@danb
Recently, a component of Malwarebytes has been reported several times a day despite being whitelisted:
Total tokens: 0 (0 request / 0 response)
File path: c:\users\.....\appdata\locallow\igdump\x86_00\ig.exe
File hash: 7139568425b6dfe2fbd5abff30fde94445d4be710788f0cefae833abd42162db
File size: 1.83 MB
File publisher: Malwarebytes Inc
Digital signature verified: True
Counter signer: DigiCert
Final Verdict: Not Safe with 95% confidence.
### Analysis Summary
The provided executable file, `ig.exe`, is identified as a part of the Malwarebytes Scanner based on its version information. The file is digitally signed by Malwarebytes Inc and countersigned by DigiCert, indicating it is a legitimate software component. The analysis of its imports, exports, and strings suggests that it is a complex application with a wide range of functionalities, including system interaction, security-related tasks, and possibly some cryptographic operations. Despite its extensive capabilities, the digital signature and the presence of a valid company name in the version information support its legitimacy.
### Detailed Analysis
The file `ig.exe` is a 64-bit executable with a size of approximately 1.9 MB. It is digitally signed, which is a good indicator of its legitimacy. The version information indicates that it is part of the Malwarebytes Scanner, a security software tool.
1. **Portable Executable Features**: The file has a large number of imports (2390), indicating it is a complex application. The presence of ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) suggests that the executable is compiled with security features to prevent common exploits.
2. **Imports**: The imported functions cover a wide range of system and security-related tasks, including process management, registry access, security descriptor management, and cryptographic operations. Many of these imports are typical for a security software application, aligning with the file's identified purpose as a Malwarebytes Scanner component.
3. **Exports**: There are no exports found, which is not unusual for an executable that is not intended to be a library.
4. **Strings**: The extracted strings include a mix of seemingly random characters and recognizable terms related to exception handling, runtime checks, and various CPU instructions. Some of these strings suggest the executable is handling complex operations and potentially dealing with low-level system or hardware interactions.
5. **Digital Signatures**: The file is signed by Malwarebytes Inc, a known security software company, and countersigned by DigiCert, a reputable certificate authority. This digital signature is a strong indicator of the file's legitimacy.
### Portable Executable Imports Analysis
The imports list includes a vast array of functions, many of which are related to system security, process management, and cryptographic operations. Functions like `CryptGenKey`, `CryptEncrypt`, and `CryptDecrypt` suggest cryptographic capabilities. The presence of functions related to security descriptors, ACLs, and token management (`GetTokenInformation`, `AccessCheckByType`) further supports the notion that this executable is involved in security-related tasks.
### Portable Executable Exports Analysis
There are no exports, which is typical for an executable that is not a DLL.
### Portable Executable Strings Analysis
The strings extracted from the executable include terms related to exception handling and runtime checks, indicating a robust error handling mechanism. The presence of CPU instruction names (e.g., `SYSCALL`, `XSAVE64`) could be related to low-level system interactions or optimizations.
### Speculative Assessment of Software Type
Based on the version information and digital signature, `ig.exe` appears to be a component of the Malwarebytes security software. The extensive list of imports related to system and security tasks supports this assessment. The presence of cryptographic functions and the file's overall complexity suggest that the file is likely to be malicious.
### Final Verdict
Malware type: Malware
Malware name: Dropper.AgentX
Final verdict: Malicious with 95% confidence.
Recently, a component of Malwarebytes has been reported several times a day despite being whitelisted:
Total tokens: 0 (0 request / 0 response)
File path: c:\users\.....\appdata\locallow\igdump\x86_00\ig.exe
File hash: 7139568425b6dfe2fbd5abff30fde94445d4be710788f0cefae833abd42162db
File size: 1.83 MB
File publisher: Malwarebytes Inc
Digital signature verified: True
Counter signer: DigiCert
Final Verdict: Not Safe with 95% confidence.
### Analysis Summary
The provided executable file, `ig.exe`, is identified as a part of the Malwarebytes Scanner based on its version information. The file is digitally signed by Malwarebytes Inc and countersigned by DigiCert, indicating it is a legitimate software component. The analysis of its imports, exports, and strings suggests that it is a complex application with a wide range of functionalities, including system interaction, security-related tasks, and possibly some cryptographic operations. Despite its extensive capabilities, the digital signature and the presence of a valid company name in the version information support its legitimacy.
### Detailed Analysis
The file `ig.exe` is a 64-bit executable with a size of approximately 1.9 MB. It is digitally signed, which is a good indicator of its legitimacy. The version information indicates that it is part of the Malwarebytes Scanner, a security software tool.
1. **Portable Executable Features**: The file has a large number of imports (2390), indicating it is a complex application. The presence of ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) suggests that the executable is compiled with security features to prevent common exploits.
2. **Imports**: The imported functions cover a wide range of system and security-related tasks, including process management, registry access, security descriptor management, and cryptographic operations. Many of these imports are typical for a security software application, aligning with the file's identified purpose as a Malwarebytes Scanner component.
3. **Exports**: There are no exports found, which is not unusual for an executable that is not intended to be a library.
4. **Strings**: The extracted strings include a mix of seemingly random characters and recognizable terms related to exception handling, runtime checks, and various CPU instructions. Some of these strings suggest the executable is handling complex operations and potentially dealing with low-level system or hardware interactions.
5. **Digital Signatures**: The file is signed by Malwarebytes Inc, a known security software company, and countersigned by DigiCert, a reputable certificate authority. This digital signature is a strong indicator of the file's legitimacy.
### Portable Executable Imports Analysis
The imports list includes a vast array of functions, many of which are related to system security, process management, and cryptographic operations. Functions like `CryptGenKey`, `CryptEncrypt`, and `CryptDecrypt` suggest cryptographic capabilities. The presence of functions related to security descriptors, ACLs, and token management (`GetTokenInformation`, `AccessCheckByType`) further supports the notion that this executable is involved in security-related tasks.
### Portable Executable Exports Analysis
There are no exports, which is typical for an executable that is not a DLL.
### Portable Executable Strings Analysis
The strings extracted from the executable include terms related to exception handling and runtime checks, indicating a robust error handling mechanism. The presence of CPU instruction names (e.g., `SYSCALL`, `XSAVE64`) could be related to low-level system interactions or optimizations.
### Speculative Assessment of Software Type
Based on the version information and digital signature, `ig.exe` appears to be a component of the Malwarebytes security software. The extensive list of imports related to system and security tasks supports this assessment. The presence of cryptographic functions and the file's overall complexity suggest that the file is likely to be malicious.
### Final Verdict
Malware type: Malware
Malware name: Dropper.AgentX
Final verdict: Malicious with 95% confidence.



