Windows Analysis Report
main old source new token.exe

Overview

General Information

Sample name: main old source new token.exe
Analysis ID: 1592111
MD5: f108805655f831fa251d38bf72379a15
SHA1: 5d767a6a47661186d5552e3684c0e5b566cac255
SHA256: c841378019c94440d87083a5df5b8934e437d322ff1ce8144eabdb7035686f5e
Tags: exeuser-JaffaCakes118
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

AI detected suspicious sample
Installs new ROOT certificates
IP address seen in connection with other malware
PE file contains more sections than normal
PE file contains sections with non-standard names
Stores large binary data to the registry

Classification

AV Detection

barindex
Source: Submited Sample Integrated Neural Analysis Model: Matched 99.5% probability
Source: main old source new token.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Joe Sandbox View IP Address: 162.159.128.233 162.159.128.233
Source: Joe Sandbox View IP Address: 162.159.133.234 162.159.133.234
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /api/v9/gateway HTTP/1.1Host: discord.comUser-Agent: DiscordBot (https://github.com/bwmarrin/discordgo, v0.28.1)Authorization: Bot MTMyOTE0OTkxNzEyMTQ4MjgzNA.GxFFE6.Gyegwm87ad4qZkqxGYNufLELbI5i_g2tnXgSZwAccept-Encoding: gzip
Source: global traffic HTTP traffic detected: GET /?v=9&encoding=json HTTP/1.1Host: gateway.discord.ggUser-Agent: Go-http-client/1.1Accept-Encoding: zlibConnection: UpgradeSec-WebSocket-Key: ska/Nu/1R4PyFkf7g4Rrnw==Sec-WebSocket-Version: 13Upgrade: websocket
Source: global traffic DNS traffic detected: DNS query: discord.com
Source: global traffic DNS traffic detected: DNS query: gateway.discord.gg
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 15 Jan 2025 18:18:10 GMTContent-Length: 0Connection: closeCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=AOlEbBvfte%2FjBSvBmpzZyORBXephVxnnpSFAZ6%2FPj0wJSxiqNsR%2F439LxNNrjzy4w1edV6F8WxNQlDZRdUl3DXqCoNiu6E6QuMi6HaPAX7YGiOPZyFrxUbhNdY2xjUhxi2ofHA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Strict-Transport-Security: max-age=31536000; includeSubDomains; preloadX-Content-Type-Options: nosniffServer: cloudflareCF-RAY: 9027dde6183f42b8-EWR
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/attachments/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/avatars/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/banners/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/channel-icons/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/guilds/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/icons/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/role-icons/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/splashes/
Source: main old source new token.exe String found in binary or memory: https://discord.com/MESSAGE_REACTION_ADDTHREAD_MEMBER_UPDATEunmarshall
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C000090000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9//sticker-packs
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9//voice/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9//voice/regions
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C000090000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/09Az~~kernel32.dllREQUEST_METHODiphlpapi.dll
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/applications
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/channels/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/gateway
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/gateway/bot
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/guilds
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/guilds/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/guilds/https://discord.com/api/v9/channels/https://discord.com/api/v9/use
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/oauth2/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/oauth2/applications
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/stage-instances
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/stickers/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/users/
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/webhooks/
Source: main old source new token.exe String found in binary or memory: https://github.com/bwmarrin/discordgo
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000C6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://status.discord.com/api/v2/scheduled-maintenances/active.json
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000C6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://status.discord.com/api/v2/scheduled-maintenances/active.jsonhttps://status.discord.com/api/v
Source: main old source new token.exe, 00000000.00000002.1753698026.000000C0000C6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://status.discord.com/api/v2/scheduled-maintenances/upcoming.json
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: main old source new token.exe Static PE information: Number of sections : 15 > 10
Source: main old source new token.exe Static PE information: Section: /19 ZLIB complexity 0.9993495849374399
Source: main old source new token.exe Static PE information: Section: /32 ZLIB complexity 0.9931508059954751
Source: main old source new token.exe Static PE information: Section: /65 ZLIB complexity 0.9992533529725248
Source: main old source new token.exe Static PE information: Section: /78 ZLIB complexity 0.9912943918665668
Source: classification engine Classification label: mal48.winEXE@2/0@2/2
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7332:120:WilError_03
Source: main old source new token.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\main old source new token.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: main old source new token.exe String found in binary or memory: error connecting to udp addr %s, %serror sending disconnect packet, %ssuccessfully reconnected to gateway1776356839400250464677810668945312588817841970012523233890533447265625ryuFtoaFixed32 called with prec > 9reflect.MakeSlice of non-slice typepersistentalloc: align is too large/memory/classes/heap/released:bytesgreyobject: obj not pointer-alignedmismatched begin/end of activeSweepmheap.freeSpanLocked - invalid freefailed to get or create weak handleattempt to clear non-empty span setruntime: close polldesc w/o unblockruntime: inconsistent read deadlineNtCreateWaitCompletionPacket failedfindrunnable: netpoll with spinningpidleput: P has non-empty run queuetraceback did not unwind completelyruntime: createevent failed; errno=file type does not support deadlinehttp: server closed idle connectionCONTINUATION frame with stream ID 0invalid utf8 payload in close framebad successive approximation valuesSubscribeServiceChangeNotificationsunsupported signature algorithm: %vtls: too many non-advancing recordstls: server selected an invalid PSKtls: invalid Kyber server key sharemime: bogus characters after %%: %qhpack: invalid Huffman-encoded datadynamic table size update too largeflate: corrupt input before offset hash/crc32: invalid hash state sizetoo many Questions to pack (>65535)bigmod: modulus is smaller than natx509: malformed extension OID fieldx509: wrong Ed25519 public key sizex509: invalid authority info accessmlkem768: invalid ciphertext lengthcrypto/md5: invalid hash state size'_' must separate successive digitsP224 point is the point at infinityP256 point is the point at infinityP384 point is the point at infinityP521 point is the point at infinitysuperfluous leading zeros in lengthchacha20: output smaller than inputtransform: short destination bufferstrings.Builder.Grow: negative countstrings: Join output length overflowaccessing a corrupted shared libraryTime.UnmarshalBinary: invalid lengthShardID must be less than ShardCounterror dispatching internal event, %scannot specify both Embed and Embedserror reconnecting to channel %s, %serror closing session connection, %serror decoding websocket message, %ssending heartbeat in response to Op1444089209850062616169452667236328125ryuFtoaFixed64 called with prec > 180123456789abcdefghijklmnopqrstuvwxyzmethod ABI and value ABI don't alignlfstack node allocated from the heap) is larger than maximum page size (key size not a multiple of key alignruntime: invalid typeBitsBulkBarrieruncaching span but s.allocCount == 0/memory/classes/metadata/other:bytes/sched/pauses/stopping/other:secondsuser arena span is on the wrong listruntime: marked free object in span runtime: unblock on closing polldescruntime: inconsistent write deadlineUnable to determine system directoryruntime: VirtualQuery failed; errno=runtime: sudog with non-nil waitlinkruntime: mcall called on m->g0 stackstartm: P required for spinning=true) is not Grunnable or Gscanrunnable
Source: main old source new token.exe String found in binary or memory: error connecting to udp addr %s, %serror sending disconnect packet, %ssuccessfully reconnected to gateway1776356839400250464677810668945312588817841970012523233890533447265625ryuFtoaFixed32 called with prec > 9reflect.MakeSlice of non-slice typepersistentalloc: align is too large/memory/classes/heap/released:bytesgreyobject: obj not pointer-alignedmismatched begin/end of activeSweepmheap.freeSpanLocked - invalid freefailed to get or create weak handleattempt to clear non-empty span setruntime: close polldesc w/o unblockruntime: inconsistent read deadlineNtCreateWaitCompletionPacket failedfindrunnable: netpoll with spinningpidleput: P has non-empty run queuetraceback did not unwind completelyruntime: createevent failed; errno=file type does not support deadlinehttp: server closed idle connectionCONTINUATION frame with stream ID 0invalid utf8 payload in close framebad successive approximation valuesSubscribeServiceChangeNotificationsunsupported signature algorithm: %vtls: too many non-advancing recordstls: server selected an invalid PSKtls: invalid Kyber server key sharemime: bogus characters after %%: %qhpack: invalid Huffman-encoded datadynamic table size update too largeflate: corrupt input before offset hash/crc32: invalid hash state sizetoo many Questions to pack (>65535)bigmod: modulus is smaller than natx509: malformed extension OID fieldx509: wrong Ed25519 public key sizex509: invalid authority info accessmlkem768: invalid ciphertext lengthcrypto/md5: invalid hash state size'_' must separate successive digitsP224 point is the point at infinityP256 point is the point at infinityP384 point is the point at infinityP521 point is the point at infinitysuperfluous leading zeros in lengthchacha20: output smaller than inputtransform: short destination bufferstrings.Builder.Grow: negative countstrings: Join output length overflowaccessing a corrupted shared libraryTime.UnmarshalBinary: invalid lengthShardID must be less than ShardCounterror dispatching internal event, %scannot specify both Embed and Embedserror reconnecting to channel %s, %serror closing session connection, %serror decoding websocket message, %ssending heartbeat in response to Op1444089209850062616169452667236328125ryuFtoaFixed64 called with prec > 180123456789abcdefghijklmnopqrstuvwxyzmethod ABI and value ABI don't alignlfstack node allocated from the heap) is larger than maximum page size (key size not a multiple of key alignruntime: invalid typeBitsBulkBarrieruncaching span but s.allocCount == 0/memory/classes/metadata/other:bytes/sched/pauses/stopping/other:secondsuser arena span is on the wrong listruntime: marked free object in span runtime: unblock on closing polldescruntime: inconsistent write deadlineUnable to determine system directoryruntime: VirtualQuery failed; errno=runtime: sudog with non-nil waitlinkruntime: mcall called on m->g0 stackstartm: P required for spinning=true) is not Grunnable or Gscanrunnable
Source: main old source new token.exe String found in binary or memory: C:/Program Files/Go/src/net/addrselect.go
Source: unknown Process created: C:\Users\user\Desktop\main old source new token.exe "C:\Users\user\Desktop\main old source new token.exe"
Source: C:\Users\user\Desktop\main old source new token.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Section loaded: gpapi.dll Jump to behavior
Source: main old source new token.exe Static PE information: Virtual size of .text is bigger than: 0x100000
Source: main old source new token.exe Static file information: File size 9882112 > 1048576
Source: main old source new token.exe Static PE information: Raw size of .text is bigger than: 0x100000 < 0x2ee200
Source: main old source new token.exe Static PE information: Raw size of .rdata is bigger than: 0x100000 < 0x317400
Source: main old source new token.exe Static PE information: Raw size of /65 is bigger than: 0x100000 < 0x107e00
Source: main old source new token.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: main old source new token.exe Static PE information: section name: .xdata
Source: main old source new token.exe Static PE information: section name: /4
Source: main old source new token.exe Static PE information: section name: /19
Source: main old source new token.exe Static PE information: section name: /32
Source: main old source new token.exe Static PE information: section name: /46
Source: main old source new token.exe Static PE information: section name: /65
Source: main old source new token.exe Static PE information: section name: /78
Source: main old source new token.exe Static PE information: section name: /90
Source: main old source new token.exe Static PE information: section name: .symtab

Persistence and Installation Behavior

barindex
Source: C:\Users\user\Desktop\main old source new token.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 Blob Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 Blob Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 Blob Jump to behavior
Source: C:\Users\user\Desktop\main old source new token.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: main old source new token.exe, 00000000.00000002.1756182893.000001EBC182C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\Desktop\main old source new token.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs