MarcФайл
For example I was approaching this trying to unpack the payload as you said before. Long run. But probably would have been better testing the binary in a sandbox first. Looking for some ioc indicating the discord token exfiltration suspect. E.g. some network request, access to browser cached data etc.
Many many thanks helpful advices