Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
QualysCloudAgent (Windows).exe

Overview

General Information

Sample name:QualysCloudAgent (Windows).exe
Analysis ID:1562263
MD5:b7472d4e38a5d4f3a272568142e2e875
SHA1:a8a6f8b37e84c100aae35ee92fbe9a6911b507ef
SHA256:844593ab69ce5f479bf937471a385b1a966dcc7b3bfca44ffa9ccfe6420b259e
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

Creates files inside the system directory
Sample file is different than original file name gathered from version info
Uses 32bit PE files

Classification

  • System is w10x64
  • QualysCloudAgent (Windows).exe (PID: 7436 cmdline: "C:\Users\user\Desktop\QualysCloudAgent (Windows).exe" MD5: B7472D4E38A5D4F3A272568142E2E875)
    • conhost.exe (PID: 7444 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: QualysCloudAgent (Windows).exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: C:\Users\user\Desktop\QualysCloudAgent (Windows).exeFile created: C:\ProgramData\Qualys\QualysAgent\InstallerLogs\CloudAgentInstaller.logJump to behavior
Source: QualysCloudAgent (Windows).exeStatic PE information: certificate valid
Source: QualysCloudAgent (Windows).exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\jenkins_home\workspace\indows-4.5-non-Arxan_release_5.1\CloudAgentInstaller\x64\Release\QASetupHost.pdb source: QualysCloudAgent (Windows).exe
Source: Binary string: C:\jenkins_home\workspace\indows-4.5-non-Arxan_release_5.1\CloudAgentInstaller\Release\QASetupHost.pdb source: QualysCloudAgent (Windows).exe
Source: Binary string: C:\jenkins_home\workspace\indows-4.5-non-Arxan_release_5.1\CloudAgentInstaller\Release\CloudAgentInstaller.pdb source: QualysCloudAgent (Windows).exe
Source: Binary string: C:\agent\_work\9\s\build\ship\x86\wixca.pdb source: QualysCloudAgent (Windows).exe
Source: Binary string: C:\jenkins_home\workspace\indows-4.5-non-Arxan_release_5.1\CloudAgentInstaller\Win32\Release\QACustomAction.pdb source: QualysCloudAgent (Windows).exe
Source: Binary string: C:\jenkins_home\workspace\indows-4.5-non-Arxan_release_5.1\CloudAgentInstaller\x64\Release\QACustomAction.pdb source: QualysCloudAgent (Windows).exe
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0K
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://ocsp.digicert.com0
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://ocsp.digicert.com0A
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://ocsp.digicert.com0C
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://ocsp.digicert.com0I
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://ocsp.digicert.com0X
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://sv.symcb.com/sv.crl0W
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://sv.symcb.com/sv.crt0
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://sv.symcd.com0&
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://www.digicert.com/CPS0
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://www.qualys.com/company/contacts/ARPHELPTELEPHONE(650)
Source: QualysCloudAgent (Windows).exeString found in binary or memory: http://www.qualys.com0
Source: QualysCloudAgent (Windows).exeString found in binary or memory: https://d.symcb.com/cps0%
Source: QualysCloudAgent (Windows).exeString found in binary or memory: https://d.symcb.com/rpa0
Source: QualysCloudAgent (Windows).exeString found in binary or memory: https://www.digicert.com/CPS0
Source: C:\Users\user\Desktop\QualysCloudAgent (Windows).exeFile created: C:\Windows\Logs\QualysAgentJump to behavior
Source: QualysCloudAgent (Windows).exe, 00000000.00000002.1685306425.0000000000A8A000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameQACustomAction.dllH vs QualysCloudAgent (Windows).exe
Source: QualysCloudAgent (Windows).exe, 00000000.00000002.1685306425.0000000000A8A000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamewixca.dll8 vs QualysCloudAgent (Windows).exe
Source: QualysCloudAgent (Windows).exe, 00000000.00000002.1685306425.0000000000A8A000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameQASetupHost.exeH vs QualysCloudAgent (Windows).exe
Source: QualysCloudAgent (Windows).exe, 00000000.00000001.1682245534.0000000000A8A000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameQACustomAction.dllH vs QualysCloudAgent (Windows).exe
Source: QualysCloudAgent (Windows).exe, 00000000.00000001.1682245534.0000000000A8A000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamewixca.dll8 vs QualysCloudAgent (Windows).exe
Source: QualysCloudAgent (Windows).exeBinary or memory string: OriginalFilenameQACustomAction.dllH vs QualysCloudAgent (Windows).exe
Source: QualysCloudAgent (Windows).exeBinary or memory string: OriginalFilenamewixca.dll8 vs QualysCloudAgent (Windows).exe
Source: QualysCloudAgent (Windows).exeBinary or memory string: OriginalFilenameQASetupHost.exeH vs QualysCloudAgent (Windows).exe
Source: QualysCloudAgent (Windows).exeBinary or memory string: OriginalFilenameCloudAgentInstaller.exeH vs QualysCloudAgent (Windows).exe
Source: QualysCloudAgent (Windows).exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engineClassification label: clean1.winEXE@2/2@0/0
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7444:120:WilError_03
Source: C:\Users\user\Desktop\QualysCloudAgent (Windows).exeMutant created: \Sessions\1\BaseNamedObjects\Global\{3D594D93-D7F0-4C44-93AC-931752E27136}
Source: QualysCloudAgent (Windows).exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\QualysCloudAgent (Windows).exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: QualysCloudAgent (Windows).exe, 00000000.00000002.1685306425.0000000000A8A000.00000002.00000001.01000000.00000003.sdmp, QualysCloudAgent (Windows).exe, 00000000.00000000.1680701072.0000000000A2B000.00000002.00000001.01000000.00000003.sdmp, QualysCloudAgent (Windows).exe, 00000000.00000001.1682245534.0000000000A8A000.00000002.00000001.01000000.00000003.sdmp, QualysCloudAgent (Windows).exe, 00000000.00000002.1685146275.0000000000A2B000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: QualysCloudAgent (Windows).exe, 00000000.00000002.1685306425.0000000000A8A000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: SELECT EXISTS (SELECT 1 FROM sqlite_master WHERE type = 'table' AND name = '%s' LIMIT 1);END TRANSACTIONBEGIN TRANSACTIONINTEGERINTEGERGroupNameProcessIDManifestIDPrivilegeName@
Source: QualysCloudAgent (Windows).exe, 00000000.00000002.1685306425.0000000000A8A000.00000002.00000001.01000000.00000003.sdmp, QualysCloudAgent (Windows).exe, 00000000.00000001.1682245534.0000000000A8A000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: SELECT EXISTS (SELECT 1 FROM sqlite_master WHERE type = 'table' AND name = '%s' LIMIT 1);
Source: QualysCloudAgent (Windows).exe, 00000000.00000002.1685306425.0000000000A8A000.00000002.00000001.01000000.00000003.sdmp, QualysCloudAgent (Windows).exe, 00000000.00000000.1680701072.0000000000A2B000.00000002.00000001.01000000.00000003.sdmp, QualysCloudAgent (Windows).exe, 00000000.00000001.1682245534.0000000000A8A000.00000002.00000001.01000000.00000003.sdmp, QualysCloudAgent (Windows).exe, 00000000.00000002.1685146275.0000000000A2B000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
Source: QualysCloudAgent (Windows).exe, 00000000.00000002.1685306425.0000000000A8A000.00000002.00000001.01000000.00000003.sdmp, QualysCloudAgent (Windows).exe, 00000000.00000001.1682245534.0000000000A8A000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: SELECT EXISTS (SELECT 1 FROM sqlite_master WHERE type = 'table' AND name = '%s' LIMIT 1);END TRANSACTION83INTEGERSizeINTEGERProcessIDGroupNamePrivilegeNameManifestID(
Source: QualysCloudAgent (Windows).exeString found in binary or memory: MBad privilege name to AdjustWin32 Error: %u - Failed to open process-token for privilege changeWin32 Error: %u - Unable to lookup for "%s" privilegeWin32 Error: %u - Unable to adjust the privilege "%s"Privilege update result: %uBad privilege name to EnablePrivilege name insertion failed.map/set<T> too longinvalid string positionstring too longWin32 Error: %u - Failed to open SCMWin32 Error: %u - Failed to open service "%s"Win32 Error: %u - Failed to query service statusService [%s] is running.Service is stopped - issuing start commandWin32 Error: %u - Failed to start service %sService is paused - issuing continue commandWin32 Error: %u - Failed to Continue serviceService is running.Service is not running - pausing 1 second...Win32 Error: %u - Failed to gain ownership of file object "%s"Win32 Error: %u - Failed to set default group of file object "%s"Win32 Error: %u - Failed to set DACL of file object "%s"SeTakeOwnershipPrivilegeFailed to adjust privilegeSeRestorePrivilegeWin32 Error: %u - Failed to create DACLWin32 Error: %u - Failed to reset security on: "%s"enabledisableAdjusting privileges to %s for %s.Win32 Error: %u - Unable to adjust privilege "%s"QualysAgentWin32 Error: %u - Pre-Setup: Failed to open a handle to the SCMPre-Setup: Driver file name is invalid.%windir%\System32\drivers\Pre-Setup: Failed to build driver file path.Pre-Setup: Failed to expand driver file path.Win32 Error: %u - Pre-Setup: Failed to delete driver file %sPre-Setup: Driver name is invalid.Win32 Error: %u - Pre-Setup: Failed to get a handle to the driver "%s"Win32 Error: %u - Pre-Setup: Failed to query the status of the driver "%s": %sPre-Setup: Driver is in a transitionary state (%u) - waiting for %u millisecondsPre-Setup: Timed out waiting for the driver to reach a stable state.Pre-Setup: Handle for %s service does not existWin32 Error: %u - Pre-Setup: Failed to obtain handle to %s driverPre-Setup: The driver %s has already stopped.Win32 Error: %u - Pre-Setup: Failed to stop %s driverPre-Setup: The driver %s has been stopped.uninstall Pre-Setup: Driver installer path is invalid.Pre-Setup: Not enough memory while trying to create driver uninstallation commandWin32 Error: %u - Pre-Setup: Driver un-installation [%s] has failed. Installer output [%s]Win32 Error: %u - Pre-Setup: Driver un-installation [%s] has failed. Installer output [%s]. Installer exit code: %dPre-Setup: Driver uninstallation [%s] has completed. Driver installer output [%s]Pre-Setup: Failed to construct driver package pathWin32 Error: %u - Pre-Setup: Failed to get the parent directory path"" /Insufficient memory while trying to create driver installation/uninstallation commandWin32 Error: %u - Pre-Setup: Failed to remove driver service for %sPre-Setup: Driver service for %s does not existWin32 Error: %u - Pre-Setup: Failed to stop the %s driverWin32 Error: %u - Pre-Setup: Failed to delete %s driver serviceWin32 Error: %u - Pre-Setup: Failed to query the existence of the driver "%s"Win32 Error: %u -
Source: QualysCloudAgent (Windows).exeString found in binary or memory: Bad privilege name to AdjustWin32 Error: %u - Failed to open process-token for privilege changeWin32 Error: %u - Unable to lookup for "%s" privilegeWin32 Error: %u - Unable to adjust the privilege "%s"Privilege update result: %uBad privilege name to EnablePrivilege name insertion failed.map/set<T> too longinvalid string positionstring too longWin32 Error: %u - Failed to open SCMWin32 Error: %u - Failed to open service "%s"Win32 Error: %u - Failed to query service statusService [%s] is running.Service is stopped - issuing start commandWin32 Error: %u - Failed to start service %sService is paused - issuing continue commandWin32 Error: %u - Failed to Continue serviceService is running.Service is not running - pausing 1 second...Win32 Error: %u - Failed to gain ownership of file object "%s"Win32 Error: %u - Failed to set default group of file object "%s"Win32 Error: %u - Failed to set DACL of file object "%s"SeTakeOwnershipPrivilegeFailed to adjust privilegeSeRestorePrivilegeWin32 Error: %u - Failed to create DACLWin32 Error: %u - Failed to reset security on: "%s"enabledisableAdjusting privileges to %s for %s.Win32 Error: %u - Unable to adjust privilege "%s"QualysAgentWin32 Error: %u - Pre-Setup: Failed to open a handle to the SCMPre-Setup: Driver file name is invalid.%windir%\System32\drivers\Pre-Setup: Failed to build driver file path.Pre-Setup: Failed to expand driver file path.Win32 Error: %u - Pre-Setup: Failed to delete driver file %sPre-Setup: Driver name is invalid.Win32 Error: %u - Pre-Setup: Failed to get a handle to the driver "%s"Win32 Error: %u - Pre-Setup: Failed to query the status of the driver "%s": %sPre-Setup: Driver is in a transitionary state (%u) - waiting for %u millisecondsPre-Setup: Timed out waiting for the driver to reach a stable state.Pre-Setup: Handle for %s service does not existWin32 Error: %u - Pre-Setup: Failed to obtain handle to %s driverPre-Setup: The driver %s has already stopped.Win32 Error: %u - Pre-Setup: Failed to stop %s driverPre-Setup: The driver %s has been stopped.uninstall Pre-Setup: Driver installer path is invalid.Pre-Setup: Not enough memory while trying to create driver uninstallation commandWin32 Error: %u - Pre-Setup: Driver un-installation [%s] has failed. Installer output [%s]Win32 Error: %u - Pre-Setup: Driver un-installation [%s] has failed. Installer output [%s]. Installer exit code: %dPre-Setup: Driver uninstallation [%s] has completed. Driver installer output [%s]Pre-Setup: Failed to construct driver package pathWin32 Error: %u - Pre-Setup: Failed to get the parent directory path"" /Insufficient memory while trying to create driver installation/uninstallation commandWin32 Error: %u - Pre-Setup: Failed to remove driver service for %sPre-Setup: Driver service for %s does not existWin32 Error: %u - Pre-Setup: Failed to stop the %s driverWin32 Error: %u - Pre-Setup: Failed to delete %s driver serviceWin32 Error: %u - Pre-Setup: Failed to query the existence of the driver "%s"Win32 Error: %u - I
Source: unknownProcess created: C:\Users\user\Desktop\QualysCloudAgent (Windows).exe "C:\Users\user\Desktop\QualysCloudAgent (Windows).exe"
Source: C:\Users\user\Desktop\QualysCloudAgent (Windows).exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\QualysCloudAgent (Windows).exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\QualysCloudAgent (Windows).exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\QualysCloudAgent (Windows).exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\QualysCloudAgent (Windows).exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\QualysCloudAgent (Windows).exeSection loaded: kernel.appcore.dllJump to behavior
Source: QualysCloudAgent (Windows).exeStatic PE information: certificate valid
Source: QualysCloudAgent (Windows).exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: QualysCloudAgent (Windows).exeStatic file information: File size 19191616 > 1048576
Source: QualysCloudAgent (Windows).exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x13a000
Source: QualysCloudAgent (Windows).exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x10c4000
Source: QualysCloudAgent (Windows).exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: QualysCloudAgent (Windows).exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: QualysCloudAgent (Windows).exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: QualysCloudAgent (Windows).exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: QualysCloudAgent (Windows).exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: QualysCloudAgent (Windows).exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: QualysCloudAgent (Windows).exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: QualysCloudAgent (Windows).exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\jenkins_home\workspace\indows-4.5-non-Arxan_release_5.1\CloudAgentInstaller\x64\Release\QASetupHost.pdb source: QualysCloudAgent (Windows).exe
Source: Binary string: C:\jenkins_home\workspace\indows-4.5-non-Arxan_release_5.1\CloudAgentInstaller\Release\QASetupHost.pdb source: QualysCloudAgent (Windows).exe
Source: Binary string: C:\jenkins_home\workspace\indows-4.5-non-Arxan_release_5.1\CloudAgentInstaller\Release\CloudAgentInstaller.pdb source: QualysCloudAgent (Windows).exe
Source: Binary string: C:\agent\_work\9\s\build\ship\x86\wixca.pdb source: QualysCloudAgent (Windows).exe
Source: Binary string: C:\jenkins_home\workspace\indows-4.5-non-Arxan_release_5.1\CloudAgentInstaller\Win32\Release\QACustomAction.pdb source: QualysCloudAgent (Windows).exe
Source: Binary string: C:\jenkins_home\workspace\indows-4.5-non-Arxan_release_5.1\CloudAgentInstaller\x64\Release\QACustomAction.pdb source: QualysCloudAgent (Windows).exe
Source: QualysCloudAgent (Windows).exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: QualysCloudAgent (Windows).exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: QualysCloudAgent (Windows).exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: QualysCloudAgent (Windows).exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: QualysCloudAgent (Windows).exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\Desktop\QualysCloudAgent (Windows).exeFile created: C:\ProgramData\Qualys\QualysAgent\InstallerLogs\CloudAgentInstaller.logJump to behavior
Source: C:\Users\user\Desktop\QualysCloudAgent (Windows).exeCode function: 0_2_009E6B12 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_009E6B12
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Command and Scripting Interpreter
1
DLL Side-Loading
1
Process Injection
1
Masquerading
OS Credential Dumping1
System Time Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Process Injection
LSASS Memory2
System Information Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1562263 Sample: QualysCloudAgent (Windows).exe Startdate: 25/11/2024 Architecture: WINDOWS Score: 1 5 QualysCloudAgent (Windows).exe 10 2->5         started        process3 7 conhost.exe 5->7         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
QualysCloudAgent (Windows).exe0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://www.qualys.com00%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.qualys.com0QualysCloudAgent (Windows).exefalse
  • Avira URL Cloud: safe
unknown
http://www.qualys.com/company/contacts/ARPHELPTELEPHONE(650)QualysCloudAgent (Windows).exefalse
    high
    No contacted IP infos
    Joe Sandbox version:41.0.0 Charoite
    Analysis ID:1562263
    Start date and time:2024-11-25 12:27:43 +01:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 2m 38s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:2
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:QualysCloudAgent (Windows).exe
    Detection:CLEAN
    Classification:clean1.winEXE@2/2@0/0
    EGA Information:Failed
    HCA Information:Failed
    Cookbook Comments:
    • Found application associated with file extension: .exe
    • Stop behavior analysis, all processes terminated
    • Execution Graph export aborted for target QualysCloudAgent (Windows).exe, PID 7436 because there are no executed function
    • Not all processes where analyzed, report is missing behavior information
    • VT rate limit hit for: QualysCloudAgent (Windows).exe
    No simulations
    No context
    No context
    No context
    No context
    No context
    Process:C:\Users\user\Desktop\QualysCloudAgent (Windows).exe
    File Type:ASCII text, with CRLF line terminators
    Category:modified
    Size (bytes):1180
    Entropy (8bit):5.221123927436535
    Encrypted:false
    SSDEEP:24:jtb3nnlMoXDW/GQeQQQ7vPHTa9UY+JPZBFaOFq7Qf:jt3neoXDW/GQeQQQbPHG+UQf
    MD5:3AAF094EBE9ADEE7AD7EE7E2F9FD945F
    SHA1:528410E5C78B5C1CCEFC74E9B9C7C2B5F3ACA665
    SHA-256:E0D221588E506C5FDEA5013399AFE063F1674FFC5F8E483D4C141A4E183D4562
    SHA-512:6B76D02C9B914859CEC333732DE6C2DF41CA4FE2F853D500909BF13243E82365F4AA43D41F5E53FBDFCA637F5EDAFB182B155765A77B03DB11A0453E69F15E88
    Malicious:false
    Reputation:low
    Preview:[11/25/2024 06:28:35.282]: Info: ===== Cloud Agent Installer starting. PID: 7436 =====..[11/25/2024 06:28:35.297]: Info: Time-zone is: UTC-05:00 (Eastern Standard Time)..[11/25/2024 06:28:35.297]: Info: Initializing the Setup Engine..[11/25/2024 06:28:35.297]: Info: Current Setup version: 5.1.0.18..[11/25/2024 06:28:35.297]: Verbose: Current machine architecture is 64-bit..[11/25/2024 06:28:35.297]: Info: Creating wrapper setup mutex.....[11/25/2024 06:28:35.313]: Info: Waiting on wrapper setup mutex.....[11/25/2024 06:28:35.313]: Info: Ownership of wrapper setup mutex obtained..[11/25/2024 06:28:35.313]: Verbose: Parsing and verifying the setup parameters.....[11/25/2024 06:28:35.313]: Error: Following mandatory parameters are missing on Setup command line: ACTIVATIONID, CUSTOMERID, WEBSERVICEURI..These must be supplied on command line during Agent install..[11/25/2024 06:28:35.313]: Error: Failed to Install: One or more mandatory parameters not specified as Setup arguments..[11/25/20
    Process:C:\Users\user\Desktop\QualysCloudAgent (Windows).exe
    File Type:ASCII text, with CRLF, CR line terminators
    Category:dropped
    Size (bytes):83
    Entropy (8bit):4.112478772926379
    Encrypted:false
    SSDEEP:3:JI0ACMyqKFEBSE1EBEj9lHQyaFQFL4Ll:JI04yqWCkEUyaFQF8R
    MD5:B68F1BDC356EADFAD3C22DA4FDF3D567
    SHA1:F46F87F98B708FF2B0BBC2AA2B831D91A7F379E2
    SHA-256:0BC2CD7F4CEA53ECDCFCAA442ABBE07A025437864956DCB0936F3584B9116313
    SHA-512:2E689504EE8909F23711E32480F74AFF11D71E59B790EA1469863A5E62B9A6117598E8A2EE7E86EEF721FCD19318CC493C6C01F1A6C75E86487D66282737C44C
    Malicious:false
    Reputation:low
    Preview:Parameter validation failed : Mandatory arguments are missing for fresh install ...
    File type:PE32 executable (console) Intel 80386, for MS Windows
    Entropy (8bit):7.562830715904774
    TrID:
    • Win32 Executable (generic) a (10002005/4) 99.96%
    • Generic Win/DOS Executable (2004/3) 0.02%
    • DOS Executable Generic (2002/1) 0.02%
    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
    File name:QualysCloudAgent (Windows).exe
    File size:19'191'616 bytes
    MD5:b7472d4e38a5d4f3a272568142e2e875
    SHA1:a8a6f8b37e84c100aae35ee92fbe9a6911b507ef
    SHA256:844593ab69ce5f479bf937471a385b1a966dcc7b3bfca44ffa9ccfe6420b259e
    SHA512:b537875c5f2745f692bdb8f528a04bf634ab75d7c68c88de3ac220e4deaa11129414965b36c0185fbf43cb95e22268c3ec0d13289df8c87632794b62c26d93d5
    SSDEEP:393216:w2BBNg45YacDU8vcEcvaSfYtGPfq0RIQUlcE1h:w2BU4maDocExeHq0RIQB6
    TLSH:E117E111B7D08078E5F762F09E7646669A767C060734C6CF92A0355E1F32AE3ED3932A
    File Content Preview:MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$.......RHJ..)$..)$..)$......)$......)$......)$..p!..)$.-w'..)$.-w .0)$.-w!.o)$..Q...)$..w ..)$..w ..)$..Q...)$..)%..($..w-.1)$..w...)$
    Icon Hash:3368ccd64c69138e
    Entrypoint:0x4f5e72
    Entrypoint Section:.text
    Digitally signed:true
    Imagebase:0x400000
    Subsystem:windows cui
    Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
    Time Stamp:0x63EBB2C1 [Tue Feb 14 16:11:45 2023 UTC]
    TLS Callbacks:
    CLR (.Net) Version:
    OS Version Major:5
    OS Version Minor:1
    File Version Major:5
    File Version Minor:1
    Subsystem Version Major:5
    Subsystem Version Minor:1
    Import Hash:f2278c43c2814179dc78c973f4cee5d6
    Signature Valid:true
    Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
    Signature Validation Error:The operation completed successfully
    Error Number:0
    Not Before, Not After
    • 01/11/2022 00:00:00 02/11/2023 23:59:59
    Subject Chain
    • CN="Qualys, Inc", OU=Operations, O="Qualys, Inc", L=Foster City, S=California, C=US
    Version:3
    Thumbprint MD5:2D91895EFD34DB41535D99240EFD14C5
    Thumbprint SHA-1:589BEEA974BB46FA9F92608F99918B9C1B1E9E30
    Thumbprint SHA-256:C508016E619B6789270421E0DA1ADD3F2B2A3E6192076B8B1F3F866F86B674FF
    Serial:0BE99AE98438C9487D2BE6F5418FE18E
    Instruction
    call 00007F84C9159AC0h
    jmp 00007F84C9158CACh
    push ebp
    mov ebp, esp
    pop ebp
    jmp 00007F84C915892Ch
    jmp 00007F84C90ACCFBh
    push ebp
    mov ebp, esp
    push 00000000h
    call dword ptr [0053B17Ch]
    push dword ptr [ebp+08h]
    call dword ptr [0053B2C8h]
    push C0000409h
    call dword ptr [0053B210h]
    push eax
    call dword ptr [0053B06Ch]
    pop ebp
    ret
    push ebp
    mov ebp, esp
    sub esp, 00000324h
    push 00000017h
    call 00007F84C91969FDh
    test eax, eax
    je 00007F84C9158E27h
    push 00000002h
    pop ecx
    int 29h
    mov dword ptr [0057A6E8h], eax
    mov dword ptr [0057A6E4h], ecx
    mov dword ptr [0057A6E0h], edx
    mov dword ptr [0057A6DCh], ebx
    mov dword ptr [0057A6D8h], esi
    mov dword ptr [0057A6D4h], edi
    mov word ptr [0057A700h], ss
    mov word ptr [0057A6F4h], cs
    mov word ptr [0057A6D0h], ds
    mov word ptr [0057A6CCh], es
    mov word ptr [0057A6C8h], fs
    mov word ptr [0057A6C4h], gs
    pushfd
    pop dword ptr [0057A6F8h]
    mov eax, dword ptr [ebp+00h]
    mov dword ptr [0057A6ECh], eax
    mov eax, dword ptr [ebp+04h]
    mov dword ptr [0057A6F0h], eax
    lea eax, dword ptr [ebp+08h]
    mov dword ptr [0057A6FCh], eax
    mov eax, dword ptr [ebp+000000DCh]
    Programming Language:
    • [ C ] VS2008 SP1 build 30729
    • [IMP] VS2008 SP1 build 30729
    • [RES] VS2015 UPD3 build 24213
    • [LNK] VS2015 UPD3.1 build 24215
    NameVirtual AddressVirtual Size Is in Section
    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_IMPORT0x172e1c0x64.rdata
    IMAGE_DIRECTORY_ENTRY_RESOURCE0x1810000x10c3f24.rsrc
    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
    IMAGE_DIRECTORY_ENTRY_SECURITY0x124a8000x2f40.reloc
    IMAGE_DIRECTORY_ENTRY_BASERELOC0x12450000xcc78.reloc
    IMAGE_DIRECTORY_ENTRY_DEBUG0x1661300x70.rdata
    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
    IMAGE_DIRECTORY_ENTRY_TLS0x1661a00x18.rdata
    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x149f780x40.rdata
    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
    IMAGE_DIRECTORY_ENTRY_IAT0x13b0000x378.rdata
    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x172d100x80.rdata
    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
    .text0x10000x139f240x13a000eb1125b2c0d841f0f1476e23cac49891False0.5442679824343153data6.627688063108964IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
    .rdata0x13b0000x3928a0x3940085a34168919c684ce2a22d8f63c80bf3False0.37627081058951967data5.110487743921977IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .data0x1750000x86ec0x4e006cd633ccb0e2fa73cff62d18cc56db70False0.2065304487179487data4.338575100516842IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
    .gfids0x17e0000x11580x1200f1a19f48f741228942a4b124dadaac0dFalse0.3793402777777778data4.010817825441338IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .tls0x1800000x150x200adb00c88d5919bab3c4b160cbf2abed5False0.03515625data0.020393135236084953IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
    .rsrc0x1810000x10c3f240x10c4000126c3f3f3473d4be77eda3dc5a3ba814unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
    .reloc0x12450000xcc780xce0093c773551c1b18368334b3de07a41684False0.6689358313106796data6.668717860411995IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
    NameRVASizeTypeLanguageCountryZLIB Complexity
    RT_ICON0x1812b00x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.4716312056737589
    RT_ICON0x1817180x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States0.29174484052532834
    RT_ICON0x1827c00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States0.22863070539419086
    RT_ICON0x184d680x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16896EnglishUnited States0.20559754369390648
    RT_ICON0x188f900x10828Device independent bitmap graphic, 128 x 256 x 32, image size 67584EnglishUnited States0.15386549154146456
    RT_STRING0x1997b80x6cdata0.6481481481481481
    RT_RCDATA0x1998240x768000Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Qualys Cloud Security Agent, Author: Qualys, Inc., Keywords: Installer, Comments: This installer database contains the logic and data required to install Qualys Cloud Security Agent., Template: Intel;1033, Revision Number: {3764BEA4-F01C-4FCB-9E02-1961B1E5D31C}, Create Time/Date: Tue Feb 14 16:12:40 2023, Last Saved Time/Date: Tue Feb 14 16:12:40 2023, Number of Pages: 300, Number of Words: 2, Name of Creating Application: WiX Toolset (4.0.0.5918), Security: 20.5325832366943359
    RT_RCDATA0x9018240x943000Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Qualys Cloud Security Agent, Author: Qualys, Inc., Keywords: Installer, Comments: This installer database contains the logic and data required to install Qualys Cloud Security Agent., Template: x64;1033, Revision Number: {A9DBEB9C-7690-4D03-8251-5D1EE38D2F50}, Create Time/Date: Tue Feb 14 16:12:54 2023, Last Saved Time/Date: Tue Feb 14 16:12:54 2023, Number of Pages: 300, Number of Words: 2, Name of Creating Application: WiX Toolset (4.0.0.5918), Security: 20.5378999710083008
    RT_GROUP_ICON0x12448240x4cdataEnglishUnited States0.75
    RT_VERSION0x12448700x34cdataEnglishUnited States0.43483412322274884
    RT_MANIFEST0x1244bbc0x365XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (809), with CRLF line terminatorsEnglishUnited States0.48676639815880324
    DLLImport
    KERNEL32.dllFindNextFileW, FindClose, OpenProcess, TerminateProcess, GetCurrentThread, SetThreadPriority, SetFilePointer, GetFileAttributesW, DeleteFileW, CreateProcessW, GetExitCodeProcess, SetFileAttributesW, GetModuleFileNameW, GetTimeZoneInformation, GetSystemDirectoryW, LoadLibraryExW, FreeLibrary, Sleep, GlobalAlloc, FlushFileBuffers, GetTickCount, QueryPerformanceCounter, MapViewOfFile, CreateFileMappingW, FormatMessageA, GetSystemTimeAsFileTime, GetCurrentProcessId, GetFileSize, LockFileEx, CreateFileMappingA, UnlockFile, HeapDestroy, HeapCompact, LoadLibraryW, GetSystemInfo, HeapReAlloc, DeleteFileA, GetVersionExA, WaitForSingleObjectEx, CreateFileA, FlushViewOfFile, GetFileAttributesExW, GetFileAttributesA, GetDiskFreeSpaceA, FormatMessageW, GetTempPathA, HeapSize, HeapValidate, UnmapViewOfFile, GetVersionExW, GetTempPathW, UnlockFileEx, SetEndOfFile, GetFullPathNameA, LockFile, OutputDebugStringA, GetDiskFreeSpaceW, InterlockedCompareExchange, HeapCreate, CompareFileTime, AreFileApisANSI, GetCurrentThreadId, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, TryEnterCriticalSection, DeleteCriticalSection, GetLocalTime, CreateDirectoryW, GetCurrentDirectoryW, InitializeCriticalSectionAndSpinCount, SetUnhandledExceptionFilter, SetEnvironmentVariableW, VirtualAlloc, VirtualFree, SetEvent, ResetEvent, ReleaseSemaphore, CreateEventW, CreateSemaphoreW, GetSystemWow64DirectoryW, GlobalFree, RaiseException, SetStdHandle, SetEnvironmentVariableA, GetProcAddress, GetModuleHandleW, DebugBreak, VerifyVersionInfoW, VerSetConditionMask, GetVersion, GetFullPathNameW, LocalFree, HeapFree, GetProcessHeap, HeapAlloc, GetSystemTime, SystemTimeToFileTime, ExpandEnvironmentStringsW, WideCharToMultiByte, MultiByteToWideChar, GetConsoleCP, SetLastError, ReleaseMutex, CopyFileW, WaitForSingleObject, CreateMutexW, GetLastError, GetCurrentProcess, IsWow64Process, SetDllDirectoryW, OutputDebugStringW, GetFileSizeEx, CloseHandle, WriteFile, CreateFileW, SizeofResource, LockResource, LoadResource, FindResourceW, WriteConsoleW, ReadConsoleW, ReadFile, FindFirstFileW, LoadLibraryA, DecodePointer, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetOEMCP, IsValidCodePage, FindFirstFileExW, SetFilePointerEx, GetConsoleMode, GetFileType, EnumSystemLocalesW, GetUserDefaultLCID, IsValidLocale, GetTimeFormatW, GetDateFormatW, GetACP, VirtualProtect, VirtualQuery, LoadLibraryExA, DuplicateHandle, GetStringTypeW, EncodePointer, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, CompareStringW, LCMapStringW, GetLocaleInfoW, GetCPInfo, UnhandledExceptionFilter, IsProcessorFeaturePresent, IsDebuggerPresent, GetStartupInfoW, InitializeSListHead, CreateTimerQueue, SignalObjectAndWait, SwitchToThread, CreateThread, GetThreadPriority, GetLogicalProcessorInformation, CreateTimerQueueTimer, ChangeTimerQueueTimer, DeleteTimerQueueTimer, GetNumaHighestNodeNumber, GetProcessAffinityMask, SetThreadAffinityMask, RegisterWaitForSingleObject, UnregisterWait, GetThreadTimes, FreeLibraryAndExitThread, GetModuleHandleA, InterlockedPopEntrySList, InterlockedPushEntrySList, InterlockedFlushSList, QueryDepthSList, UnregisterWaitEx, RtlUnwind, ExitThread, GetModuleHandleExW, ExitProcess, GetStdHandle, GetCommandLineA, GetCommandLineW
    ADVAPI32.dllTreeResetNamedSecurityInfoW, ControlService, StartServiceW, CloseServiceHandle, QueryServiceStatusEx, OpenServiceW, OpenSCManagerW, GetTokenInformation, AdjustTokenPrivileges, OpenProcessToken, LookupPrivilegeValueW, CryptReleaseContext, GetSecurityDescriptorDacl, GetSecurityDescriptorGroup, GetSecurityDescriptorOwner, RegCreateKeyExW, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegQueryValueExW, RegCloseKey, RegDeleteValueW, RegSetValueExW, RegOpenKeyExW, RegDeleteKeyW
    SHELL32.dllSHCreateDirectoryExW
    SHLWAPI.dllPathFileExistsW, PathCombineA, PathAppendW, PathRemoveFileSpecW, PathCombineW, PathIsDirectoryW
    Language of compilation systemCountry where language is spokenMap
    EnglishUnited States
    No network behavior found

    Click to jump to process

    Click to jump to process

    Click to jump to process

    Target ID:0
    Start time:06:28:34
    Start date:25/11/2024
    Path:C:\Users\user\Desktop\QualysCloudAgent (Windows).exe
    Wow64 process (32bit):true
    Commandline:"C:\Users\user\Desktop\QualysCloudAgent (Windows).exe"
    Imagebase:0x8f0000
    File size:19'191'616 bytes
    MD5 hash:B7472D4E38A5D4F3A272568142E2E875
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    Target ID:1
    Start time:06:28:35
    Start date:25/11/2024
    Path:C:\Windows\System32\conhost.exe
    Wow64 process (32bit):false
    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Imagebase:0x7ff7699e0000
    File size:862'208 bytes
    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:high
    Has exited:true

    No disassembly