| File name: | dwagent.exe |
| Full analysis: | https://app.any.run/tasks/fa25350b-92a1-4608-8f4e-f287606d02cd |
| Verdict: | Malicious activity |
| Analysis date: | April 18, 2024, 07:59:51 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5: | C5DD9F933FA61419E0A528A47E518FF6 |
| SHA1: | C3C03874588D19DF4A1652B829DC82B088B69BBA |
| SHA256: | FB6058303A2C97F2ED84F44436EFBD94DF29B1F3B61D639C93EC0B005ED675E8 |
| SSDEEP: | 98304:9eMy73Lk8qAGAOtIkk3J1QROt8HbsNl6JuqS4dA0e827ZbFPI6XyR3gRH1QDPIj1:N42fcWxDCnV9PQ78S5wPsq |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.1) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:11:18 12:45:44+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug |
| PEType: | PE32 |
| LinkerVersion: | 2.3 |
| CodeSize: | 291328 |
| InitializedDataSize: | 355328 |
| UninitializedDataSize: | 26624 |
| EntryPoint: | 0x1490 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 572 | C:\Windows\system32\cmd.exe /c ""C:\Program Files\DWAgent\native\dwagsvc.exe" deleteService" | C:\Windows\System32\cmd.exe | — | dwagent.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1020 | "C:\Program Files\DWAgent\native\dwaglnc.exe" systray | C:\Program Files\DWAgent\native\dwaglnc.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1028 | "C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtime\dwagent.exe" -S -m installer gotoopt=install | C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtime\dwagent.exe | dwagent.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1112 | C:\Windows\system32\cmd.exe /c ""C:\Program Files\DWAgent\native\dwagsvc.exe" installService" | C:\Windows\System32\cmd.exe | — | dwagent.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1196 | "C:\Users\admin\AppData\Local\Temp\dwagent.exe" | C:\Users\admin\AppData\Local\Temp\dwagent.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1316 | "C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtime\dwagent.exe" -S -m installer | C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtime\dwagent.exe | — | dwagent.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1784 | "C:\Program Files\DWAgent\native\dwagsvc.exe" installShortcuts | C:\Program Files\DWAgent\native\dwagsvc.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2040 | "C:\Program Files\DWAgent\native\dwagsvc.exe" removeShortcuts | C:\Program Files\DWAgent\native\dwagsvc.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2056 | "C:\Program Files\DWAgent\native\dwagsvc.exe" installAutoRun | C:\Program Files\DWAgent\native\dwagsvc.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2072 | "C:\Program Files\DWAgent\native\dwagsvc.exe" deleteService | C:\Program Files\DWAgent\native\dwagsvc.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (1196) dwagent.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1196) dwagent.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1196) dwagent.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1196) dwagent.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3472) dwagent.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3472) dwagent.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3472) dwagent.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3472) dwagent.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3652) dwagsvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | delete value | Name: | DWAgentMon |
Value: | |||
| (PID) Process: | (2056) dwagsvc.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | DWAgentMon |
Value: "C:\Program Files\DWAgent\native\dwaglnc.exe" systray | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1196 | dwagent.exe | C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\win.7z | — | |
MD5:— | SHA256:— | |||
| 1196 | dwagent.exe | C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtimepy3.7z | — | |
MD5:— | SHA256:— | |||
| 1196 | dwagent.exe | C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\runtimepy2.7z | — | |
MD5:— | SHA256:— | |||
| 1196 | dwagent.exe | C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\cacerts.pem | text | |
MD5:32251E46C3292406BDEA9D87C337C7D1 | SHA256:6E29902102C4FF469B6B2F687FCABCE5D6982ECDAB9AD46EA91D6E67E8446A81 | |||
| 1196 | dwagent.exe | C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\detectinfo.py | text | |
MD5:401F48BE24D349632A2438B5EC3B606E | SHA256:184A44033F071547A6077630458303A2729784AB10208ECC95F6F7F59906835F | |||
| 1196 | dwagent.exe | C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\ipc.py | text | |
MD5:C5D804450DEA060F85CC586990F70AC3 | SHA256:7F5BC8D46F41A874AE5D4975DDC732482413020D498E80AE5465AC4B1C8806AE | |||
| 1196 | dwagent.exe | C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\communication.py | text | |
MD5:ACCA5D712EE28A5677AB6E3C85590D03 | SHA256:4CDC84CFBFA834C611F21A59D424D3019206A7D7CED6D845CDBDA5E0FFABF541 | |||
| 1196 | dwagent.exe | C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\ui\gdi.py | text | |
MD5:332AC5D315D125781BF7AEF25397F252 | SHA256:32CE7ABEC3A75A2F1D9C2B92E3FB139C8249AD91DF04CB0F5632C16C85C74748 | |||
| 1196 | dwagent.exe | C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\LICENSES\core | text | |
MD5:CFD7D66D2864C38232EC1EF20B27C13A | SHA256:CDE215E5B42363EB28CA2462C4558FF4807B38F383C537624C31E44657AC58F4 | |||
| 1196 | dwagent.exe | C:\Users\admin\AppData\Local\Temp\dwagent20240418080004\ui\configure.py | text | |
MD5:90F22428154CC23008B41A4B890D3205 | SHA256:241FB7D6890249AB1440AFAD75775723249DA6C597802361C3BF6510765625B4 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1028 | dwagent.exe | 74.208.130.208:443 | www.dwservice.net | IONOS SE | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.dwservice.net |
| unknown |