cn3.exe

The executable cn3.exe has been detected as malware by 7 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from fabrik.smartstartinc.net and multiple other hosts. While running, it connects to the Internet address vultr.com on port 47.
MD5:
397db7289ec420c7a20f195e1d74fdc5

SHA-1:
dc89c994506d0f5d7d0efc4ad33820a50115045d

SHA-256:
36a43d5af95b7f6ce2d47ac06612c72ad26663c10f66e5bdc77ce4de8561aaad

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
12/28/2024 2:04:11 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
MSIL:Bladabindi-JK [Trj]
160215-2

Dr.Web
BackDoor.Bladabindi.1194
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.MSIL.Bladabindi
10.0.0.5366

ESET NOD32
MSIL/Bladabindi.AS trojan
8.0.319.0

McAfee
Trojan.BackDoor-NJRat!397DB7289EC4
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.6352.0

VIPRE Antivirus
Threat.4799966
47240

File size:
23.5 KB (24,064 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\cn3.exe

File PE Metadata
Compilation timestamp:
2/15/2016 6:27:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:Tk2qa14sEY29S9ShR4u2e/CXp6EXLyzMdOJ/xJvz2jmzUM9l/Us0X/s:rqTSClxxo8JDvUgjJ

Entry address:
0x744E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
21.5 KB (22,016 bytes)

The file cn3.exe has been seen being distributed by the following 3 URLs.

https://fabrik.smartstartinc.net/.../cn3.exe

http://manningpr.com.au/.../Control.exe

The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to vultr.com  (45.32.151.87:47)

Remove cn3.exe - Powered by Reason Core Security