greenvpn.exe

The executable greenvpn.exe has been detected as malware by 11 anti-virus scanners. The file has been seen being downloaded from 7xkerv.dl1.z0.glb.clouddn.com.
Version:
1.0.0.0

MD5:
5f3941628452eb0fd82838238af7991d

SHA-1:
327835ae9a194945f217751ddd2527f3b9595054

SHA-256:
946c9906ca619d9c2671a7c177e14dacf71249c8257cbb526cb6fe78fbfbc14f

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
1/13/2025 12:39:56 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2696853
490

Arcabit
Trojan.Generic.D292695
1.0.0.568

Bitdefender
Trojan.GenericKD.2696853
1.0.20.1375

Emsisoft Anti-Malware
Trojan.GenericKD.2696853
8.15.10.02.06

F-Secure
Trojan.GenericKD.2696853
11.2015-02-10_6

G Data
Trojan.GenericKD.2696853
15.10.25

K7 AntiVirus
Riskware
13.210.17400

MicroWorld eScan
Trojan.GenericKD.2696853
16.0.0.825

nProtect
Trojan.GenericKD.2696853
15.10.01.01

Trend Micro
PAK_Generic.005
10.465.02

VIPRE Antivirus
Trojan.Win32.Generic
44224

File size:
3.4 MB (3,544,064 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
1/19/2015 5:48:01 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:xddG6Aq9SSSr0phuLV5WbySxHuKPPe8n4tmJpu1efuRRaeHzwl7fTEf4DEJcZ38/:Tg0w5WbSIedmJpu1efuRRaPlfEJM

Entry address:
0x258544

Entry point:
55, 8B, EC, 83, C4, F0, B8, 58, 03, 65, 00, E8, 68, 26, DB, FF, E8, 6B, 7D, FF, FF, A1, EC, 27, 66, 00, 8B, 00, E8, 8F, 8E, E8, FF, A1, EC, 27, 66, 00, 8B, 00, B2, 01, E8, BD, AB, E8, FF, 8B, 0D, 3C, 23, 66, 00, A1, EC, 27, 66, 00, 8B, 00, 8B, 15, E0, 9A, 64, 00, E8, 81, 8E, E8, FF, 8B, 0D, 50, 28, 66, 00, A1, EC, 27, 66, 00, 8B, 00, 8B, 15, 6C, 6A, 64, 00, E8, 69, 8E, E8, FF, 33, C0, 55, 68, F3, 85, 65, 00, 64, FF, 30, 64, 89, 20, A1, 50, 28, 66, 00, 8B, 00, 8B, 10, FF, 92, 10, 01, 00, 00, A1, 3C, 23, 66...
 
[+]

Entropy:
6.5065

Developed / compiled with:
Microsoft Visual C++

Code size:
2.3 MB (2,455,552 bytes)

The file greenvpn.exe has been seen being distributed by the following URL.

Remove greenvpn.exe - Powered by Reason Core Security