pcsecurity77.exe

The executable pcsecurity77.exe, “SJP PC Security Checker” has been detected as malware by 8 anti-virus scanners. The file has been seen being downloaded from www.sjp.co.uk.
Description:
SJP PC Security Checker

Version:
7.7.0.0

MD5:
7a8cc38577e678555d5c63cb0326c21b

SHA-1:
dbc785e503aec7bc18f158cb40cd0d0977149538

SHA-256:
ea5d4212b7be5177d5218fd38ae121c8ead83711b174aa8f9f2d20928adfc88b

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
11/5/2024 10:29:24 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dldr.Agent.sfo.1
7.11.204.194

avast!
Win32:Malware-gen
2014.9-160224

Comodo Security
UnclassifiedMalware
20815

Norman
Suspicious_Gen4.DHHUV
11.20160224

Qihoo 360 Security
Win32/Trojan.e7d
1.0.0.1015

Sophos
Mal/Generic-L
4.98

Vba32 AntiVirus
Trojan-Downloader.Autoit.gen
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
36908

File size:
461.8 KB (472,932 bytes)

Copyright:
Nick Holden @ St. James's Place

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\appdata\local\temp\pcsecurity77.exe

File PE Metadata
Compilation timestamp:
1/29/2012 9:32:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:v6Wq4aaE6KwyF5L0Y2D1PqLzzxVvoTR/7z0OI:tthEVaPqLzzxVvoTBP0J

Entry address:
0xD9EA0

Entry point:
60, BE, 00, 80, 49, 00, 8D, BE, 00, 90, F6, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.1078

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
268 KB (274,432 bytes)

The file pcsecurity77.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-50-19-208-204.compute-1.amazonaws.com  (50.19.208.204:80)

Remove pcsecurity77.exe - Powered by Reason Core Security