File name:

Agent.exe

Full analysis: https://app.any.run/tasks/5fece2be-e7dc-4315-85d2-8573aa42a4b5
Verdict: Malicious activity
Analysis date: September 26, 2023, 02:57:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

FC393356229572AC20CEAC5BB528D0AD

SHA1:

929C87AF5F743370189F7C18EB6316D4C6141908

SHA256:

CEFE71F6747E64CC28152FC1F76C5AFE70F74C00C661BFCE09EB389DFD1FC4F1

SSDEEP:

49152:IsO6VN9RSKuz61bSfwKp/W7brm5OD2kJBpANCDjBTxwR6KK4CHx/hfVkouLwdBF9:IsDbrh1+fwKkEq2kNhZ3hfeoZe0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • Agent.exe (PID: 1680)
    • Executes as Windows Service

      • Agent.exe (PID: 2104)
  • INFO

    • Reads the machine GUID from the registry

      • Agent.exe (PID: 1680)
      • Agent.exe (PID: 2104)
    • Checks supported languages

      • Agent.exe (PID: 1680)
      • Agent.exe (PID: 2104)
    • Reads the computer name

      • Agent.exe (PID: 1680)
      • Agent.exe (PID: 2104)
    • Reads Environment values

      • Agent.exe (PID: 1680)
      • Agent.exe (PID: 2104)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (41)
.exe | Win64 Executable (generic) (36.3)
.dll | Win32 Dynamic Link Library (generic) (8.6)
.exe | Win32 Executable (generic) (5.9)
.exe | Win16/32 Executable Delphi generic (2.7)

EXIF

EXE

AssemblyVersion: 7.5.0.37231
ProductVersion: 7.5.0.37231
ProductName:
OriginalFileName: Agent.exe .exe
LegalTrademarks:
LegalCopyright:
InternalName: Agent.exe .exe
FileVersion: 7.5.0.37231
FileDescription:
CompanyName:
Comments:
CharacterSet: Unicode
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 7.5.0.37231
FileVersionNumber: 7.5.0.37231
Subsystem: Windows command line
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x66000a
UninitializedDataSize: -
InitializedDataSize: 1808384
CodeSize: 4862976
LinkerVersion: 8
PEType: PE32
ImageFileCharacteristics: Executable, 32-bit
TimeStamp: 2023:09:07 12:06:15+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start agent.exe agent.exe agent.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1680"C:\Agent.exe" C:\Agent.exe
explorer.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
7.5.0.37231
Modules
Images
c:\agent.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2104C:\Agent.exe --windows-service TrueC:\Agent.exe
services.exe
User:
SYSTEM
Company:
Integrity Level:
SYSTEM
Description:
Exit code:
0
Version:
7.5.0.37231
Modules
Images
c:\agent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2968"C:\Agent.exe" C:\Agent.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Exit code:
3221226540
Version:
7.5.0.37231
Modules
Images
c:\agent.exe
c:\windows\system32\ntdll.dll
Total events
1 096
Read events
1 096
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
13
DNS requests
5
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1680
Agent.exe
142.250.186.174:443
www.google-analytics.com
GOOGLE
US
whitelisted
2104
Agent.exe
142.250.186.174:443
www.google-analytics.com
GOOGLE
US
whitelisted
2104
Agent.exe
98.124.96.160:443
HOMESC
US
unknown
2104
Agent.exe
142.251.141.40:443
ssl.google-analytics.com
GOOGLE
US
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2104
Agent.exe
142.250.186.142:443
www.google-analytics.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 142.250.186.174
  • 142.250.186.142
whitelisted
ssl.google-analytics.com
  • 142.251.141.40
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info