| download: | TheAltening.zip |
| Full analysis: | https://app.any.run/tasks/fd29e48b-0359-4f99-808f-51ce78bd8157 |
| Verdict: | Malicious activity |
| Analysis date: | January 26, 2020, 18:15:54 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 128613D33309441A61A2B11EEFFA5411 |
| SHA1: | 602FF3D21AF1668D64E5EC7C1D774A1C41931C66 |
| SHA256: | 7E374B6E1C1D8116C9390A6A51A67476A5753214B175468E68FEBB4CF7C80B39 |
| SSDEEP: | 786432:UR4MVQPpOQ9il1dAZibuyVi0sKENHQj2oVyEXsODl2:UR4MVwOmS10ib1aKEYO |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2019:12:31 20:17:05 |
| ZipCRC: | 0x67b9decf |
| ZipCompressedSize: | 30587268 |
| ZipUncompressedSize: | 86228619 |
| ZipFileName: | TheAltening.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1492 | "C:\Users\admin\Desktop\TheAltening.exe" | C:\Users\admin\Desktop\TheAltening.exe | explorer.exe | ||||||||||||
User: admin Company: GUI-CORE Integrity Level: HIGH Description: GUI-CORE Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1916 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\TheAltening.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (1916) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1916) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1916) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1916) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\TheAltening.zip | |||
| (PID) Process: | (1916) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1916) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1916) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1916) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1916) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (1916) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1916 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1916.10584\TheAltening.exe | — | |
MD5:— | SHA256:— | |||
| 1492 | TheAltening.exe | C:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\GUI-CORE.deps.json | text | |
MD5:— | SHA256:— | |||
| 1492 | TheAltening.exe | C:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\Microsoft.DiaSymReader.Native.x86.dll | executable | |
MD5:4FF7094E3EDFDA47CED912012044296B | SHA256:F21DA9FB831AC943736135B6EE109A4B352511B8D6C07CB03C66B61996D1DDC9 | |||
| 1492 | TheAltening.exe | C:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\API-MS-Win-core-xstate-l2-1-0.dll | executable | |
MD5:641BADD4D75C3CC6669A1C7F40FFBBFA | SHA256:1A657F1E35BC6F2E4D5B3A0D465DA1FAABE1AC3387E25ADAEDD53FEFAF0C6812 | |||
| 1492 | TheAltening.exe | C:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\api-ms-win-core-datetime-l1-1-0.dll | executable | |
MD5:8894176AF3EA65A09AE5CF4C0E6FF50F | SHA256:C64B7C6400E9BACC1A4F1BAED6374BFBCE9A3F8CF20C2D03F81EF18262F89C60 | |||
| 1492 | TheAltening.exe | C:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\api-ms-win-core-localization-l1-2-0.dll | executable | |
MD5:23BD405A6CFD1E38C74C5150EEC28D0A | SHA256:A7FA48DE6C06666B80184AFEE7E544C258E0FB11399AB3FE47D4E74667779F41 | |||
| 1492 | TheAltening.exe | C:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\api-ms-win-core-debug-l1-1-0.dll | executable | |
MD5:879920C7FA905036856BCB10875121D9 | SHA256:7E4CBA620B87189278B5631536CDAD9BFDA6E12ABD8E4EB647CB85369A204FE8 | |||
| 1492 | TheAltening.exe | C:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\api-ms-win-core-errorhandling-l1-1-0.dll | executable | |
MD5:D91BF81CF5178D47D1A588B0DF98EB24 | SHA256:F8E3B45FD3E22866006F16A9E73E28B5E357F31F3C275B517692A5F16918B492 | |||
| 1492 | TheAltening.exe | C:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\GUI-CORE.runtimeconfig.json | text | |
MD5:5A285CB4F7105F3D3E9953141DB45FAE | SHA256:D4D1F1EFC0908FEA5E7EE2D6976C0DF5F62204B10E3067B460E89378AEB71DC8 | |||
| 1492 | TheAltening.exe | C:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\api-ms-win-core-console-l1-1-0.dll | executable | |
MD5:AABBB38C4110CC0BF7203A567734A7E7 | SHA256:24B07028C1E38B9CA2F197750654A0DFB7D33C2E52C9DD67100609499E8028DB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1492 | TheAltening.exe | GET | 200 | 2.19.43.67:80 | http://cert.int-x3.letsencrypt.org/ | unknown | der | 1.15 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1492 | TheAltening.exe | 142.44.142.126:443 | api.thealtening.com | OVH SAS | CA | unknown |
1492 | TheAltening.exe | 2.19.43.67:80 | cert.int-x3.letsencrypt.org | Akamai International B.V. | — | unknown |
Domain | IP | Reputation |
|---|---|---|
api.thealtening.com |
| suspicious |
cert.int-x3.letsencrypt.org |
| whitelisted |