Malicious
Classifications
Spyware
Threat Names
Mal/Generic-S AgentTesla.v4 AgentTesla
Dynamic Analysis Report
Created on 2024-02-12T12:53:37+00:00
Ynstr.exe
Windows Exe (x86-32)
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "4 minutes, 59 seconds" to "10 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\Ynstr.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004B4C4E |
Size Of Code | 0x000B2E00 |
Size Of Initialized Data | 0x00000800 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2024-02-12 11:23 (UTC+1) |
Version Information (11)
»
Comments | - |
CompanyName | - |
FileDescription | - |
FileVersion | 1.0.0.0 |
InternalName | Ynstr.exe |
LegalCopyright | - |
LegalTrademarks | - |
OriginalFilename | Ynstr.exe |
ProductName | - |
ProductVersion | 1.0.0.0 |
Assembly Version | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00402000 | 0x000B2C64 | 0x000B2E00 | 0x00000200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.64 |
.rsrc | 0x004B6000 | 0x00000556 | 0x00000600 | 0x000B3000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.91 |
.reloc | 0x004B8000 | 0x0000000C | 0x00000200 | 0x000B3600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | - | 0x004B4C5C | 0x000B4C28 | 0x000B2E28 | 0x00000000 |
Memory Dumps (47)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
ynstr.exe | 1 | 0x00B80000 | 0x00C39FFF | Relevant Image | 32-bit | - |
...
|
||
buffer | 1 | 0x04750000 | 0x04801FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x04840000 | 0x04840FFF | First Execution | 32-bit | 0x04840000 |
...
|
||
clrjit.dll | 1 | 0x6DCE0000 | 0x6DD5FFFF | First Execution | 32-bit | 0x6DD41D21 |
...
|
||
buffer | 1 | 0x04890000 | 0x048CDFFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x04B30000 | 0x04B75FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x04890000 | 0x048CDFFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
ynstr.exe | 1 | 0x00B80000 | 0x00C39FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00400000 | 0x00441FFF | Content Changed | 32-bit | - |
...
|
||
ynstr.exe | 2 | 0x00CC0000 | 0x00D79FFF | Relevant Image | 32-bit | - |
...
|
||
ynstr.exe | 1 | 0x00B80000 | 0x00C39FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x04F9E000 | 0x04F9FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x04B9C000 | 0x04B9FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00BCE000 | 0x00BCFFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00189000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00400000 | 0x00441FFF | First Network Behavior | 32-bit | - |
...
|
||
ynstr.exe | 2 | 0x00CC0000 | 0x00D79FFF | First Network Behavior | 32-bit | - |
...
|
||
mtwbsyxsy.exe | 6 | 0x00DE0000 | 0x00E99FFF | Relevant Image | 32-bit | - |
...
|
||
sbrfm.exe | 7 | 0x00250000 | 0x00309FFF | Relevant Image | 32-bit | - |
...
|
||
buffer | 6 | 0x049E0000 | 0x04A91FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 7 | 0x04780000 | 0x04831FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 7 | 0x04870000 | 0x04870FFF | First Execution | 32-bit | 0x04870000 |
...
|
||
buffer | 6 | 0x02680000 | 0x02680FFF | First Execution | 32-bit | 0x02680000 |
...
|
||
clrjit.dll | 7 | 0x72E70000 | 0x72EEFFFF | First Execution | 32-bit | 0x72ED6C02 |
...
|
||
clrjit.dll | 6 | 0x72E70000 | 0x72EEFFFF | First Execution | 32-bit | 0x72EC2A1E |
...
|
||
buffer | 6 | 0x04AE0000 | 0x04B1DFFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 6 | 0x04DD0000 | 0x04E15FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 7 | 0x048C0000 | 0x048FDFFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 7 | 0x04B60000 | 0x04BA5FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 8 | 0x00400000 | 0x00441FFF | Content Changed | 32-bit | - |
...
|
||
mtwbsyxsy.exe | 8 | 0x00790000 | 0x00849FFF | Relevant Image | 32-bit | - |
...
|
||
buffer | 9 | 0x00400000 | 0x00441FFF | Content Changed | 32-bit | - |
...
|
||
sbrfm.exe | 9 | 0x00FC0000 | 0x01079FFF | Relevant Image | 32-bit | - |
...
|
||
mtwbsyxsy.exe | 6 | 0x00DE0000 | 0x00E99FFF | Process Termination | 32-bit | - |
...
|
||
sbrfm.exe | 7 | 0x00250000 | 0x00309FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 9 | 0x04EFD000 | 0x04EFFFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 9 | 0x00E2C000 | 0x00E2FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 9 | 0x00BEE000 | 0x00BEFFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 9 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 9 | 0x00400000 | 0x00441FFF | First Network Behavior | 32-bit | - |
...
|
||
sbrfm.exe | 9 | 0x00FC0000 | 0x01079FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 8 | 0x04E4E000 | 0x04E4FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 8 | 0x0493C000 | 0x0493FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 8 | 0x043AE000 | 0x043AFFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 8 | 0x00189000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 8 | 0x00400000 | 0x00441FFF | First Network Behavior | 32-bit | - |
...
|
||
mtwbsyxsy.exe | 8 | 0x00790000 | 0x00849FFF | First Network Behavior | 32-bit | - |
...
|
1a95ef6e164b7b75a798264283d1207315732bb7b02cc56c4a6c95d51da6b8ca | Downloaded File | Text |
Clean
|
...
|
»