File name:

dwagent.exe

Full analysis: https://app.any.run/tasks/fa25350b-92a1-4608-8f4e-f287606d02cd
Verdict: Malicious activity
Analysis date: April 18, 2024, 07:59:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5:

C5DD9F933FA61419E0A528A47E518FF6

SHA1:

C3C03874588D19DF4A1652B829DC82B088B69BBA

SHA256:

FB6058303A2C97F2ED84F44436EFBD94DF29B1F3B61D639C93EC0B005ED675E8

SSDEEP:

98304:9eMy73Lk8qAGAOtIkk3J1QROt8HbsNl6JuqS4dA0e827ZbFPI6XyR3gRH1QDPIj1:N42fcWxDCnV9PQ78S5wPsq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1028)
    • Changes the autorun value in the registry

      • dwagsvc.exe (PID: 2056)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1028)
    • Process drops python dynamic module

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1028)
    • The process drops C-runtime libraries

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1028)
    • Process drops legitimate windows executable

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1028)
    • Reads the Internet Settings

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 3472)
      • dwaglnc.exe (PID: 1020)
    • Reads security settings of Internet Explorer

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 3472)
      • dwaglnc.exe (PID: 1020)
    • Application launched itself

      • dwagent.exe (PID: 1196)
    • Starts CMD.EXE for commands execution

      • dwagent.exe (PID: 1028)
    • Executes as Windows Service

      • dwagsvc.exe (PID: 3576)
    • Creates a software uninstall entry

      • dwagsvc.exe (PID: 1784)
  • INFO

    • Checks supported languages

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1316)
      • dwagsvc.exe (PID: 3844)
      • dwagsvc.exe (PID: 2072)
      • dwagsvc.exe (PID: 2780)
      • dwagsvc.exe (PID: 3576)
      • dwagent.exe (PID: 2260)
      • dwagsvc.exe (PID: 3652)
      • dwaglnc.exe (PID: 1020)
      • dwagsvc.exe (PID: 3984)
      • dwagsvc.exe (PID: 2056)
      • dwagsvc.exe (PID: 2040)
      • dwagsvc.exe (PID: 1784)
      • dwagent.exe (PID: 3772)
      • dwagent.exe (PID: 1028)
      • dwagent.exe (PID: 3472)
    • Create files in a temporary directory

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1316)
      • dwagent.exe (PID: 1028)
    • Reads the computer name

      • dwagent.exe (PID: 1196)
      • dwagent.exe (PID: 1316)
      • dwagent.exe (PID: 3472)
      • dwagent.exe (PID: 1028)
      • dwagsvc.exe (PID: 3844)
      • dwagsvc.exe (PID: 2072)
      • dwagsvc.exe (PID: 3984)
      • dwagsvc.exe (PID: 3576)
      • dwagent.exe (PID: 2260)
      • dwagsvc.exe (PID: 3652)
      • dwagsvc.exe (PID: 2780)
      • dwagsvc.exe (PID: 1784)
      • dwagsvc.exe (PID: 2040)
      • dwagent.exe (PID: 3772)
      • dwaglnc.exe (PID: 1020)
    • Reads the machine GUID from the registry

      • dwagent.exe (PID: 1316)
      • dwagent.exe (PID: 1028)
      • dwagent.exe (PID: 2260)
      • dwagent.exe (PID: 3772)
    • Creates files in the program directory

      • dwagent.exe (PID: 1028)
      • dwagent.exe (PID: 2260)
      • dwagsvc.exe (PID: 3576)
      • dwagent.exe (PID: 3772)
      • dwagsvc.exe (PID: 1784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.1)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:11:18 12:45:44+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, No debug
PEType: PE32
LinkerVersion: 2.3
CodeSize: 291328
InitializedDataSize: 355328
UninitializedDataSize: 26624
EntryPoint: 0x1490
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
70
Monitored processes
25
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start dwagent.exe dwagent.exe no specs dwagent.exe dwagent.exe cmd.exe no specs dwagsvc.exe no specs cmd.exe no specs dwagsvc.exe no specs cmd.exe no specs dwagsvc.exe no specs cmd.exe no specs dwagsvc.exe no specs dwagsvc.exe no specs dwagent.exe no specs cmd.exe no specs dwagsvc.exe no specs cmd.exe no specs dwagsvc.exe cmd.exe no specs dwaglnc.exe no specs dwagent.exe no specs cmd.exe no specs dwagsvc.exe no specs cmd.exe no specs dwagsvc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
572C:\Windows\system32\cmd.exe /c ""C:\Program Files\DWAgent\native\dwagsvc.exe" deleteService"C:\Windows\System32\cmd.exedwagent.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1020"C:\Program Files\DWAgent\native\dwaglnc.exe" systrayC:\Program Files\DWAgent\native\dwaglnc.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\dwagent\native\dwaglnc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1028"C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtime\dwagent.exe" -S -m installer gotoopt=installC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtime\dwagent.exe
dwagent.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dwagent20240418080004\runtime\dwagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\dwagent20240418080004\runtime\python27.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1112C:\Windows\system32\cmd.exe /c ""C:\Program Files\DWAgent\native\dwagsvc.exe" installService"C:\Windows\System32\cmd.exedwagent.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1196"C:\Users\admin\AppData\Local\Temp\dwagent.exe" C:\Users\admin\AppData\Local\Temp\dwagent.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dwagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1316"C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtime\dwagent.exe" -S -m installerC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtime\dwagent.exedwagent.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dwagent20240418080004\runtime\dwagent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\dwagent20240418080004\runtime\python27.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1784"C:\Program Files\DWAgent\native\dwagsvc.exe" installShortcutsC:\Program Files\DWAgent\native\dwagsvc.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\dwagent\native\dwagsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2040"C:\Program Files\DWAgent\native\dwagsvc.exe" removeShortcutsC:\Program Files\DWAgent\native\dwagsvc.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\dwagent\native\dwagsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2056"C:\Program Files\DWAgent\native\dwagsvc.exe" installAutoRunC:\Program Files\DWAgent\native\dwagsvc.exe
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\dwagent\native\dwagsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2072"C:\Program Files\DWAgent\native\dwagsvc.exe" deleteServiceC:\Program Files\DWAgent\native\dwagsvc.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\dwagent\native\dwagsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
Total events
8 736
Read events
8 706
Write events
29
Delete events
1

Modification events

(PID) Process:(1196) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1196) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1196) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1196) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3472) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3472) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3472) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3472) dwagent.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3652) dwagsvc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:DWAgentMon
Value:
(PID) Process:(2056) dwagsvc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:DWAgentMon
Value:
"C:\Program Files\DWAgent\native\dwaglnc.exe" systray
Executable files
68
Suspicious files
574
Text files
148
Unknown types
477

Dropped files

PID
Process
Filename
Type
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\win.7z
MD5:
SHA256:
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtimepy3.7z
MD5:
SHA256:
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtimepy2.7z
MD5:
SHA256:
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\cacerts.pemtext
MD5:32251E46C3292406BDEA9D87C337C7D1
SHA256:6E29902102C4FF469B6B2F687FCABCE5D6982ECDAB9AD46EA91D6E67E8446A81
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\detectinfo.pytext
MD5:401F48BE24D349632A2438B5EC3B606E
SHA256:184A44033F071547A6077630458303A2729784AB10208ECC95F6F7F59906835F
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\ipc.pytext
MD5:C5D804450DEA060F85CC586990F70AC3
SHA256:7F5BC8D46F41A874AE5D4975DDC732482413020D498E80AE5465AC4B1C8806AE
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\communication.pytext
MD5:ACCA5D712EE28A5677AB6E3C85590D03
SHA256:4CDC84CFBFA834C611F21A59D424D3019206A7D7CED6D845CDBDA5E0FFABF541
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\ui\gdi.pytext
MD5:332AC5D315D125781BF7AEF25397F252
SHA256:32CE7ABEC3A75A2F1D9C2B92E3FB139C8249AD91DF04CB0F5632C16C85C74748
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\LICENSES\coretext
MD5:CFD7D66D2864C38232EC1EF20B27C13A
SHA256:CDE215E5B42363EB28CA2462C4558FF4807B38F383C537624C31E44657AC58F4
1196dwagent.exeC:\Users\admin\AppData\Local\Temp\dwagent20240418080004\ui\configure.pytext
MD5:90F22428154CC23008B41A4B890D3205
SHA256:241FB7D6890249AB1440AFAD75775723249DA6C597802361C3BF6510765625B4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
12
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1028
dwagent.exe
74.208.130.208:443
www.dwservice.net
IONOS SE
US
unknown

DNS requests

Domain
IP
Reputation
www.dwservice.net
  • 74.208.130.208
  • 116.203.208.186
unknown

Threats

No threats detected
No debug info