download:

TheAltening.zip

Full analysis: https://app.any.run/tasks/fd29e48b-0359-4f99-808f-51ce78bd8157
Verdict: Malicious activity
Analysis date: January 26, 2020, 18:15:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

128613D33309441A61A2B11EEFFA5411

SHA1:

602FF3D21AF1668D64E5EC7C1D774A1C41931C66

SHA256:

7E374B6E1C1D8116C9390A6A51A67476A5753214B175468E68FEBB4CF7C80B39

SSDEEP:

786432:UR4MVQPpOQ9il1dAZibuyVi0sKENHQj2oVyEXsODl2:UR4MVwOmS10ib1aKEYO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • TheAltening.exe (PID: 1492)
    • Changes settings of System certificates

      • TheAltening.exe (PID: 1492)
  • SUSPICIOUS

    • Creates files in the program directory

      • TheAltening.exe (PID: 1492)
    • Modifies the open verb of a shell class

      • TheAltening.exe (PID: 1492)
    • Executable content was dropped or overwritten

      • TheAltening.exe (PID: 1492)
    • Creates files in the user directory

      • TheAltening.exe (PID: 1492)
    • Adds / modifies Windows certificates

      • TheAltening.exe (PID: 1492)
  • INFO

    • Manual execution by user

      • TheAltening.exe (PID: 1492)
    • Dropped object may contain Bitcoin addresses

      • TheAltening.exe (PID: 1492)
    • Reads settings of System Certificates

      • TheAltening.exe (PID: 1492)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:12:31 20:17:05
ZipCRC: 0x67b9decf
ZipCompressedSize: 30587268
ZipUncompressedSize: 86228619
ZipFileName: TheAltening.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs thealtening.exe

Process information

PID
CMD
Path
Indicators
Parent process
1492"C:\Users\admin\Desktop\TheAltening.exe" C:\Users\admin\Desktop\TheAltening.exe
explorer.exe
User:
admin
Company:
GUI-CORE
Integrity Level:
HIGH
Description:
GUI-CORE
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\thealtening.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
1916"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\TheAltening.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
2 421
Read events
1 061
Write events
1 356
Delete events
4

Modification events

(PID) Process:(1916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1916) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\TheAltening.zip
(PID) Process:(1916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(1916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
265
Suspicious files
1
Text files
4
Unknown types
1

Dropped files

PID
Process
Filename
Type
1916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1916.10584\TheAltening.exe
MD5:
SHA256:
1492TheAltening.exeC:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\GUI-CORE.deps.jsontext
MD5:
SHA256:
1492TheAltening.exeC:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\Microsoft.DiaSymReader.Native.x86.dllexecutable
MD5:4FF7094E3EDFDA47CED912012044296B
SHA256:F21DA9FB831AC943736135B6EE109A4B352511B8D6C07CB03C66B61996D1DDC9
1492TheAltening.exeC:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\API-MS-Win-core-xstate-l2-1-0.dllexecutable
MD5:641BADD4D75C3CC6669A1C7F40FFBBFA
SHA256:1A657F1E35BC6F2E4D5B3A0D465DA1FAABE1AC3387E25ADAEDD53FEFAF0C6812
1492TheAltening.exeC:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:8894176AF3EA65A09AE5CF4C0E6FF50F
SHA256:C64B7C6400E9BACC1A4F1BAED6374BFBCE9A3F8CF20C2D03F81EF18262F89C60
1492TheAltening.exeC:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\api-ms-win-core-localization-l1-2-0.dllexecutable
MD5:23BD405A6CFD1E38C74C5150EEC28D0A
SHA256:A7FA48DE6C06666B80184AFEE7E544C258E0FB11399AB3FE47D4E74667779F41
1492TheAltening.exeC:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:879920C7FA905036856BCB10875121D9
SHA256:7E4CBA620B87189278B5631536CDAD9BFDA6E12ABD8E4EB647CB85369A204FE8
1492TheAltening.exeC:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:D91BF81CF5178D47D1A588B0DF98EB24
SHA256:F8E3B45FD3E22866006F16A9E73E28B5E357F31F3C275B517692A5F16918B492
1492TheAltening.exeC:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\GUI-CORE.runtimeconfig.jsontext
MD5:5A285CB4F7105F3D3E9953141DB45FAE
SHA256:D4D1F1EFC0908FEA5E7EE2D6976C0DF5F62204B10E3067B460E89378AEB71DC8
1492TheAltening.exeC:\Users\admin\AppData\Local\Temp\.net\TheAltening\5d4\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:AABBB38C4110CC0BF7203A567734A7E7
SHA256:24B07028C1E38B9CA2F197750654A0DFB7D33C2E52C9DD67100609499E8028DB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1492
TheAltening.exe
GET
200
2.19.43.67:80
http://cert.int-x3.letsencrypt.org/
unknown
der
1.15 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1492
TheAltening.exe
142.44.142.126:443
api.thealtening.com
OVH SAS
CA
unknown
1492
TheAltening.exe
2.19.43.67:80
cert.int-x3.letsencrypt.org
Akamai International B.V.
unknown

DNS requests

Domain
IP
Reputation
api.thealtening.com
  • 142.44.142.126
suspicious
cert.int-x3.letsencrypt.org
  • 2.19.43.67
whitelisted

Threats

No threats detected
No debug info