rc7.exe

VAJgPgyekGj

This is a setup program which is used to install the application. The file has been seen being downloaded from ln.sync.com.
Publisher:
VAJgPgyekGj

Description:
JCEyJcnQ

Version:
5.6.706.6104

MD5:
0a4341141715a576dae4726e4a44d200

SHA-1:
007a736d4c203451e57df280e8433d84caf13be2

SHA-256:
59456abe1f6f17bb283536e0cc620cff7bb3884345d4f00e742c773ecfc9694d

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/26/2024 2:11:45 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/TrojanDropper.Small.DG trojan
7.0.302.0

Qihoo 360 Security
QVM03.0.Malware.Gen
1.0.0.1120

Quick Heal
TrojanPWS.ZBot
3.16.14.00

File size:
532 KB (544,768 bytes)

Product version:
5.6.706.6104

Trademarks:
DielECEcS

Original file name:
VvSGxBA.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\rc7.exe

File PE Metadata
Compilation timestamp:
3/4/2016 2:38:50 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:icIHwAO5f6dDD5n3Atzu9DPCf0t5y0wFhuZW6xBNOEdFWOdrdujlel5xmhKYO904:icpAeGBQdYOuMaNdWipuMlWFC

Entry address:
0x7B5EE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6702

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
488 KB (499,712 bytes)

The file rc7.exe has been seen being distributed by the following URL.

Scan rc7.exe - Powered by Reason Core Security