inter_weather_v345.exe

WeatherMan

The application inter_weather_v345.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Interstat’. The file has been seen being downloaded from dl.interstat.eu. While running, it connects to the Internet address static.25.22.243.136.clients.your-server.de on port 80 using the HTTP protocol.
Publisher:
WeatherMan

Product:
WeatherMan

Version:
1.0.3.40

MD5:
848bdbfa655c2a7e705817329106720b

SHA-1:
f71317e1865f7750349042287d91a697edcfcd66

SHA-256:
d43bd19ce60bcc5e96dc571482dd0acad77732cc4a50972a62098cf04fe85294

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 3:22:51 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Techsnab (M)
16.10.10.10

File size:
4.3 MB (4,551,680 bytes)

Product version:
1.0.3.40

Copyright:
Copyright (C) 2016

Original file name:
WeatherMan.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\inter_weather_v345.exe

File PE Metadata
Compilation timestamp:
4/26/2016 8:46:07 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
98304:TIpJbNZA2kL1mq80h2VCPD9vG1mq80hPRN:TIzbNZAQq8rCPTq82R

Entry address:
0x9A437

Entry point:
E8, 0E, 3D, 01, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 10, 32, 4F, 00, E8, C3, 88, 00, 00, E8, 18, 55, 00, 00, 0F, B7, F0, 6A, 02, E8, A9, 7B, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 38, 8A, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.5894

Code size:
832 KB (851,968 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Interstat

Command:
C:\users\{user}\appdata\roaming\interstat\interstat.exe


The file inter_weather_v345.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to static.25.22.243.136.clients.your-server.de  (136.243.22.25:80)

Remove inter_weather_v345.exe - Powered by Reason Core Security