Click to jump to signature section
Source: main.exe | Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: Joe Sandbox View | IP Address: 162.159.133.234 162.159.133.234 |
Source: Joe Sandbox View | IP Address: 162.159.135.232 162.159.135.232 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /api/v9/gateway HTTP/1.1Host: discord.comUser-Agent: DiscordBot (https://github.com/bwmarrin/discordgo, v0.28.1)Authorization: Bot MTMyOTE1MzA2MjAzNTUyNTczNQ.GBlPSk.65ejGNMtJ75aP7ZZJhBWYoPIN-p7uvw3vy95egAccept-Encoding: gzip |
Source: global traffic | HTTP traffic detected: GET /?v=9&encoding=json HTTP/1.1Host: gateway.discord.ggUser-Agent: Go-http-client/1.1Accept-Encoding: zlibConnection: UpgradeSec-WebSocket-Key: yQz05quw2GMcxQzzDAEY8A==Sec-WebSocket-Version: 13Upgrade: websocket |
Source: global traffic | DNS traffic detected: DNS query: discord.com |
Source: global traffic | DNS traffic detected: DNS query: gateway.discord.gg |
Source: global traffic | HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 15 Jan 2025 18:40:09 GMTContent-Length: 0Connection: closeCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=jfkNzBRdOklNWds8y1fIiErYOgpkrV4Z8bLdMxzu91q0YVqOH%2Fnp6ULXAsmAOtgqPt3UMsrOPECRaJDDAO42j%2FhCypXmwlMgaSI8Nz37ubcn5v0r1xZY%2BW6t7dVxOAU%2FPNEaIg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Strict-Transport-Security: max-age=31536000; includeSubDomains; preloadX-Content-Type-Options: nosniffServer: cloudflareCF-RAY: 9027fe182dca32ca-EWR |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://cdn.discordapp.com/attachments/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://cdn.discordapp.com/avatars/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://cdn.discordapp.com/banners/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://cdn.discordapp.com/channel-icons/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://cdn.discordapp.com/guilds/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://cdn.discordapp.com/icons/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://cdn.discordapp.com/role-icons/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://cdn.discordapp.com/splashes/ |
Source: main.exe | String found in binary or memory: https://discord.com/MESSAGE_REACTION_ADDTHREAD_MEMBER_UPDATEunmarshall |
Source: main.exe, 00000000.00000002.2121725257.000000C000188000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9//sticker-packs |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9//voice/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9//voice/regions |
Source: main.exe, 00000000.00000002.2121725257.000000C000188000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/09Az~~kernel32.dllREQUEST_METHODiphlpapi.dll |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/applications |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/channels/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/gateway |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/gateway/bot |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/guilds |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/guilds/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/guilds/https://discord.com/api/v9/channels/https://discord.com/api/v9/use |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/oauth2/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/oauth2/applications |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/stage-instances |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/stickers/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/users/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/webhooks/ |
Source: main.exe | String found in binary or memory: https://github.com/bwmarrin/discordgo |
Source: main.exe, 00000000.00000002.2121725257.000000C0001BE000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://status.discord.com/api/v2/scheduled-maintenances/ |
Source: main.exe, 00000000.00000002.2121725257.000000C0001BE000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://status.discord.com/api/v2/scheduled-maintenances/D |
Source: main.exe, 00000000.00000002.2121725257.000000C0001C0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://status.discord.com/api/v2/scheduled-maintenances/active.json |
Source: main.exe, 00000000.00000002.2121725257.000000C0001C0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://status.discord.com/api/v2/scheduled-maintenances/active.jsonhttps://status.discord.com/api/v |
Source: main.exe, 00000000.00000002.2121725257.000000C0001C0000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://status.discord.com/api/v2/scheduled-maintenances/upcoming.json |
Source: unknown | Network traffic detected: HTTP traffic on port 49706 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49705 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49706 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49705 |
Source: main.exe | Static PE information: Section: /19 ZLIB complexity 0.9997105089027911 |
Source: main.exe | Static PE information: Section: /32 ZLIB complexity 0.9944322680995475 |
Source: main.exe | Static PE information: Section: /65 ZLIB complexity 0.9992629542495265 |
Source: main.exe | Static PE information: Section: /78 ZLIB complexity 0.9907113854244229 |
Source: classification engine | Classification label: mal48.winEXE@2/0@2/2 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:432:120:WilError_03 |
Source: main.exe | Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: main.exe | String found in binary or memory: error connecting to udp addr %s, %serror sending disconnect packet, %ssuccessfully reconnected to gateway1776356839400250464677810668945312588817841970012523233890533447265625ryuFtoaFixed32 called with prec > 9reflect.MakeSlice of non-slice typepersistentalloc: align is too large/memory/classes/heap/released:bytesgreyobject: obj not pointer-alignedmismatched begin/end of activeSweepmheap.freeSpanLocked - invalid freefailed to get or create weak handleattempt to clear non-empty span setruntime: close polldesc w/o unblockruntime: inconsistent read deadlineNtCreateWaitCompletionPacket failedfindrunnable: netpoll with spinningpidleput: P has non-empty run queuetraceback did not unwind completelyruntime: createevent failed; errno=2006-01-02T15:04:05.999999999Z07:00non-positive interval for NewTickernetwork dropped connection on resettransport endpoint is not connectedfile type does not support deadlinehttp: server closed idle connectionCONTINUATION frame with stream ID 0invalid utf8 payload in close framebad successive approximation valuesSubscribeServiceChangeNotificationsunsupported signature algorithm: %vtls: too many non-advancing recordstls: server selected an invalid PSKtls: invalid Kyber server key sharemime: bogus characters after %%: %qhpack: invalid Huffman-encoded datadynamic table size update too largeflate: corrupt input before offset hash/crc32: invalid hash state sizetoo many Questions to pack (>65535)bigmod: modulus is smaller than natx509: malformed extension OID fieldx509: wrong Ed25519 public key sizex509: invalid authority info accessmlkem768: invalid ciphertext lengthcrypto/md5: invalid hash state size'_' must separate successive digitsP224 point is the point at infinityP256 point is the point at infinityP384 point is the point at infinityP521 point is the point at infinitysuperfluous leading zeros in lengthchacha20: output smaller than inputtransform: short destination bufferstrings.Builder.Grow: negative countstrings: Join output length overflowShardID must be less than ShardCounterror dispatching internal event, %scannot specify both Embed and Embedserror reconnecting to channel %s, %serror closing session connection, %serror decoding websocket message, %ssending heartbeat in response to Op1444089209850062616169452667236328125ryuFtoaFixed64 called with prec > 180123456789abcdefghijklmnopqrstuvwxyzmethod ABI and value ABI don't alignlfstack node allocated from the heap) is larger than maximum page size (key s |