miragent.exe

MANDIANT Corporation

It runs as a separate (within the context of its own process) windows Service named “Intelligent Response Agent”.
Publisher:
MANDIANT Corporation  (signed and verified)

Version:
2.2.05

MD5:
8584a25222700fcbd4eb0cca13bdaaf3

SHA-1:
c024dac1db5371ab8ce91adcf2beb5278e48ef53

SHA-256:
9b16cdd6afc0682642dec2c1d13366460645a97c079afbbd66feb09da7b6aef7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 11:58:34 AM UTC  (today)

File size:
9 MB (9,449,848 bytes)

Product version:
2.2.1504

Copyright:
Copyright © 2012

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mandiant\mandiant intelligent response agent\miragent.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/20/2012 7:00:00 PM

Valid to:
3/1/2014 6:59:59 PM

Subject:
CN=MANDIANT Corporation, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=MANDIANT Corporation, L=Alexandria, S=Virginia, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0CFEB863E9CC913CBAB622E75693D64F

File PE Metadata
Compilation timestamp:
9/25/2012 4:14:57 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
98304:PeUuCUuQwua2Kih5F1y4YpZT3ze/EnqikQUTvZB8B+ecQomB142UpOvI:Pe3pw52LcP5qLljjeYmB1jI

Entry address:
0x373DE4

Entry point:
E8, 30, 7D, 01, 00, E9, A5, FE, FF, FF, 8B, FF, 55, 8B, EC, FF, 75, 0C, FF, 75, 08, FF, 15, 20, 12, 9D, 00, 85, C0, 75, 08, FF, 15, 94, 13, 9D, 00, EB, 02, 33, C0, 85, C0, 74, 0C, 50, E8, 78, C1, FF, FF, 59, 83, C8, FF, 5D, C3, 33, C0, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, FF, 75, 0C, 8D, 4D, F0, E8, B9, 82, FF, FF, 0F, B6, 45, 08, 8B, 4D, F0, 8B, 89, C8, 00, 00, 00, 0F, B7, 04, 41, 25, 00, 80, 00, 00, 80, 7D, FC, 00, 74, 07, 8B, 4D, F8, 83, 61, 70, FD, C9, C3, 8B, FF, 55, 8B, EC, 6A, 00, FF, 75, 08, E8...
 
[+]

Entropy:
6.5017

Code size:
5.8 MB (6,093,312 bytes)

Service
Display name:
Intelligent Response Agent

Type:
Win32OwnProcess


Scan miragent.exe - Powered by Reason Core Security