File name:

SecuriteInfo.com.Win32.PWSX-gen.1520.18940

Full analysis: https://app.any.run/tasks/b4abded6-b117-4ac8-a1ed-439807c09ed5
Verdict: Malicious activity
Threats:

Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.

Analysis date: December 06, 2022, 03:36:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
rat
agenttesla
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

E666703D6C7B837F913C6ED5EAB6B1C0

SHA1:

D7B50F4057A56FC66F8E84A857FF59657ADD1929

SHA256:

A88EE1A9027BE5F82DF034C1367C54C7B3D925EB17802A77BADFE8423FC54F83

SSDEEP:

12288:fckVTTbvAFniZJ2pys3SniLMe9scSgxxHgB3ZG+11rjmahgKZ/nXt7virmWhlGLB:U2IG2pysVCcSyxHgBpG+1n

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe (PID: 3440)
    • AGENTTESLA detected by memory dumps

      • SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe (PID: 3440)
    • AGENTTESLA was detected

      • SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe (PID: 3440)
  • SUSPICIOUS

    • Application launched itself

      • SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe (PID: 2616)
    • Reads browser cookies

      • SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe (PID: 3440)
  • INFO

    • Checks supported languages

      • SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe (PID: 2616)
      • SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe (PID: 3440)
    • Reads the computer name

      • SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe (PID: 2616)
      • SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe (PID: 3440)
    • Reads Environment values

      • SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe (PID: 3440)
    • Process looks inside Credentials folder

      • SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe (PID: 3440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 2057-Oct-05 06:36:27
Comments: -
CompanyName: Microsoft
FileDescription: CadMotorista
FileVersion: 1.0.0.0
InternalName: EEUi.exe
LegalCopyright: Copyright © 2020
LegalTrademarks: -
OriginalFilename: EEUi.exe
ProductName: CadMotorista
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

DOS Header

e_magic: MZ
e_cblp: 144
e_cp: 3
e_crlc: -
e_cparhdr: 4
e_minalloc: -
e_maxalloc: 65535
e_ss: -
e_sp: 184
e_csum: -
e_ip: -
e_cs: -
e_ovno: -
e_oemid: -
e_oeminfo: -
e_lfanew: 128

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 3
TimeDateStamp: 2057-Oct-05 06:36:27
PointerToSymbolTable: -
NumberOfSymbols: -
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
8192
855076
855552
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
7.40769
.rsrc
868352
904
1024
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
2.85929
.reloc
876544
12
512
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
0.0980042

Resources

Title
Entropy
Size
Codepage
Language
Type
1
3.27483
812
UNKNOWN
UNKNOWN
RT_VERSION

Imports

mscoree.dll
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start securiteinfo.com.win32.pwsx-gen.1520.18940.exe no specs #AGENTTESLA securiteinfo.com.win32.pwsx-gen.1520.18940.exe

Process information

PID
CMD
Path
Indicators
Parent process
2616"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe" C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exeExplorer.EXE
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
CadMotorista
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\securiteinfo.com.win32.pwsx-gen.1520.18940.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3440"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe
SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
CadMotorista
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\securiteinfo.com.win32.pwsx-gen.1520.18940.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
Total events
587
Read events
587
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
0
Unknown types
2

Dropped files

PID
Process
Filename
Type
3440SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exeC:\Users\admin\AppData\Local\Temp\tmpG473.tmpexecutable
MD5:E666703D6C7B837F913C6ED5EAB6B1C0
SHA256:A88EE1A9027BE5F82DF034C1367C54C7B3D925EB17802A77BADFE8423FC54F83
3440SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exeC:\Users\admin\AppData\Roaming\lf3qft54.mh1\Firefox\Profiles\qldyz51w.default\cookies.sqlitesqlite
MD5:23D08A78BC908C0B29E9800D3D5614E7
SHA256:F6BD7DF5DFAE9FD88811A807DBA14085E00C1B5A6D7CC3D06CC68F6015363D59
3440SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exeC:\Users\admin\AppData\Roaming\lf3qft54.mh1\Chrome\Default\Cookiessqlite
MD5:B8E63E7225C9F4E0A81371F29D6456D8
SHA256:35A6919CE60EA8E0A44934F8B267BDE2C5A063C2E32F22D34724F168C43150C8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3440
SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe
198.54.120.122:587
smtp.fixtech.gq
NAMECHEAP-NET
US
malicious

DNS requests

Domain
IP
Reputation
smtp.fixtech.gq
  • 198.54.120.122
malicious

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET INFO DNS Query for Suspicious .gq Domain
3440
SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe
Generic Protocol Command Decode
SURICATA Applayer Detect protocol only one direction
3440
SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe
Generic Protocol Command Decode
SURICATA Applayer Detect protocol only one direction
3440
SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe
A Network Trojan was detected
ET TROJAN AgentTesla Exfil Via SMTP
3440
SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe
A Network Trojan was detected
AV TROJAN Win.Keylogger.AgentTesla SMTP Activity
3440
SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe
A Network Trojan was detected
ET TROJAN AgentTesla Exfil Via SMTP
3440
SecuriteInfo.com.Win32.PWSX-gen.1520.18940.exe
A Network Trojan was detected
AV TROJAN Win.Keylogger.AgentTesla SMTP Activity
4 ETPRO signatures available at the full report
No debug info