File name:

Spark.exe

Full analysis: https://app.any.run/tasks/3dffd8d8-0f06-4783-903f-2f68ff1e4387
Verdict: Malicious activity
Analysis date: October 10, 2024, 18:42:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
alina
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D431F54201251619C07E4D5BF39E01CD

SHA1:

553D1AFA824C34F348F8C53D1B043D3B671D946A

SHA256:

1FABBD3D6FB5BF868EF07BE4774649C4DD3F90959EF1E4477EDD08F96DE47F03

SSDEEP:

12288:XOAVvlnNDoV35r9YwOyEQF0LEkPlSaIbV:3NDU35hYd7QF0LEwIa8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Spark.exe (PID: 1652)
      • windefender.exe (PID: 3660)
      • windefender.exe (PID: 3540)
    • Runs injected code in another process

      • windefender.exe (PID: 3660)
    • Application was injected by another process

      • explorer.exe (PID: 1296)
    • ALINA has been detected (YARA)

      • Spark.exe (PID: 1652)
      • windefender.exe (PID: 3660)
      • windefender.exe (PID: 3540)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Spark.exe (PID: 1652)
    • Starts itself from another location

      • Spark.exe (PID: 1652)
    • Application launched itself

      • taskmgr.exe (PID: 1672)
    • Reads the Internet Settings

      • Spark.exe (PID: 1652)
      • taskmgr.exe (PID: 1672)
    • Reads security settings of Internet Explorer

      • Spark.exe (PID: 1652)
  • INFO

    • Reads the computer name

      • Spark.exe (PID: 1652)
      • windefender.exe (PID: 3660)
      • windefender.exe (PID: 3540)
    • Checks supported languages

      • Spark.exe (PID: 1652)
      • windefender.exe (PID: 3660)
      • windefender.exe (PID: 3540)
    • Creates files or folders in the user directory

      • Spark.exe (PID: 1652)
    • The process uses the downloaded file

      • explorer.exe (PID: 1296)
      • taskmgr.exe (PID: 1672)
      • taskmgr.exe (PID: 2116)
    • Reads security settings of Internet Explorer

      • taskmgr.exe (PID: 1672)
      • explorer.exe (PID: 1296)
    • Manual execution by a user

      • windefender.exe (PID: 3540)
      • taskmgr.exe (PID: 1672)
    • Checks proxy server information

      • Spark.exe (PID: 1652)
    • Reads the machine GUID from the registry

      • Spark.exe (PID: 1652)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:05:23 10:51:59+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 605696
InitializedDataSize: 166400
UninitializedDataSize: -
EntryPoint: 0x486f3
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #ALINA spark.exe #ALINA windefender.exe taskmgr.exe no specs taskmgr.exe #ALINA windefender.exe explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
1296C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1652"C:\Users\admin\AppData\Local\Temp\Spark.exe" C:\Users\admin\AppData\Local\Temp\Spark.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\spark.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1672"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2116"C:\Windows\system32\taskmgr.exe" /1C:\Windows\System32\taskmgr.exe
taskmgr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3540"C:\Users\admin\AppData\Roaming\Installed\windefender.exe" C:\Users\admin\AppData\Roaming\Installed\windefender.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\roaming\installed\windefender.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3660"C:\Users\admin\AppData\Roaming\Installed\windefender.exe"C:\Users\admin\AppData\Roaming\Installed\windefender.exe
Spark.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\roaming\installed\windefender.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
1 391
Read events
1 312
Write events
73
Delete events
6

Modification events

(PID) Process:(1652) Spark.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
Operation:writeName:identifier
Value:
rvqkhh
(PID) Process:(1652) Spark.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:windefender
Value:
C:\Users\admin\AppData\Roaming\Installed\windefender.exe
(PID) Process:(1296) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
01000000D08C9DDF0115D1118C7A00C04FC297EB010000007635A32ECD75DE45A2A95C2C0D619F1A000000000200000000001066000000010000200000000AB72F0155905316FFDC2647CB3C06CD7F59ACC4402F337814CD76F0C78C7591000000000E80000000020000200000001F32ED83C4AAF56C205C9A91270763AE5FE28F505FE14D20FBD0E06FCCE9267030000000522C7D295068BD909B2CBE5D33C728D7865513DB418507BF37E984FCD0B67C1A074C3332C345FD155627945ECE43FE1640000000EE35B6782DA00114F353D5F08B2F5F48D11C26B19640BDC4658C5CC96DEC4FE7239BA38FF3E9920014BF7A5102B48F729644E603FFC1A0BD141DA10E203C8BC6
(PID) Process:(1652) Spark.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1652) Spark.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1652) Spark.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1652) Spark.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1652) Spark.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(1652) Spark.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(1652) Spark.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
Executable files
1
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1652Spark.exeC:\Users\admin\AppData\Roaming\ntkrnlbinary
MD5:430AC646952B2DAA81792F397C4A4134
SHA256:72180326AC50E668090E0811619EA57380E855C51196DDE84F3E603D3BB17F1A
1652Spark.exeC:\Users\admin\AppData\Roaming\Installed\windefender.exeexecutable
MD5:D431F54201251619C07E4D5BF39E01CD
SHA256:1FABBD3D6FB5BF868EF07BE4774649C4DD3F90959EF1E4477EDD08F96DE47F03
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
239.255.255.250:3702
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
1060
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
adobeflasherup1.com
unknown
javaoracle2.ru
unknown

Threats

No threats detected
No debug info