cosa.exe

The executable cosa.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Nawyug’. While running, it connects to the Internet address redirect.domcollect.com on port 80 using the HTTP protocol.
MD5:
aec4dffe4d2d8f91d9d00f101e86ac65

SHA-1:
8dac616de1f64232805300f682f93ff22740c79a

SHA-256:
8857c6218cfa3c44cfcbd774bc7e83adb178f60cca442490ebf4b5c5a9a36bd4

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/16/2024 3:33:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
17.3.16.13

File size:
436 KB (446,464 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\inzyr\cosa.exe

File PE Metadata
Compilation timestamp:
10/31/2009 3:00:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x1000

Entry point:
68, 01, 20, 4A, 00, E8, 01, 00, 00, 00, C3, C3, 70, 6C, 74, 75, 5D, D8, A2, FE, 2F, 74, 41, 45, 78, C1, 7A, E3, B3, 36, FA, 30, 0F, CE, DF, 49, 8F, 92, 6B, 03, 3C, 7E, BA, DC, 31, 8E, 62, 28, 88, 30, 48, 3A, A4, 44, 7C, 9F, C7, F6, 28, 1D, A2, 5E, A9, 04, 22, F7, 6C, 10, 1E, 79, 8F, E7, BE, 53, 65, 92, 13, C3, B1, FC, 86, 62, 91, FD, 70, 1C, 7E, 94, 45, 4C, BA, 3C, A1, CD, C8, 6F, 22, 5C, 39, 0F, E7, 22, 05, 1C, 15, FA, 98, 6D, 1D, A7, 1B, 03, 52, 6A, B5, B1, BC, E6, 57, C6, 90, 5D, 51, E7, 3F, 4A, A1, EB...
 
[+]

Entropy:
7.9363

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
80 KB (81,920 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Nawyug

Command:
C:\users\{user}\appdata\roaming\inzyr\cosa.exe


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to redirect.domcollect.com  (91.195.241.121:80)

Remove cosa.exe - Powered by Reason Core Security