File name:

Windows.Diagnostic.Document.bin

Full analysis: https://app.any.run/tasks/a2d0a86f-edf7-4374-aaf7-c4e5802b7776
Verdict: Malicious activity
Analysis date: November 01, 2023, 21:22:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

04AFFF1465A223A806774104B652A4F0

SHA1:

2F7056621E1A8ECB20A7639635D403E2C44E6135

SHA256:

9A785F508890D250AB9E3A43F974A89F3311EBD0E85EC98B46C76BDB7BEF7CFB

SSDEEP:

98304:/iTNTdVDCiTchi7n9w+94bwjIDWfP2pG3AwhOdzTF3bDc/D1pYtpKWbcI5D8wXu/:PS/88y4oeExU6pAYTsq6P66XfOTxhRU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Windows.Diagnostic.Document.bin.exe (PID: 1956)
      • agent.exe (PID: 3000)
      • agent.exe (PID: 1032)
      • agent.tmp (PID: 1248)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Windows.Diagnostic.Document.bin.exe (PID: 1956)
      • winagent.exe (PID: 2544)
      • HelpPane.exe (PID: 1368)
    • Process drops legitimate windows executable

      • agent.tmp (PID: 1248)
    • Reads the Windows owner or organization settings

      • agent.tmp (PID: 1248)
    • Reads settings of System Certificates

      • winagent.exe (PID: 2544)
    • Adds/modifies Windows certificates

      • agent.tmp (PID: 1248)
    • Reads Internet Explorer settings

      • HelpPane.exe (PID: 1368)
    • Searches for installed software

      • winagent.exe (PID: 2544)
    • Reads Microsoft Outlook installation path

      • HelpPane.exe (PID: 1368)
  • INFO

    • Create files in a temporary directory

      • Windows.Diagnostic.Document.bin.exe (PID: 1956)
      • agent.exe (PID: 3000)
      • agent.exe (PID: 1032)
      • agent.tmp (PID: 1248)
      • winagent.exe (PID: 2544)
    • Checks supported languages

      • Windows.Diagnostic.Document.bin.exe (PID: 1956)
      • agent.tmp (PID: 2112)
      • agent.exe (PID: 3000)
      • agent.exe (PID: 1032)
      • agent.tmp (PID: 1248)
      • unzip.exe (PID: 1688)
      • winagent.exe (PID: 2544)
      • unzip.exe (PID: 3028)
    • Reads the computer name

      • Windows.Diagnostic.Document.bin.exe (PID: 1956)
      • agent.tmp (PID: 2112)
      • agent.tmp (PID: 1248)
      • winagent.exe (PID: 2544)
    • Reads the machine GUID from the registry

      • winagent.exe (PID: 2544)
      • HelpPane.exe (PID: 1368)
    • Creates files in the program directory

      • unzip.exe (PID: 3028)
      • winagent.exe (PID: 2544)
      • agent.tmp (PID: 1248)
    • Reads product name

      • winagent.exe (PID: 2544)
    • Reads Environment values

      • winagent.exe (PID: 2544)
    • Checks proxy server information

      • HelpPane.exe (PID: 1368)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2007:07:22 04:33:09+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 74752
InitializedDataSize: 21504
UninitializedDataSize: -
EntryPoint: 0x11de6
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.2.0.715
ProductVersionNumber: 1.2.0.715
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: N-able Technologies
FileDescription: Advanced Monitoring Agent Setup
FileVersion: -
InternalName: -
OriginalFileName: -
ProductName: Advanced Monitoring Agent
ProductVersion: -
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
9
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start windows.diagnostic.document.bin.exe no specs agent.exe no specs agent.tmp no specs agent.exe agent.tmp no specs unzip.exe no specs unzip.exe no specs winagent.exe helppane.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1032"C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exe" /SPAWNWND=$F0196 /NOTIFYWND=$9035C /VERYSILENT /norestartC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exe
agent.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Advanced Monitoring Agent Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\7zipsfx.000\agent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1248"C:\Users\admin\AppData\Local\Temp\is-U5TNF.tmp\agent.tmp" /SL5="$C02D4,8488367,56832,C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exe" /SPAWNWND=$F0196 /NOTIFYWND=$9035C /VERYSILENT /norestartC:\Users\admin\AppData\Local\Temp\is-U5TNF.tmp\agent.tmpagent.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-u5tnf.tmp\agent.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1368C:\Windows\helppane.exe -EmbeddingC:\Windows\HelpPane.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Help and Support
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\helppane.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1688"C:\Program Files\Advanced Monitoring Agent\unzip.exe"C:\Program Files\Advanced Monitoring Agent\unzip.exeagent.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\program files\advanced monitoring agent\unzip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
1956"C:\Users\admin\AppData\Local\Temp\Windows.Diagnostic.Document.bin.exe" C:\Users\admin\AppData\Local\Temp\Windows.Diagnostic.Document.bin.exeexplorer.exe
User:
admin
Company:
N-able Technologies
Integrity Level:
MEDIUM
Description:
Advanced Monitoring Agent Setup
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\windows.diagnostic.document.bin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2112"C:\Users\admin\AppData\Local\Temp\is-OT4M2.tmp\agent.tmp" /SL5="$9035C,8488367,56832,C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exe" /VERYSILENT /norestartC:\Users\admin\AppData\Local\Temp\is-OT4M2.tmp\agent.tmpagent.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ot4m2.tmp\agent.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2544"C:\Program Files\Advanced Monitoring Agent\winagent.exe" /autoinstallC:\Program Files\Advanced Monitoring Agent\winagent.exe
agent.tmp
User:
admin
Company:
Remote Monitoring
Integrity Level:
HIGH
Description:
winagent
Exit code:
1
Version:
10.13.8
Modules
Images
c:\program files\advanced monitoring agent\winagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3000"C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exe" /VERYSILENT /norestartC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\agent.exeWindows.Diagnostic.Document.bin.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Advanced Monitoring Agent Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\7zipsfx.000\agent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3028"C:\Program Files\Advanced Monitoring Agent\unzip.exe" package.zipC:\Program Files\Advanced Monitoring Agent\unzip.exeagent.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\advanced monitoring agent\unzip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
Total events
8 786
Read events
8 742
Write events
38
Delete events
6

Modification events

(PID) Process:(1956) Windows.Diagnostic.Document.bin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1956) Windows.Diagnostic.Document.bin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1956) Windows.Diagnostic.Document.bin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1956) Windows.Diagnostic.Document.bin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1248) agent.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
4BDF579E69B39BB3576BB9772852C33D9AC8CDC97487BA1570E89BA22E06FC85
(PID) Process:(1248) agent.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\Advanced Monitoring Agent\assetscan.exe
(PID) Process:(1248) agent.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(1248) agent.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
3B5594105AEB39774E7A26EB006FE071B38885E3D4270EE641119ECB832B65CD
(PID) Process:(1248) agent.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
E0040000208BD389090DDA01
(PID) Process:(1248) agent.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
Executable files
43
Suspicious files
9
Text files
15
Unknown types
0

Dropped files

PID
Process
Filename
Type
1248agent.tmpC:\Program Files\Advanced Monitoring Agent\5.lngtext
MD5:1190EE81B83F5CEA64FD4942D76C03CF
SHA256:D5D7923A30EE8BA3071AD0D74359362F116C4D914E154103F27A909CF842CCA0
1032agent.exeC:\Users\admin\AppData\Local\Temp\is-U5TNF.tmp\agent.tmpexecutable
MD5:A2C4D52C66B4B399FACADB8CC8386745
SHA256:6C0465CE64C07E729C399A338705941D77727C7D089430957DF3E91A416E9D2A
1248agent.tmpC:\Program Files\Advanced Monitoring Agent\unins000.exeexecutable
MD5:D7C918793B7F6EBFB34D34FCBF0A8749
SHA256:9C2F4F7BDAB3FFD39EFAF9DD904CF031A38E1253B6645A61A2FA8364E0808299
1956Windows.Diagnostic.Document.bin.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\package.zipcompressed
MD5:1745EF3FCAC773919BB858FB22C341AB
SHA256:C5C049E25F9A6F811C791B92EFCB411B3BD8B598938C2429C84A3F8A543F1138
1248agent.tmpC:\Program Files\Advanced Monitoring Agent\is-A4O4O.tmpexecutable
MD5:D7C918793B7F6EBFB34D34FCBF0A8749
SHA256:9C2F4F7BDAB3FFD39EFAF9DD904CF031A38E1253B6645A61A2FA8364E0808299
1248agent.tmpC:\Program Files\Advanced Monitoring Agent\4.lngtext
MD5:AE2624E65E959A3CC5BFD1C90F85231F
SHA256:999EB14EABFBDAF625E5BBCC5237318B2DB016CDDCFB3827E3A262064589666C
1248agent.tmpC:\Program Files\Advanced Monitoring Agent\is-A5FJC.tmptext
MD5:E4361DEF38811D2F295B5686BD2C2B5B
SHA256:0E5882114864D4A708B472D524063867FA770958B770B67FC0AF7F8ED4757AD2
1248agent.tmpC:\Program Files\Advanced Monitoring Agent\is-NJSJQ.tmptext
MD5:94566142FEDCB1289CCD8E5D67D36EC5
SHA256:8922C25B3A4D394F4AF801F469493D8B0941C6ED03D31C00A616E53D930D8934
1248agent.tmpC:\Program Files\Advanced Monitoring Agent\2.lngtext
MD5:94566142FEDCB1289CCD8E5D67D36EC5
SHA256:8922C25B3A4D394F4AF801F469493D8B0941C6ED03D31C00A616E53D930D8934
1248agent.tmpC:\Program Files\Advanced Monitoring Agent\is-0GSAA.tmptext
MD5:25ACC83AC6AEEBFE0BC6BDB16BD18654
SHA256:3A21D91CB744AE5A380194E63F2B31A659867DF8927B9023526C3AB865E62848
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
8
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2544
winagent.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?063373823eb16189
unknown
compressed
61.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
2544
winagent.exe
104.18.35.154:443
upload1europe1.systemmonitor.eu.com
CLOUDFLARENET
shared
2544
winagent.exe
209.197.3.8:80
ctldl.windowsupdate.com
STACKPATH-CDN
US
whitelisted

DNS requests

Domain
IP
Reputation
upload1europe1.systemmonitor.eu.com
  • 104.18.35.154
  • 172.64.152.102
unknown
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
upload2europe1.systemmonitor.eu.com
  • 104.18.35.154
  • 172.64.152.102
unknown
upload3europe1.systemmonitor.eu.com
  • 104.18.35.154
  • 172.64.152.102
unknown

Threats

No threats detected
No debug info