| File name: | SeafkoAgent.exe |
| Full analysis: | https://app.any.run/tasks/630b8f25-c8c5-4e48-8c31-403083651961 |
| Verdict: | Malicious activity |
| Analysis date: | January 21, 2019, 20:28:14 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | A6CAAB5963E62B6F4B85FA9993999B71 |
| SHA1: | CE246DBD144EAEFC25AC801954435D91A13A697C |
| SHA256: | 8E3401A72E28060C8D3CAD5EC1440B521D09208F4ECDBE2B777208A253D45829 |
| SSDEEP: | 24576:fGfomqdQYddBgyHCBEJPplYq6r/6hllzJ6Ic01re2g+b60/1WR:+GBgyHC6JPIiDJJ6Ic0JTgZn |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (56.7) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (21.3) |
| .scr | | | Windows screen saver (10.1) |
| .dll | | | Win32 Dynamic Link Library (generic) (5) |
| .exe | | | Win32 Executable (generic) (3.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:13 08:56:14+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 1617920 |
| InitializedDataSize: | 2560 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x18cfee |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | Windows Explorer |
| CompanyName: | Microsoft |
| FileDescription: | Windows Explorer |
| FileVersion: | 1.0.0.0 |
| InternalName: | SeafkoAgent.exe |
| LegalCopyright: | Copyright © 2019 |
| LegalTrademarks: | SAEFKO |
| OriginalFileName: | SeafkoAgent.exe |
| ProductName: | Windows Explorer |
| ProductVersion: | 1.0.0.0 |
| AssemblyVersion: | 1.0.0.0 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 13-Jan-2019 07:56:14 |
| Debug artifacts: |
|
| Comments: | Windows Explorer |
| CompanyName: | Microsoft |
| FileDescription: | Windows Explorer |
| FileVersion: | 1.0.0.0 |
| InternalName: | SeafkoAgent.exe |
| LegalCopyright: | Copyright © 2019 |
| LegalTrademarks: | SAEFKO |
| OriginalFilename: | SeafkoAgent.exe |
| ProductName: | Windows Explorer |
| ProductVersion: | 1.0.0.0 |
| Assembly Version: | 1.0.0.0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000080 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 3 |
| Time date stamp: | 13-Jan-2019 07:56:14 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00002000 | 0x0018AFF4 | 0x0018B000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.43954 |
.rsrc | 0x0018E000 | 0x00000610 | 0x00000800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.45544 |
.reloc | 0x00190000 | 0x0000000C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.10191 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.00112 | 490 | UNKNOWN | UNKNOWN | RT_MANIFEST |
mscoree.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2752 | "C:\Users\admin\AppData\Local\explorer.exe" | C:\Users\admin\AppData\Local\explorer.exe | SeafkoAgent.exe | ||||||||||||
User: admin Company: Microsoft Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3000 | "C:\Users\admin\AppData\Local\Temp\SeafkoAgent.exe" | C:\Users\admin\AppData\Local\Temp\SeafkoAgent.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3000) SeafkoAgent.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3000) SeafkoAgent.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2752) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | explorer |
Value: C:\Users\admin\AppData\Local\explorer.exe | |||
| (PID) Process: | (2752) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2752) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2752) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2752 | explorer.exe | C:\Users\admin\AppData\Local\Microsoft\explorer.exe_Url_vlhelphgjtvlqdutrar14pu4p3dag15u\1.0.0.0\doiofaxj.newcfg | — | |
MD5:— | SHA256:— | |||
| 2752 | explorer.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\History1 | sqlite | |
MD5:— | SHA256:— | |||
| 2752 | explorer.exe | C:\Users\admin\AppData\Local\Newtonsoft.Json.dll | executable | |
MD5:83222120C8095B8623FE827FB70FAF6B | SHA256:EFF79DE319CA8941A2E62FB573230D82B79B80958E5A26AB1A4E87193EB13503 | |||
| 3000 | SeafkoAgent.exe | C:\Users\admin\AppData\Local\explorer.exe | executable | |
MD5:— | SHA256:— | |||
| 2752 | explorer.exe | C:\Users\admin\AppData\Local\AForge.Video.dll | executable | |
MD5:0BD34AA29C7EA4181900797395A6DA78 | SHA256:BAFA6ED04CA2782270074127A0498DDE022C2A9F4096C6BB2B8E3C08BB3D404D | |||
| 2752 | explorer.exe | C:\Users\admin\AppData\Local\CommonData.dll | executable | |
MD5:— | SHA256:— | |||
| 2752 | explorer.exe | C:\Users\admin\AppData\Local\sqlite3.dll | executable | |
MD5:87F9E5A6318AC1EC5EE05AA94A919D7A | SHA256:7705B87603E0D772E1753441001FCF1AC2643EE41BF14A8177DE2C056628665C | |||
| 2752 | explorer.exe | C:\Users\admin\AppData\Local\AForge.Video.DirectShow.dll | executable | |
MD5:17ED442E8485AC3F7DC5B3C089654A61 | SHA256:666D44798D94EAFA1ED21AF79E9BC0293FFD96F863AB5D87F78BCEE9EF9FFD6B | |||
| 2752 | explorer.exe | C:\Users\admin\AppData\Local\Microsoft\explorer.exe_Url_vlhelphgjtvlqdutrar14pu4p3dag15u\1.0.0.0\user.config | xml | |
MD5:— | SHA256:— | |||
| 2752 | explorer.exe | C:\Users\admin\AppData\Local\log.txt | text | |
MD5:B1BA38B1A3EA7B6C92453E502B3A9399 | SHA256:70C444228BE0B3D0A662B40693B53C7F2C1E176E17386BD12D5FAC56D7AAE963 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2752 | explorer.exe | POST | 200 | 145.14.145.44:80 | http://psychiatric-limp.000webhostapp.com/server.php?pass=aufteile88&command=RegisterNewMachine | US | text | 25 b | shared |
2752 | explorer.exe | GET | 204 | 172.217.22.78:80 | http://clients3.google.com/generate_204 | US | — | — | whitelisted |
2752 | explorer.exe | GET | 200 | 145.14.145.44:80 | http://psychiatric-limp.000webhostapp.com/server.php?pass=aufteile88&command=UpdateIRCServer&server=W3siSVJDX1NFUkVWRVIiOiJpcmMuZGVlcHNwYWNlLm9yZyIsIklSQ19QT1JUIjo2NjY3LCJJUkNfTklDS05BTUUiOiJ3YXphemcifSx7IklSQ19TRVJFVkVSIjoiaXJjLmFiamVjdHMubmV0IiwiSVJDX1BPUlQiOjY2NjksIklSQ19OSUNLTkFNRSI6ImZmZ2tpaCJ9XQ==&id=55 | US | text | 399 b | shared |
2752 | explorer.exe | GET | 200 | 145.14.145.44:80 | http://psychiatric-limp.000webhostapp.com/server.php?pass=aufteile88&command=UpdateHTTPIRCStatus&machine_id=55&irc_status=1 | US | text | 2 b | shared |
2752 | explorer.exe | GET | 200 | 145.14.145.44:80 | http://psychiatric-limp.000webhostapp.com/server.php?pass=aufteile88&command=UpdateHTTPIRCStatus&machine_id=55&irc_status=2 | US | text | 2 b | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2752 | explorer.exe | 172.217.22.78:80 | clients3.google.com | Google Inc. | US | whitelisted |
2752 | explorer.exe | 216.239.36.21:443 | ipinfo.io | Google Inc. | US | whitelisted |
2752 | explorer.exe | 69.162.163.58:6667 | irc.deepspace.org | Steadfast | US | unknown |
2752 | explorer.exe | 145.14.145.44:80 | psychiatric-limp.000webhostapp.com | Hostinger International Limited | US | shared |
2752 | explorer.exe | 23.236.134.201:6669 | irc.abjects.net | B2 Net Solutions Inc. | CA | malicious |
2752 | explorer.exe | 94.23.108.48:6669 | irc.azzurra.org | OVH SAS | FR | malicious |
2752 | explorer.exe | 149.56.231.24:6669 | irc.chat4all.org | OVH SAS | CA | unknown |
2752 | explorer.exe | 216.18.189.227:6667 | irc.ecnet.org | Reflected Networks, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
clients3.google.com |
| whitelisted |
ipinfo.io |
| shared |
psychiatric-limp.000webhostapp.com |
| shared |
irc.deepspace.org |
| unknown |
irc.azzurra.org |
| malicious |
irc.abjects.net |
| malicious |
irc.chat4all.org |
| unknown |
irc.ecnet.org |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2752 | explorer.exe | A Network Trojan was detected | ET POLICY Possible External IP Lookup Domain Observed in SNI (ipinfo. io) |
2752 | explorer.exe | Potential Corporate Privacy Violation | ET POLICY Possible External IP Lookup SSL Cert Observed (ipinfo.io) |
1056 | svchost.exe | Not Suspicious Traffic | ET INFO Observed Free Hosting Domain (*.000webhostapp .com in DNS Lookup) |
2752 | explorer.exe | Misc activity | ET CHAT IRC PONG response |
2752 | explorer.exe | Misc activity | ET CHAT IRC PING command |
2752 | explorer.exe | Misc activity | ET CHAT IRC authorization message |