ellinia.exe

Launcher

The executable ellinia.exe has been detected as malware by 11 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from maple.ellinia.net. While running, it connects to the Internet address a253-12-209-91.zyztm.com on port 23497.
Product:
Launcher

Version:
0.0.0.0

MD5:
67f620a11a730966d8b9003797771468

SHA-1:
968dfa424f592957f7b3d41681c831a3f364fc6e

SHA-256:
8327e9cf215b7a1e0251ad41d316d166957a20e170a6b096e941d6df2d64943f

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
12/27/2024 4:54:33 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12056861
822

Avira AntiVirus
TR/Crypt.XPACK.Gen
7.11.182.216

avast!
Win32:Malware-gen
2014.9-141105

Bitdefender
Trojan.Generic.12056861
1.0.20.1545

Bkav FE
HW32.Packed
1.3.0.6185

Emsisoft Anti-Malware
Trojan.Generic.12056861
8.14.11.05.11

F-Secure
Trojan.Generic.12056861
11.2014-05-11_4

G Data
Trojan.Generic.12056861
14.11.24

IKARUS anti.virus
Trojan.Crypt
t3scan.1.8.3.0

McAfee
Artemis!67F620A11A73
5600.6956

nProtect
Trojan.Generic.12056861
14.10.31.01

File size:
4.8 MB (5,025,792 bytes)

Product version:
0.0.0.0

Original file name:
Redirector.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
10/27/2014 2:40:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:Ut5iY1paDpXElYvuiRpXfiyidIguEcvqKx/PTjiqtKYqwRIHZGn4KqD:EiY1pcNEGvuOpXfiErxzOqRRIHZGn4

Entry address:
0x4D008A

Entry point:
FF, 25, 80, 00, 8D, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9993  (probably packed)

Code size:
28.5 KB (29,184 bytes)

The file ellinia.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to a253-12-209-91.zyztm.com  (91.209.12.253:23497)

Remove ellinia.exe - Powered by Reason Core Security