Task Information
Task ID: ed149195-eef0-11ec-921d-42010aa4000b
File name: SQLAGENTIHC.exe
Task parameters: ClamAV scan: True
Unpack: True
Share file: True
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
Rule name: exploit_any_poppopret
Alert
Author: Jeff White [karttoon@gmail.com] @noottrak
Description: Identify POP -> POP -> RET opcodes for quick ROP Gadget creation in target binaries.
TLP: TLP:WHITE
Unpacker
The following YARA rules matched on the unpacked file.
Rule name: exploit_any_poppopret
Author: Jeff White [karttoon@gmail.com] @noottrak
Description: Identify POP -> POP -> RET opcodes for quick ROP Gadget creation in target binaries.
TLP : TLP:WHITE
Rule name: meth_get_eip
Author: Willi Ballenthin
TLP : TLP:WHITE
Rule name: pdb_YARAify
Author: @wowabiy314
Description: PDB
TLP : TLP:WHITE
Unpacked Files
The following files could be unpacked from this sample.
File name 4390000.dll
MD5 hash: 0c1c61d07b00c8e7c96fe56906d44198
SHA256 hash: 19d594b05e0886dec12f759408b2f273453217a2caf1947ec2bee686e95f7e74
File size: 46'932 bytes
File type: application/x-dosexec
YARA matches: 2
File name 400000.SQLAGENTSWE.exe.tag
MD5 hash: fedc8b576197622a796c12f1c797e4f0
SHA256 hash: 4e8f17b950984d707d2aacd39fd34b78ae7f31fc59cefe6002eb58bbbb741ce1
File size: 127'019 bytes
File type: text/plain
YARA matches: 0
File name 400000.dea96605-8181-416b-9fca-21c7c629e508.exe.tag
MD5 hash: bc199fcbfa8c34cd16fcc899af860670
SHA256 hash: 26862be0db0ae88e68aba25d5cbe20562a93109c38e45b8e8b9eded9a204f309
File size: 128'416 bytes
File type: text/plain
YARA matches: 0
File name 400000.dea96605-8181-416b-9fca-21c7c629e508.exe
MD5 hash: 6cdb4c231ae9903478e23d2a83d64182
SHA256 hash: 43c3b85efd60316c9ea9246a2ea12abe75a60cc8ef109c40b0dcac9df75eef6d
File size: 1'494'397 bytes
File type: application/x-dosexec
YARA matches: 3
File name 400000.SQLAGENTSWE.exe
MD5 hash: caabb7daaa3650615c87a547ba574eb5
SHA256 hash: 78a36bca4d1990d4c6ee643a5b54b69bbca8a77ee89d5678cd1ed658b71cbe4b
File size: 1'494'485 bytes
File type: application/x-dosexec
YARA matches: 3
File name 4310000.dll
MD5 hash: a775bcec215c422e97d37251e9b9b47d
SHA256 hash: 1e68e214c6c1a91e56341ace8e5b6f07448dc0482502efb68b333d61c5c4e9d2
File size: 46'932 bytes
File type: application/x-dosexec
YARA matches: 2