04cfc7.exe

The application 04cfc7.exe has been detected as a potentially unwanted program by 40 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘04CFC7’.
MD5:
aa0df065eb4f335edbabdd734cfd6e11

SHA-1:
2ade2583fa0789d2e8eb02c175e20dae8e27e928

Scanner detections:
40 / 68

Status:
Potentially unwanted

Analysis date:
11/30/2024 9:04:19 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
GenPack:Backdoor.Generic.184365
261

Agnitum Outpost
Worm.Autorun
7.1.1

AhnLab V3 Security
Worm/Win32.FlyStudio
2014.08.22

Avira AntiVirus
TR/Dropper.Gen
7.11.168.140

avast!
Win32:Flystud-Q [Trj]
2014.9-160518

AVG
Generic3_c
2017.0.2739

Baidu Antivirus
Trojan.Win32.Scar
4.0.3.16518

Bitdefender
GenPack:Backdoor.Generic.184365
1.0.20.695

Bkav FE
W32.FlyStudioTn
1.3.0.4959

Clam AntiVirus
Worm.FlyStudio-28
0.98/21411

Comodo Security
UnclassifiedMalware
19272

Dr.Web
Win32.HLLW.Autoruner.26035
9.0.1.0139

Emsisoft Anti-Malware
GenPack:Backdoor.Generic.184365
8.16.05.18.07

ESET NOD32
Win32/FlyStudio.OGW
10.10295

Fortinet FortiGate
W32/PckdFlyStudio.gen
5/18/2016

F-Prot
W32/Nuj.A.gen
v6.4.7.1.166

F-Secure
Trojan-Dropper:W32/Peed.gen!A
11.2016-18-05_4

G Data
GenPack:Backdoor.Generic.184365
16.5.24

IKARUS anti.virus
Trojan.Win32.FlyStudio
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.183.13125

Kaspersky
Trojan.Win32.Scar
14.0.0.191

Malwarebytes
Worm.AutoRun
v2016.05.18.07

McAfee
Flyagent
5600.6395

Microsoft Security Essentials
Backdoor:Win32/FlyAgent.F
1.10903

MicroWorld eScan
GenPack:Backdoor.Generic.184365
17.0.0.417

NANO AntiVirus
Trojan.Win32.Scar.wgzeg
0.28.2.61721

nProtect
Trojan/W32.Agent.1462734
14.08.21.01

Panda Antivirus
Adware/AccesMembre
16.05.18.07

Qihoo 360 Security
Win32/Trojan.323
1.0.0.1015

Quick Heal
Backdoor.FlyAgent.F
5.16.14.00

Rising Antivirus
PE:Malware.FakeFolder@CV!1.6AA9
23.00.65.16516

Sophos
Mal/EncPk-NB
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-XPFraud
9135

Total Defense
Win32/Nuj.B!generic
37.0.11135

Trend Micro House Call
WORM_FLYSTUDI.B
7.2.139

Trend Micro
WORM_FLYSTUDI.B
10.465.18

Vba32 AntiVirus
TrojanDownloader.FlyStudio
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Autorun.dm
32434

ViRobot
Trojan.Win32.A.Scar.1462734
2011.4.7.4223

Zillya! Antivirus
Downloader.FlyStudio.Win32.2405
2.0.0.1897

File size:
1.4 MB (1,462,734 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\693ebf\04cfc7.exe

File PE Metadata
Compilation timestamp:
12/24/1972 9:33:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
4.0

CTPH (ssdeep):
24576:pZhabbJPjwbJW8tweTYhI1u0PdlLokm+/d938FRyK9wr3tP:pZONwbtDkgPdFFRV1sub5

Entry address:
0x1314

Entry point:
52, F9, 56, 57, 50, 53, 51, 0F, 82, BB, FF, FF, FF, C8, 25, CE, 09, 62, 2B, 80, DF, 5A, 14, 9B, 54, EB, CF, 59, 87, 47, 0F, 85, 4A, FE, FF, FF, E9, AD, FE, FF, FF, BC, 59, 8E, D0, F7, AD, 39, 00, 16, 84, 59, EA, BD, A3, 02, 22, BE, E4, AF, 04, 95, 26, DA, F8, 9B, A9, CA, F5, 7D, BB, AD, 44, ED, 95, E6, 87, 97, 80, A8, F9, 57, 3C, C4, 83, C2, FF, F8, 0F, 83, C0, FF, FF, FF, A9, A1, BF, C0, 61, 87, 28, 79, 9C, E4, 28, 74, F6, 34, 5B, B1, FD, 1E, DE, A5, E6, 54, AA, 3B, 7F, BB, 20, 19, 65, CC, E4, 24, 77, 3A...
 
[+]

Entropy:
7.8228  (probably packed)

Code size:
24 KB (24,576 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
04CFC7

Command:
C:\Windows\System32\693ebf\04cfc7.exe


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-52-0-217-44.compute-1.amazonaws.com  (52.0.217.44:80)

Remove 04cfc7.exe - Powered by Reason Core Security