msn.exe

The executable msn.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘apo5’. While running, it connects to the Internet address ws8.mysecurewebserver.com on port 80 using the HTTP protocol.
MD5:
b146e5ba489dca47f2c8401f2dba3b64

SHA-1:
d3c6eb94244f5758915834d240bc771408953683

SHA-256:
5105e737faf3afb3b97eb710aba0330f0e296741c74078606412eb5a82f7f527

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/27/2024 5:14:03 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Worm.Macoute (H)
17.1.24.11

File size:
1.7 MB (1,751,552 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
3/26/2011 8:06:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.20

Entry address:
0x12C0

Entry point:
60, 1D, C5, 45, BB, DA, 0F, CF, 20, E2, 53, 53, 80, FB, BE, 84, CB, 08, E9, 8A, F9, 4E, 85, D0, 08, ED, 0F, AD, F9, C0, F0, 56, E8, 46, 00, 00, 00, 2B, C9, FE, C4, 0F, BA, F0, 06, 3A, DB, 89, DB, F6, C1, BC, 15, 95, EA, E3, F7, 81, EB, 04, A4, 9D, 8D, 81, C1, 89, 0F, 00, 00, 0F, BA, E6, B2, C6, C4, 86, 39, CD, 81, E9, 88, 0F, 00, 00, 84, E0, 02, F0, 2B, F0, 0F, BC, C6, 0F, CF, 81, F9, 2A, 00, 00, 00, 0F, 8C, BC, FF, FF, FF, 0F, A5, F1, 0F, A5, DA, 0F, BA, E1, F6, 0F, A4, CD, A2, 05, 4B, 62, AB, 48, FF, CD...
 
[+]

Code size:
232 KB (237,568 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
apo5

Command:
C:\win\msn.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ws8.mysecurewebserver.com  (202.75.52.228:80)

TCP (HTTP):
Connects to odhinn.agava.net  (89.108.96.156:80)

TCP (HTTP):
Connects to double4.holm.ru  (89.108.91.168:80)

Remove msn.exe - Powered by Reason Core Security