File name:

dwagent.exe

Full analysis: https://app.any.run/tasks/fa25350b-92a1-4608-8f4e-f287606d02cd
Verdict: Malicious activity
Analysis date: April 18, 2024, 07:59:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5:

C5DD9F933FA61419E0A528A47E518FF6

SHA1:

C3C03874588D19DF4A1652B829DC82B088B69BBA

SHA256:

FB6058303A2C97F2ED84F44436EFBD94DF29B1F3B61D639C93EC0B005ED675E8

SSDEEP:

98304:9eMy73Lk8qAGAOtIkk3J1QROt8HbsNl6JuqS4dA0e827ZbFPI6XyR3gRH1QDPIj1:N42fcWxDCnV9PQ78S5wPsq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1028)
    • Changes the autorun value in the registry

      • dwagsvc.exe (PID: 2056)
  • SUSPICIOUS

    • Process drops python dynamic module

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1028)
    • Process drops legitimate windows executable

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1028)
    • Executable content was dropped or overwritten

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1028)
    • Reads the Internet Settings

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 3472)
      • dwaglnc.exe (PID: 1020)
    • Reads security settings of Internet Explorer

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 3472)
      • dwaglnc.exe (PID: 1020)
    • The process drops C-runtime libraries

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1028)
    • Application launched itself

      • dwagent.exe (PID: 1196)
    • Starts CMD.EXE for commands execution

      • dwagent.exe (PID: 1028)
    • Executes as Windows Service

      • dwagsvc.exe (PID: 3576)
    • Creates a software uninstall entry

      • dwagsvc.exe (PID: 1784)
  • INFO

    • Checks supported languages

      • dwagent.exe (PID: 1316)
      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 3472)
      • dwagent.exe (PID: 1028)
      • dwagsvc.exe (PID: 3844)
      • dwagsvc.exe (PID: 2780)
      • dwagsvc.exe (PID: 3984)
      • dwagsvc.exe (PID: 2072)
      • dwagsvc.exe (PID: 2056)
      • dwagsvc.exe (PID: 3652)
      • dwagsvc.exe (PID: 2040)
      • dwaglnc.exe (PID: 1020)
      • dwagent.exe (PID: 3772)
      • dwagsvc.exe (PID: 1784)
      • dwagsvc.exe (PID: 3576)
      • dwagent.exe (PID: 2260)
    • Reads the computer name

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1316)
      • dwagent.exe (PID: 3472)
      • dwagent.exe (PID: 1028)
      • dwagsvc.exe (PID: 2072)
      • dwagsvc.exe (PID: 3844)
      • dwagsvc.exe (PID: 2780)
      • dwagsvc.exe (PID: 3984)
      • dwagsvc.exe (PID: 3576)
      • dwaglnc.exe (PID: 1020)
      • dwagent.exe (PID: 2260)
      • dwagsvc.exe (PID: 3652)
      • dwagsvc.exe (PID: 2040)
      • dwagsvc.exe (PID: 1784)
      • dwagent.exe (PID: 3772)
    • Create files in a temporary directory

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1316)
      • dwagent.exe (PID: 1028)
    • Reads the machine GUID from the registry

      • dwagent.exe (PID: 1316)
      • dwagent.exe (PID: 1028)
      • dwagent.exe (PID: 2260)
      • dwagent.exe (PID: 3772)
    • Creates files in the program directory

      • dwagent.exe (PID: 1028)
      • dwagsvc.exe (PID: 3576)
      • dwagent.exe (PID: 2260)
      • dwagent.exe (PID: 3772)
      • dwagsvc.exe (PID: 1784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.1)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:11:18 12:45:44+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, No debug
PEType: PE32
LinkerVersion: 2.3
CodeSize: 291328
InitializedDataSize: 355328
UninitializedDataSize: 26624
EntryPoint: 0x1490
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
70
Monitored processes
25
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start dwagent.exe dwagent.exe no specs dwagent.exe dwagent.exe cmd.exe no specs dwagsvc.exe no specs cmd.exe no specs dwagsvc.exe no specs cmd.exe no specs dwagsvc.exe no specs cmd.exe no specs dwagsvc.exe no specs dwagsvc.exe no specs dwagent.exe no specs cmd.exe no specs dwagsvc.exe no specs cmd.exe no specs dwagsvc.exe cmd.exe no specs dwaglnc.exe no specs dwagent.exe no specs cmd.exe no specs dwagsvc.exe no specs cmd.exe no specs dwagsvc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
572C:\Windows\system32\cmd.exe /c ""C:\Program Files\DWAgent\native\dwagsvc.exe" deleteService"C:\Windows\System32\cmd.exedwagent.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1020"C:\Program Files\DWAgent\native\dwaglnc.exe" systrayC:\Program Files\DWAgent\native\dwaglnc.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\dwagent\native\dwaglnc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1028"C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtime\dwagent.exe" -S -m installer gotoopt=installC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtime\dwagent.exe
dwagent.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dwagent20240418080004\runtime\dwagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\dwagent20240418080004\runtime\python27.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1112C:\Windows\system32\cmd.exe /c ""C:\Program Files\DWAgent\native\dwagsvc.exe" installService"C:\Windows\System32\cmd.exedwagent.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1196"C:\Users\admin\AppData\Local\Temp\dwagent.exe" C:\Users\admin\AppData\Local\Temp\dwagent.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dwagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1316"C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtime\dwagent.exe" -S -m installerC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtime\dwagent.exedwagent.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dwagent20240418080004\runtime\dwagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\dwagent20240418080004\runtime\python27.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1784"C:\Program Files\DWAgent\native\dwagsvc.exe" installShortcutsC:\Program Files\DWAgent\native\dwagsvc.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\dwagent\native\dwagsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2040"C:\Program Files\DWAgent\native\dwagsvc.exe" removeShortcutsC:\Program Files\DWAgent\native\dwagsvc.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\dwagent\native\dwagsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2056"C:\Program Files\DWAgent\native\dwagsvc.exe" installAutoRunC:\Program Files\DWAgent\native\dwagsvc.exe
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\dwagent\native\dwagsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2072"C:\Program Files\DWAgent\native\dwagsvc.exe" deleteServiceC:\Program Files\DWAgent\native\dwagsvc.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\dwagent\native\dwagsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
Total events
8 736
Read events
8 706
Write events
29
Delete events
1

Modification events

(PID) Process:(1196) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1196) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1196) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1196) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3472) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3472) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3472) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3472) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3652) dwagsvc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:DWAgentMon
Value:
(PID) Process:(2056) dwagsvc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:DWAgentMon
Value:
"C:\Program Files\DWAgent\native\dwaglnc.exe" systray
Executable files
68
Suspicious files
574
Text files
148
Unknown types
477

Dropped files

PID
Process
Filename
Type
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\win.7z
MD5:
SHA256:
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtimepy3.7z
MD5:
SHA256:
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtimepy2.7z
MD5:
SHA256:
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\LICENSES\coretext
MD5:CFD7D66D2864C38232EC1EF20B27C13A
SHA256:CDE215E5B42363EB28CA2462C4558FF4807B38F383C537624C31E44657AC58F4
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\ui\configure.pytext
MD5:90F22428154CC23008B41A4B890D3205
SHA256:241FB7D6890249AB1440AFAD75775723249DA6C597802361C3BF6510765625B4
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\ui\gdi.pytext
MD5:332AC5D315D125781BF7AEF25397F252
SHA256:32CE7ABEC3A75A2F1D9C2B92E3FB139C8249AD91DF04CB0F5632C16C85C74748
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\ui\images\activities_logo.bmpimage
MD5:C96F5BCF310AE61596F5571BF9EDC16F
SHA256:15B89F3DAB535AE859274864511ACEA1163A12C7AB1D6D7E9EB6008993AF31B3
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\ui\images\activities_screencapture.bmpimage
MD5:2888F93DB980597599915BC83163870A
SHA256:8CC3722C2757A435E7924DDF26E32D878CFBF1055B3F28B37C1C249D6F32AABB
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\native.pytext
MD5:CA4D0231BE63091F5BFA1E25B479C36E
SHA256:FFB87E22348273AA6C4B007837535FAB5AE0BE57AC202DA3752ADF1455F8F07A
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\resources.pytext
MD5:EFC381B9D9180DF5072CDC0EA6EE47EF
SHA256:EA61BC4453D02C8BD29921C329452038D253873EFD55A6A40C298B54680C813D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
12
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1028
dwagent.exe
74.208.130.208:443
www.dwservice.net
IONOS SE
US
unknown

DNS requests

Domain
IP
Reputation
www.dwservice.net
  • 74.208.130.208
  • 116.203.208.186
unknown

Threats

No threats detected
No debug info