File name:

Updated PI.exe

Full analysis: https://app.any.run/tasks/8b6897db-feaa-4a2e-b9ab-bb38d59d1824
Verdict: Malicious activity
Threats:

Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.

Analysis date: October 25, 2023, 08:45:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
agenttesla
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

700DF676D2F191D31DFFD642C6097431

SHA1:

50C7B7BAC21A63E177E68C53AE43C3CBB8D92378

SHA256:

821EC2DDC08C58C9F292CCF54BA288925F3BD591224C39DEA71D4711E6CBC1E9

SSDEEP:

12288:wYI75TKHtYp8L0O2Ib47m1m1VnNH0uZliaKCZrFBsEvH9v+MMFgR/mZRM+:4mSBqbQoOF0uZliaRrFBsEvH9v+tFgkJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Updated PI.exe (PID: 2536)
    • Uses Task Scheduler to run other applications

      • Updated PI.exe (PID: 2536)
    • Steals credentials from Web Browsers

      • Updated PI.exe (PID: 2416)
    • AGENTTESLA has been detected (YARA)

      • Updated PI.exe (PID: 2416)
    • Actions looks like stealing of personal data

      • Updated PI.exe (PID: 2416)
  • SUSPICIOUS

    • Application launched itself

      • Updated PI.exe (PID: 2536)
    • Reads the Internet Settings

      • Updated PI.exe (PID: 2536)
    • Accesses Microsoft Outlook profiles

      • Updated PI.exe (PID: 2416)
    • Connects to SMTP port

      • Updated PI.exe (PID: 2416)
    • Reads settings of System Certificates

      • Updated PI.exe (PID: 2416)
    • Reads browser cookies

      • Updated PI.exe (PID: 2416)
  • INFO

    • Creates files or folders in the user directory

      • Updated PI.exe (PID: 2536)
    • Checks supported languages

      • Updated PI.exe (PID: 2536)
      • Updated PI.exe (PID: 2416)
    • Reads the computer name

      • Updated PI.exe (PID: 2536)
      • Updated PI.exe (PID: 2416)
    • Create files in a temporary directory

      • Updated PI.exe (PID: 2536)
    • Reads the machine GUID from the registry

      • Updated PI.exe (PID: 2536)
      • Updated PI.exe (PID: 2416)
    • Reads Environment values

      • Updated PI.exe (PID: 2416)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

AgentTesla

(PID) Process(2416) Updated PI.exe
Protocolsmtp
Hostmail.svshygiene.com.my
Port587
Usernamejohn@svshygiene.com.my
Password1122Jon889900
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

AssemblyVersion: 1.0.0.0
ProductVersion: 1.0.0.0
ProductName: EntidadesCompartidas
OriginalFileName: AZDb.exe
LegalTrademarks: -
LegalCopyright: Copyright © 2015
InternalName: AZDb.exe
FileVersion: 1.0.0.0
FileDescription: EntidadesCompartidas
CompanyName: -
Comments: -
CharacterSet: Unicode
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 1.0.0.0
FileVersionNumber: 1.0.0.0
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0xa4e5a
UninitializedDataSize: -
InitializedDataSize: 2048
CodeSize: 667648
LinkerVersion: 6
PEType: PE32
ImageFileCharacteristics: Executable, No line numbers, No symbols, 32-bit
TimeStamp: 2023:10:20 02:26:41+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start updated pi.exe no specs schtasks.exe no specs #AGENTTESLA updated pi.exe

Process information

PID
CMD
Path
Indicators
Parent process
776"C:\Windows\System32\schtasks.exe" /Create /TN "Updates\TpFXAQem" /XML "C:\Users\admin\AppData\Local\Temp\tmp4F7E.tmp"C:\Windows\SysWOW64\schtasks.exeUpdated PI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2416"C:\Users\admin\AppData\Local\Temp\Updated PI.exe"C:\Users\admin\AppData\Local\Temp\Updated PI.exe
Updated PI.exe
User:
admin
Integrity Level:
MEDIUM
Description:
EntidadesCompartidas
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\updated pi.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\mscoree.dll
AgentTesla
(PID) Process(2416) Updated PI.exe
Protocolsmtp
Hostmail.svshygiene.com.my
Port587
Usernamejohn@svshygiene.com.my
Password1122Jon889900
2536"C:\Users\admin\AppData\Local\Temp\Updated PI.exe" C:\Users\admin\AppData\Local\Temp\Updated PI.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
EntidadesCompartidas
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\updated pi.exe
c:\windows\system32\wow64cpu.dll
c:\windows\system32\wow64.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
966
Read events
953
Write events
13
Delete events
0

Modification events

(PID) Process:(2536) Updated PI.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2536) Updated PI.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2536) Updated PI.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2536) Updated PI.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2416) Updated PI.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\156\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
1
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2536Updated PI.exeC:\Users\admin\AppData\Roaming\TpFXAQem.exeexecutable
MD5:700DF676D2F191D31DFFD642C6097431
SHA256:821EC2DDC08C58C9F292CCF54BA288925F3BD591224C39DEA71D4711E6CBC1E9
2536Updated PI.exeC:\Users\admin\AppData\Local\Temp\tmp4F7E.tmpxml
MD5:618A19862BA9F6574E28ABC0B5FE1579
SHA256:06BDC4D478EBF8F6D8E41FCB68BBDC94F1B3393E02F3B758F4D6B9B633EB548E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
1
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
239.255.255.250:1900
unknown
4
System
192.168.100.255:137
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2416
Updated PI.exe
43.252.212.107:587
mail.svshygiene.com.my
Exa Bytes Network Sdn.Bhd.
MY
unknown

DNS requests

Domain
IP
Reputation
mail.svshygiene.com.my
  • 43.252.212.107
malicious

Threats

PID
Process
Class
Message
2416
Updated PI.exe
Successful Credential Theft Detected
STEALER [ANY.RUN] Attempt to exfiltrate via SMTP
No debug info