File name: | Delivery Note - AWD 200038485852- 2349203968876.gz |
Full analysis: | https://app.any.run/tasks/37abda00-2a76-4c0b-9b5d-e9f58cc5c4ae |
Verdict: | Malicious activity |
Threats: | Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold. |
Analysis date: | October 22, 2019, 06:47:50 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/gzip |
File info: | gzip compressed data, was "Delivery Note - AWD 200038485852- 2349203968876.exe", last modified: Tue Oct 22 03:44:08 2019, from FAT filesystem (MS-DOS, OS/2, NT) |
MD5: | 1203CE1D3BBA02C90A0B73937F7BB725 |
SHA1: | 3A4EC86162142EFAE157580BA630FE7D969094E5 |
SHA256: | 90DBE9F00B5703E671C52E6995395989C85A780FC882699176F6E02525323566 |
SSDEEP: | 12288:+qUyx17F5e1uiO0KyrO5+16zj8NO6BXCbh122ohgDC8MJW+iHtrj4559Nco6x+/Q:+qHu1c0b65+16zwNXAXoh7bwt4Yj0VS |
.z/gz/gzip | | | GZipped data (100) |
---|
ArchivedFileName: | Delivery Note - AWD 200038485852- 2349203968876.exe |
---|---|
OperatingSystem: | FAT filesystem (MS-DOS, OS/2, NT/Win32) |
ExtraFlags: | (none) |
ModifyDate: | 2019:10:22 05:44:08+02:00 |
Flags: | FileName |
Compression: | Deflated |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2168 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Delivery Note - AWD 200038485852- 2349203968876.gz.z" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 Modules
| |||||||||||||||
3376 | "C:\Users\admin\Desktop\Delivery Note - AWD 200038485852- 2349203968876.exe" | C:\Users\admin\Desktop\Delivery Note - AWD 200038485852- 2349203968876.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
2184 | "C:\\\\Windows\\\\Microsoft.NET\\\\Framework\\\\v2.0.50727\\\\RegAsm.exe" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe | Delivery Note - AWD 200038485852- 2349203968876.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Assembly Registration Utility Version: 2.0.50727.5420 (Win7SP1.050727-5400) Modules
|
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Delivery Note - AWD 200038485852- 2349203968876.gz.z | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2168) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
(PID) Process: | (2184) RegAsm.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RegAsm_RASAPI32 |
Operation: | write | Name: | EnableFileTracing |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2184 | RegAsm.exe | C:\Users\admin\AppData\Local\Temp\637073273340878750_9afee31a-ca67-4b5a-a3ff-4358a07021a7.db | sqlite | |
MD5:0B3C43342CE2A99318AA0FE9E531C57B | SHA256:0CCB4915E00390685621DA3D75EBFD5EDADC94155A79C66415A7F4E9763D71B8 | |||
2168 | WinRAR.exe | C:\Users\admin\Desktop\Delivery Note - AWD 200038485852- 2349203968876.exe | executable | |
MD5:A991005C3EB17F2B0463B1C5285F5C1C | SHA256:2E55B89E4004826564C10B8560E5860F5215390399F7461A53B7548124859C2A |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2184 | RegAsm.exe | GET | 200 | 52.55.255.113:80 | http://checkip.amazonaws.com/ | US | text | 15 b | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2184 | RegAsm.exe | 23.95.206.190:21 | ftp.pehledinekam.com | ColoCrossing | US | malicious |
2184 | RegAsm.exe | 52.55.255.113:80 | checkip.amazonaws.com | Amazon.com, Inc. | US | shared |
2184 | RegAsm.exe | 23.95.206.190:59903 | ftp.pehledinekam.com | ColoCrossing | US | malicious |
Domain | IP | Reputation |
---|---|---|
checkip.amazonaws.com |
| shared |
ftp.pehledinekam.com |
| malicious |
PID | Process | Class | Message |
---|---|---|---|
— | — | A Network Trojan was detected | MALWARE [PTsecurity] AgentTesla IP Check |
— | — | Generic Protocol Command Decode | SURICATA Applayer Detect protocol only one direction |
— | — | A Network Trojan was detected | MALWARE [PTsecurity] AgentTesla Exfiltration |
— | — | A Network Trojan was detected | MALWARE [PTsecurity] AgentTesla Exfiltration |