lol.exe

The executable lol.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Windows Update’. The file has been seen being downloaded from exeupp.com. While running, it connects to the Internet address bzq-84-108-18-22.cablep.bezeqint.net on port 3175.
MD5:
368b37fbd11798171500f42b2752bb8d

SHA-1:
7a9b59662f0f87a3c223d2e12e2e127694dec51a

SHA-256:
59e4b09ad46a5e56df03fc1d10f38b82ef324c928b8382e6ae9fb8396fd8d966

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/27/2024 10:26:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.5.4.12

File size:
128 KB (131,072 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\lol.exe

File PE Metadata
Compilation timestamp:
8/2/2012 1:23:15 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:qEYw98LPzR9mGOPQhXFCRVpmL+OT1cmO8tzyZ:qEYTrCmXFKpmLcmOyQ

Entry address:
0x1C288

Entry point:
55, 8B, EC, 83, C4, EC, 53, 33, C0, 89, 45, EC, B8, 64, AF, 41, 00, E8, 5E, 9E, FE, FF, 8B, 1D, AC, DE, 41, 00, 33, C0, 55, 68, B2, C3, 41, 00, 64, FF, 30, 64, 89, 20, E8, 81, E9, FF, FF, 8D, 4D, EC, 8B, 15, 8C, DD, 41, 00, 8B, 12, A1, 90, DD, 41, 00, 8B, 00, E8, 02, A9, FE, FF, 8B, 55, EC, A1, CC, DE, 41, 00, E8, D1, 83, FE, FF, A1, 58, DD, 41, 00, 8B, 00, BA, C8, C3, 41, 00, E8, 70, 87, FE, FF, 75, 14, 8B, 15, 8C, DD, 41, 00, 8B, 12, A1, 90, DD, 41, 00, 8B, 00, E8, C2, A6, FE, FF, A1, A8, DC, 41, 00, 8B...
 
[+]

Entropy:
6.5458

Developed / compiled with:
Microsoft Visual C++

Code size:
105.5 KB (108,032 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Windows Update

Command:
C:\users\{user}\appdata\local\microsoft\svchost.exe


The file lol.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP:
Connects to bzq-84-108-18-22.cablep.bezeqint.net  (84.108.18.22:3175)

TCP:
Connects to bzq-84-108-153-134.cablep.bezeqint.net  (84.108.153.134:3175)

TCP:
Connects to bzq-84-108-17-214.cablep.bezeqint.net  (84.108.17.214:3175)

Remove lol.exe - Powered by Reason Core Security