PaAgent.exe

AT&T Participant Agent

AT&T Inc.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Launch AT&T Connect Participant web browser agent’.
Publisher:
AT&T Inc.  (signed and verified)

Product:
AT&T Participant Agent

Description:
AT&T Participant Agent Application

Version:
11.7.218.112

MD5:
a71cc2ec6daca217ea8cf21832132cfb

SHA-1:
44651a33c4de9ba462bb7976a280f1377dd8c661

SHA-256:
b96b6549fc5c0854f44843846130f801193924be268dc9f4887026315f0b4a62

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 10:33:21 AM UTC  (today)

File size:
158.2 KB (162,016 bytes)

Product version:
11.7.218.112

Copyright:
©2016 AT&T Intellectual Property. All rights reserved

Original file name:
PaAgent.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\att connect\participant\paagent.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
1/20/2016 2:00:00 AM

Valid to:
12/11/2016 1:59:59 AM

Subject:
CN=AT&T Inc., O=AT&T Inc., L=San Antonio, S=Texas, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
4769DB5E31278C7BA68810424C828246

File PE Metadata
Compilation timestamp:
2/1/2016 9:52:55 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:pdCaaCcd3HmNc6vC777777777777777737s77777777777777dm7777777777773:pkRZHlF777777777777777737s77777c

Entry address:
0x82BD

Entry point:
E8, 1F, 05, 00, 00, E9, 91, FE, FF, FF, 3B, 0D, 28, E0, 40, 00, 75, 02, F3, C3, E9, 8F, 01, 00, 00, 83, 3D, 9C, E8, 40, 00, 00, 74, 03, 33, C0, C3, 56, 6A, 04, 6A, 20, FF, 15, 1C, A2, 40, 00, 59, 59, 8B, F0, 56, FF, 15, 98, A0, 40, 00, A3, 9C, E8, 40, 00, A3, 98, E8, 40, 00, 85, F6, 75, 05, 6A, 18, 58, 5E, C3, 83, 26, 00, 33, C0, 5E, C3, 6A, 14, 68, C0, BC, 40, 00, E8, D2, 05, 00, 00, FF, 35, 9C, E8, 40, 00, 8B, 35, 94, A0, 40, 00, FF, D6, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, 24, A2, 40, 00...
 
[+]

Entropy:
6.5683

Code size:
33 KB (33,792 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Launch AT&T Connect Participant web browser agent

Command:
"C:\users\{user}\appdata\local\att connect\participant\paagent.exe"


Scan PaAgent.exe - Powered by Reason Core Security