| File name: | Windows.Diagnostic.Document.bin |
| Full analysis: | https://app.any.run/tasks/a2d0a86f-edf7-4374-aaf7-c4e5802b7776 |
| Verdict: | Malicious activity |
| Analysis date: | November 01, 2023, 21:22:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 04AFFF1465A223A806774104B652A4F0 |
| SHA1: | 2F7056621E1A8ECB20A7639635D403E2C44E6135 |
| SHA256: | 9A785F508890D250AB9E3A43F974A89F3311EBD0E85EC98B46C76BDB7BEF7CFB |
| SSDEEP: | 98304:/iTNTdVDCiTchi7n9w+94bwjIDWfP2pG3AwhOdzTF3bDc/D1pYtpKWbcI5D8wXu/:PS/88y4oeExU6pAYTsq6P66XfOTxhRU |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2007:07:22 04:33:09+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 74752 |
| InitializedDataSize: | 21504 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x11de6 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.2.0.715 |
| ProductVersionNumber: | 1.2.0.715 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | N-able Technologies |
| FileDescription: | Advanced Monitoring Agent Setup |
| FileVersion: | - |
| InternalName: | - |
| OriginalFileName: | - |
| ProductName: | Advanced Monitoring Agent |
| ProductVersion: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1032 | "C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exe" /SPAWNWND=$F0196 /NOTIFYWND=$9035C /VERYSILENT /norestart | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exe | agent.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Advanced Monitoring Agent Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 1248 | "C:\Users\admin\AppData\Local\Temp\is-U5TNF.tmp\agent.tmp" /SL5="$C02D4,8488367,56832,C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exe" /SPAWNWND=$F0196 /NOTIFYWND=$9035C /VERYSILENT /norestart | C:\Users\admin\AppData\Local\Temp\is-U5TNF.tmp\agent.tmp | — | agent.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 1368 | C:\Windows\helppane.exe -Embedding | C:\Windows\HelpPane.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Help and Support Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1688 | "C:\Program Files\Advanced Monitoring Agent\unzip.exe" | C:\Program Files\Advanced Monitoring Agent\unzip.exe | — | agent.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 1956 | "C:\Users\admin\AppData\Local\Temp\Windows.Diagnostic.Document.bin.exe" | C:\Users\admin\AppData\Local\Temp\Windows.Diagnostic.Document.bin.exe | — | explorer.exe | |||||||||||
User: admin Company: N-able Technologies Integrity Level: MEDIUM Description: Advanced Monitoring Agent Setup Exit code: 0 Modules
| |||||||||||||||
| 2112 | "C:\Users\admin\AppData\Local\Temp\is-OT4M2.tmp\agent.tmp" /SL5="$9035C,8488367,56832,C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exe" /VERYSILENT /norestart | C:\Users\admin\AppData\Local\Temp\is-OT4M2.tmp\agent.tmp | — | agent.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 2544 | "C:\Program Files\Advanced Monitoring Agent\winagent.exe" /autoinstall | C:\Program Files\Advanced Monitoring Agent\winagent.exe | agent.tmp | ||||||||||||
User: admin Company: Remote Monitoring Integrity Level: HIGH Description: winagent Exit code: 1 Version: 10.13.8 Modules
| |||||||||||||||
| 3000 | "C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exe" /VERYSILENT /norestart | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exe | — | Windows.Diagnostic.Document.bin.exe | |||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Advanced Monitoring Agent Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 3028 | "C:\Program Files\Advanced Monitoring Agent\unzip.exe" package.zip | C:\Program Files\Advanced Monitoring Agent\unzip.exe | — | agent.tmp | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (1956) Windows.Diagnostic.Document.bin.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1956) Windows.Diagnostic.Document.bin.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1956) Windows.Diagnostic.Document.bin.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1956) Windows.Diagnostic.Document.bin.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1248) agent.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: 4BDF579E69B39BB3576BB9772852C33D9AC8CDC97487BA1570E89BA22E06FC85 | |||
| (PID) Process: | (1248) agent.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Program Files\Advanced Monitoring Agent\assetscan.exe | |||
| (PID) Process: | (1248) agent.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (1248) agent.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: 3B5594105AEB39774E7A26EB006FE071B38885E3D4270EE641119ECB832B65CD | |||
| (PID) Process: | (1248) agent.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Owner |
Value: E0040000208BD389090DDA01 | |||
| (PID) Process: | (1248) agent.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1248 | agent.tmp | C:\Program Files\Advanced Monitoring Agent\5.lng | text | |
MD5:1190EE81B83F5CEA64FD4942D76C03CF | SHA256:D5D7923A30EE8BA3071AD0D74359362F116C4D914E154103F27A909CF842CCA0 | |||
| 1032 | agent.exe | C:\Users\admin\AppData\Local\Temp\is-U5TNF.tmp\agent.tmp | executable | |
MD5:A2C4D52C66B4B399FACADB8CC8386745 | SHA256:6C0465CE64C07E729C399A338705941D77727C7D089430957DF3E91A416E9D2A | |||
| 1248 | agent.tmp | C:\Program Files\Advanced Monitoring Agent\unins000.exe | executable | |
MD5:D7C918793B7F6EBFB34D34FCBF0A8749 | SHA256:9C2F4F7BDAB3FFD39EFAF9DD904CF031A38E1253B6645A61A2FA8364E0808299 | |||
| 1956 | Windows.Diagnostic.Document.bin.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\package.zip | compressed | |
MD5:1745EF3FCAC773919BB858FB22C341AB | SHA256:C5C049E25F9A6F811C791B92EFCB411B3BD8B598938C2429C84A3F8A543F1138 | |||
| 1248 | agent.tmp | C:\Program Files\Advanced Monitoring Agent\is-A4O4O.tmp | executable | |
MD5:D7C918793B7F6EBFB34D34FCBF0A8749 | SHA256:9C2F4F7BDAB3FFD39EFAF9DD904CF031A38E1253B6645A61A2FA8364E0808299 | |||
| 1248 | agent.tmp | C:\Program Files\Advanced Monitoring Agent\4.lng | text | |
MD5:AE2624E65E959A3CC5BFD1C90F85231F | SHA256:999EB14EABFBDAF625E5BBCC5237318B2DB016CDDCFB3827E3A262064589666C | |||
| 1248 | agent.tmp | C:\Program Files\Advanced Monitoring Agent\is-A5FJC.tmp | text | |
MD5:E4361DEF38811D2F295B5686BD2C2B5B | SHA256:0E5882114864D4A708B472D524063867FA770958B770B67FC0AF7F8ED4757AD2 | |||
| 1248 | agent.tmp | C:\Program Files\Advanced Monitoring Agent\is-NJSJQ.tmp | text | |
MD5:94566142FEDCB1289CCD8E5D67D36EC5 | SHA256:8922C25B3A4D394F4AF801F469493D8B0941C6ED03D31C00A616E53D930D8934 | |||
| 1248 | agent.tmp | C:\Program Files\Advanced Monitoring Agent\2.lng | text | |
MD5:94566142FEDCB1289CCD8E5D67D36EC5 | SHA256:8922C25B3A4D394F4AF801F469493D8B0941C6ED03D31C00A616E53D930D8934 | |||
| 1248 | agent.tmp | C:\Program Files\Advanced Monitoring Agent\is-0GSAA.tmp | text | |
MD5:25ACC83AC6AEEBFE0BC6BDB16BD18654 | SHA256:3A21D91CB744AE5A380194E63F2B31A659867DF8927B9023526C3AB865E62848 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2544 | winagent.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?063373823eb16189 | unknown | compressed | 61.6 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2544 | winagent.exe | 104.18.35.154:443 | upload1europe1.systemmonitor.eu.com | CLOUDFLARENET | — | shared |
2544 | winagent.exe | 209.197.3.8:80 | ctldl.windowsupdate.com | STACKPATH-CDN | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
upload1europe1.systemmonitor.eu.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
upload2europe1.systemmonitor.eu.com |
| unknown |
upload3europe1.systemmonitor.eu.com |
| unknown |