjWYZSHG4gDnnUCghS6xTXJCH+O0KjDQcR7uCitkrOFMm4N6A==' |
Source: unknown | Process created: C:\Users\user\Desktop\Discordd.exe "C:\Users\user\Desktop\Discordd.exe" | |
Source: C:\Users\user\Desktop\Discordd.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "Discord" /tr '"C:\Users\user\AppData\Roaming\Discord.exe"' & exit | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\Discordd.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\tmp6438.tmp.bat"" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /f /sc onlogon /rl highest /tn "Discord" /tr '"C:\Users\user\AppData\Roaming\Discord.exe"' | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 3 | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\Discord.exe C:\Users\user\AppData\Roaming\Discord.exe | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Roaming\Discord.exe "C:\Users\user\AppData\Roaming\Discord.exe" | |
Source: C:\Users\user\Desktop\Discordd.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "Discord" /tr '"C:\Users\user\AppData\Roaming\Discord.exe"' & exit | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\tmp6438.tmp.bat"" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /f /sc onlogon /rl highest /tn "Discord" /tr '"C:\Users\user\AppData\Roaming\Discord.exe"' | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\timeout.exe timeout 3 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Roaming\Discord.exe "C:\Users\user\AppData\Roaming\Discord.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: Discordd.exe, pcecfOeVpdr.cs | High entropy of concatenated method names: 'WkFeYeLzkfoQ', 'JXHYXwXaYYXaFRWt', 'HcXYVbWwxlVJv', 'KcoTuUweWYpg', 'KKSSiyMwdvbhIlx', 'xvPOVeaNfPW', 'ThIYmHZUIvHob', 'msvlsGGsoi', 'UetXFXSlpRPPFMdl', 'XEoIgtqrVMYAq' |
Source: Discord.exe.2.dr, pcecfOeVpdr.cs | High entropy of concatenated method names: 'WkFeYeLzkfoQ', 'JXHYXwXaYYXaFRWt', 'HcXYVbWwxlVJv', 'KcoTuUweWYpg', 'KKSSiyMwdvbhIlx', 'xvPOVeaNfPW', 'ThIYmHZUIvHob', 'msvlsGGsoi', 'UetXFXSlpRPPFMdl', 'XEoIgtqrVMYAq' |
Source: 2.2.Discordd.exe.24fbd14.0.raw.unpack, pcecfOeVpdr.cs | High entropy of concatenated method names: 'WkFeYeLzkfoQ', 'JXHYXwXaYYXaFRWt', 'HcXYVbWwxlVJv', 'KcoTuUweWYpg', 'KKSSiyMwdvbhIlx', 'xvPOVeaNfPW', 'ThIYmHZUIvHob', 'msvlsGGsoi', 'UetXFXSlpRPPFMdl', 'XEoIgtqrVMYAq' |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Discordd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Discord.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |