File name:

이미지 무단사용 내용.alz

Full analysis: https://app.any.run/tasks/ebceef72-75d8-4c8a-a594-3c9d260f29f5
Verdict: Malicious activity
Analysis date: April 12, 2019, 04:56:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/octet-stream
File info: data
MD5:

25A43D695D3D26D5367E9C31913EE4B5

SHA1:

1318A1B5616AFCC36B0261ED47C2A732BC6E4CAF

SHA256:

8E219F166A9F2027C5201EC91B8C52D7B4E22E0169AE36CDDEF04335F42865A2

SSDEEP:

6144:K5o3FicBWvxKjOmzKI83AJIl5YuMnAQksqPr6Lei85o3FicBWvxKjOmzKI83AJIG:tFiOWvKxKIL6zMnkRerFiOWvKxKIL6zW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ALZip851.exe (PID: 3932)
      • ALZip851.exe (PID: 3240)
      • ALZip.exe (PID: 804)
      • ALUpdate.exe (PID: 2556)
      • Alupdate.exe (PID: 3532)
      • ALUpdate.exe (PID: 3248)
      • ALZip.exe (PID: 1868)
      • ALCMUpdate.exe (PID: 3488)
      • AuthSerialReg.exe (PID: 3368)
      • ALSTSCollector.exe (PID: 2172)
    • Loads dropped or rewritten executable

      • ALZip851.exe (PID: 3240)
      • ALZip.exe (PID: 1868)
      • ALZip.exe (PID: 804)
    • Registers / Runs the DLL via REGSVR32.EXE

      • ALZip851.exe (PID: 3240)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • firefox.exe (PID: 1880)
      • ALZip851.exe (PID: 3240)
    • Reads internet explorer settings

      • ALZip851.exe (PID: 3240)
    • Reads Internet Cache Settings

      • ALZip851.exe (PID: 3240)
    • Creates files in the program directory

      • ALZip851.exe (PID: 3240)
    • Creates COM task schedule object

      • regsvr32.exe (PID: 1320)
    • Creates files in the user directory

      • ALZip.exe (PID: 804)
      • ALUpdate.exe (PID: 2556)
      • Alupdate.exe (PID: 3532)
      • ALCMUpdate.exe (PID: 3488)
      • ALZip.exe (PID: 1868)
    • Creates a software uninstall entry

      • ALZip851.exe (PID: 3240)
    • Application launched itself

      • ALUpdate.exe (PID: 2556)
    • Modifies the open verb of a shell class

      • ALZip.exe (PID: 804)
  • INFO

    • Modifies the open verb of a shell class

      • rundll32.exe (PID: 2852)
    • Reads CPU info

      • firefox.exe (PID: 1880)
    • Application launched itself

      • firefox.exe (PID: 1880)
    • Reads settings of System Certificates

      • firefox.exe (PID: 1880)
    • Creates files in the user directory

      • firefox.exe (PID: 1880)
    • Dropped object may contain TOR URL's

      • firefox.exe (PID: 1880)
    • Dropped object may contain Bitcoin addresses

      • ALZip851.exe (PID: 3240)
    • Changes settings of System certificates

      • pingsender.exe (PID: 2332)
    • Adds / modifies Windows certificates

      • pingsender.exe (PID: 2332)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.alz | ALZip compressed archive (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
21
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start rundll32.exe no specs notepad.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe firefox.exe alzip851.exe no specs alzip851.exe regsvr32.exe no specs alupdate.exe no specs alzip.exe alupdate.exe no specs alupdate.exe alzip.exe no specs alcmupdate.exe pingsender.exe authserialreg.exe alstscollector.exe no specs explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
804"C:\Program Files\ESTsoft\ALZip\ALZip.exe" "/install"C:\Program Files\ESTsoft\ALZip\ALZip.exe
ALZip851.exe
User:
admin
Company:
ESTsoft Corp.
Integrity Level:
HIGH
Description:
ALZip
Exit code:
0
Version:
11, 8, 23, 0
Modules
Images
c:\program files\estsoft\alzip\alzip.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1320regsvr32.exe /s "C:\Program Files\ESTsoft\ALZip\AZCTM.dll"C:\Windows\system32\regsvr32.exeALZip851.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1868"C:\Program Files\ESTsoft\ALZip\ALZip.exe" C:\Program Files\ESTsoft\ALZip\ALZip.exeALZip851.exe
User:
admin
Company:
ESTsoft Corp.
Integrity Level:
MEDIUM
Description:
ALZip
Exit code:
0
Version:
11, 8, 23, 0
Modules
Images
c:\program files\estsoft\alzip\alzip.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1880"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exe
explorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
65.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
2152"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2172"C:\Program Files\ESTsoft\Common\ALSTSCollector.exe" C:\Program Files\ESTsoft\Common\ALSTSCollector.exeALZip.exe
User:
admin
Company:
ESTsoft corp.
Integrity Level:
MEDIUM
Description:
ALSTS Collector
Exit code:
0
Version:
11, 7, 15, 0
Modules
Images
c:\program files\estsoft\common\alstscollector.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2332"C:\Program Files\Mozilla Firefox\pingsender.exe" https://incoming.telemetry.mozilla.org/submit/telemetry/7edd06fa-da93-4a2e-a977-4c80c7d94af0/main/Firefox/65.0.2/release/20190225143501?v=4 C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\7edd06fa-da93-4a2e-a977-4c80c7d94af0C:\Program Files\Mozilla Firefox\pingsender.exe
firefox.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
MEDIUM
Exit code:
0
Version:
65.0.2
Modules
Images
c:\program files\mozilla firefox\pingsender.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
2452"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1880.27.1417219556\1391346440" -childID 4 -isForBrowser -prefsHandle 7208 -prefMapHandle 7836 -prefsLen 7035 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1880 "\\.\pipe\gecko-crash-server-pipe.1880" 7624 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
65.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
2556"C:\Program Files\ESTsoft\ALUpdate\ALUpdate.exe" /SetNowALTools altoolsC:\Program Files\ESTsoft\ALUpdate\ALUpdate.exeALZip851.exe
User:
admin
Company:
ESTsoft Corp.
Integrity Level:
HIGH
Description:
ALTools Automatic Updater Program
Exit code:
0
Version:
11, 4, 28, 2
Modules
Images
c:\program files\estsoft\alupdate\alupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2584"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1880.13.1896658563\375540520" -childID 2 -isForBrowser -prefsHandle 2532 -prefMapHandle 2536 -prefsLen 216 -prefMapSize 180950 -schedulerPrefs 0001,2 -parentBuildID 20190225143501 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1880 "\\.\pipe\gecko-crash-server-pipe.1880" 2548 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
65.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
Total events
4 380
Read events
3 186
Write events
1 180
Delete events
14

Modification events

(PID) Process:(2852) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:LangID
Value:
0904
(PID) Process:(2852) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Value:
Adobe Acrobat Reader DC
(PID) Process:(2852) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\eHome\ehshell.exe
Value:
Windows Media Center
(PID) Process:(2852) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Internet Explorer\iexplore.exe
Value:
Internet Explorer
(PID) Process:(2852) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\system32\mspaint.exe
Value:
Paint
(PID) Process:(2852) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\system32\NOTEPAD.EXE
Value:
Notepad
(PID) Process:(2852) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\PROGRA~1\MICROS~1\Office14\OIS.EXE
Value:
Microsoft Office 2010
(PID) Process:(2852) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Opera\Opera.exe
Value:
Opera Internet Browser
(PID) Process:(2852) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Windows Photo Viewer\PhotoViewer.dll
Value:
Windows Photo Viewer
(PID) Process:(2852) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\VideoLAN\VLC\vlc.exe
Value:
VLC media player
Executable files
72
Suspicious files
623
Text files
210
Unknown types
220

Dropped files

PID
Process
Filename
Type
1880firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
1880firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\cache2\trash32408
MD5:
SHA256:
1880firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.js
MD5:
SHA256:
1880firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmp
MD5:
SHA256:
1880firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm
MD5:
SHA256:
1880firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-malware-simple.sbstore
MD5:
SHA256:
1880firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-malware-simple.pset
MD5:
SHA256:
1880firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-phish-simple.sbstore
MD5:
SHA256:
1880firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-phish-simple.pset
MD5:
SHA256:
1880firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\safebrowsing-updating\test-unwanted-simple.sbstore
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
98
TCP/UDP connections
367
DNS requests
664
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1880
firefox.exe
POST
200
216.58.212.227:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
1880
firefox.exe
POST
200
95.101.0.130:80
http://ocsp.trustwave.com/
unknown
der
638 b
whitelisted
1880
firefox.exe
POST
200
216.58.212.227:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
1880
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
1880
firefox.exe
POST
200
188.121.36.239:80
http://ocsp.godaddy.com/
NL
der
1.74 Kb
whitelisted
1880
firefox.exe
POST
200
216.58.212.227:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
1880
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
1880
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
1880
firefox.exe
POST
200
216.58.212.227:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
1880
firefox.exe
POST
200
188.121.36.239:80
http://ocsp.godaddy.com/
NL
der
1.74 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1880
firefox.exe
95.101.0.210:80
detectportal.firefox.com
Akamai International B.V.
whitelisted
1880
firefox.exe
143.204.221.59:443
snippets.cdn.mozilla.net
US
unknown
1880
firefox.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
1880
firefox.exe
54.149.115.79:443
tiles.services.mozilla.com
Amazon.com, Inc.
US
unknown
1880
firefox.exe
172.217.168.234:443
safebrowsing.googleapis.com
Google Inc.
US
whitelisted
1880
firefox.exe
216.58.212.206:443
consent.google.com
Google Inc.
US
whitelisted
1880
firefox.exe
172.217.19.196:443
www.google.com
Google Inc.
US
whitelisted
1880
firefox.exe
172.217.17.99:443
www.gstatic.com
Google Inc.
US
whitelisted
1880
firefox.exe
172.217.20.99:443
ssl.gstatic.com
Google Inc.
US
whitelisted
1880
firefox.exe
52.26.235.130:443
shavar.services.mozilla.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
detectportal.firefox.com
  • 95.101.0.210
whitelisted
search.services.mozilla.com
  • 34.213.175.109
whitelisted
tiles.services.mozilla.com
  • 54.149.115.79
whitelisted
snippets.cdn.mozilla.net
  • 143.204.221.59
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
safebrowsing.googleapis.com
  • 172.217.168.234
whitelisted
ocsp.pki.goog
  • 216.58.212.227
whitelisted
www.youtube.com
  • 172.217.17.78
whitelisted
www.amazon.de
  • 143.204.223.172
  • 52.41.57.47
whitelisted
www.facebook.com
  • 31.13.91.36
whitelisted

Threats

PID
Process
Class
Message
3240
ALZip851.exe
A Network Trojan was detected
ET POLICY User-Agent (NSIS_Inetc (Mozilla)) - Sometimes used by hostile installers
6 ETPRO signatures available at the full report
Process
Message
ALZip851.exe
Name
ALZip851.exe
Name
ALZip851.exe
checkurl
ALZip851.exe
changename
ALZip851.exe
changename
ALZip851.exe
default
ALZip851.exe
Free
ALZip851.exe
C:\Program Files\ESTsoft\ALZip\nsmBF7A.tmp
ALZip851.exe
stemp1
ALZip851.exe
stemp2