cachemgr.exe

The executable cachemgr.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘StubPath’. While running, it connects to the Internet address windowxp.lv on port 80 using the HTTP protocol.
MD5:
8e8bf41efee6a375e9e73c42cec32b4e

SHA-1:
5dca5d56d28b8c82b593c09f6572b83970019b22

SHA-256:
06369c6dafd7dccc198ab339ccf76e0bc7d7f9090389db8bb85630a1861858aa

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/28/2024 4:39:06 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Trojan.Installer (M)
16.3.25.15

File size:
166 KB (169,984 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\cachemgr.exe

File PE Metadata
Compilation timestamp:
12/20/2011 1:45:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:5OhXzHjHmMfL8sgeGibbc8pc1Eg6H/JyiVDDZyIJFLgNWsWvZRqQVgx5h:aDNgfcc8i1iHByiVp9JFLVtZRqLxj

Entry address:
0x12EFC

Entry point:
E8, 82, 27, 00, 00, E9, 79, FE, FF, FF, CC, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 78, BD, 41, 00, 89, 0D, 74, BD, 41, 00, 89, 15, 70, BD, 41, 00, 89, 1D, 6C, BD, 41, 00, 89, 35, 68, BD, 41, 00, 89, 3D, 64, BD, 41, 00, 66, 8C, 15, 90, BD, 41, 00, 66, 8C, 0D, 84, BD, 41, 00, 66, 8C, 1D, 60, BD, 41, 00, 66, 8C, 05, 5C, BD, 41, 00, 66, 8C, 25, 58, BD, 41, 00, 66, 8C, 2D, 54, BD, 41, 00, 9C, 8F, 05, 88, BD, 41, 00, 8B, 45, 00, A3, 7C, BD, 41, 00, 8B, 45, 04, A3, 80, BD, 41, 00, 8D, 45, 08, A3, 8C, BD...
 
[+]

Entropy:
6.5061

Code size:
95 KB (97,280 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
StubPath

Command:
"C:\ProgramData\cachemgr.exe" -as


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to windowxp.lv  (207.46.232.182:80)

TCP (HTTP):
Connects to designedforbig.co.za  (207.46.197.32:80)

Remove cachemgr.exe - Powered by Reason Core Security