c06150d65e64b0d8304f1ffb83acf59b.exe

Version:
2.40.2.69

MD5:
615cf49fc53068626e37bc3804875810

SHA-1:
cdcdb50bfcea73b187b86d60ffd6c5edd52b7589

SHA-256:
b6693eafd5f814d71ba32c0a3da2e63b4f4213dc2e15f182a34a5f8085fbc434

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/5/2024 6:48:17 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
PUA.MSIL.Wajam
4.0.3.16225

ESET NOD32
MSIL/Wajam.F potentially unwanted application
8.0.319.0

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1120

File size:
491 KB (502,784 bytes)

Product version:
2.40.2.69

Original file name:
8HV346.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\wajnetworkenhancer\wajnetworkenhancer internet enhancer\c06150d65e64b0d8304f1ffb83acf59b.exe

File PE Metadata
Compilation timestamp:
2/17/2016 11:51:56 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:0owPBeSqKziUGxEk9A0qHOuvnQtzNRCg5X9O5xrBeluthAybRs:0ou7D/no7dO12

Entry address:
0x7C0AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
488.5 KB (500,224 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to IP-130-73-156-104.static.fibrenoire.ca  (104.156.73.130:80)

TCP (HTTP):
Connects to rtr3.l7.search.vip.sg3.yahoo.com  (106.10.162.43:80)

TCP (HTTP SSL):
Connects to ec2-52-20-120-15.compute-1.amazonaws.com  (52.20.120.15:443)

TCP (HTTP):
Connects to cdn-117-121-249-253.sin.llnw.net  (117.121.249.253:80)

TCP (HTTP):
Connects to 7d.a0.a86c.ip4.static.sl-reverse.com  (108.168.160.125:80)

Scan c06150d65e64b0d8304f1ffb83acf59b.exe - Powered by Reason Core Security