rc7cracked.exe

The executable rc7cracked.exe has been detected as malware by 15 anti-virus scanners. While running, it connects to the Internet address xo5.x10hosting.com on port 80 using the HTTP protocol.
Version:
0.0.0.0

MD5:
1410d80eace89b5087cabd9c24751b71

SHA-1:
5450e7ec943b820191c8207af2fcca0d1eb5dd67

SHA-256:
e8ab7d6700a19fd61048ce79aae16ed8c115f14f50146ef4f91939001711ed68

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
4/1/2025 8:30:43 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Heur.MSIL.Krypt.2
-40

AhnLab V3 Security
Trojan/Win32.Generic.C289731
3.8.3.16

Avira AntiVirus
TR/Dropper.Gen
8.3.3.4

Arcabit
Trojan.MSIL.Krypt.2
1.0.0.802

avast!
Win32:Malware-gen
2014.9-170315

AVG
ILHeur
2018.0.2438

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.17315

Bitdefender
Gen:Heur.MSIL.Krypt.2
1.0.20.370

Emsisoft Anti-Malware
Gen:Heur.MSIL.Krypt
8.17.03.15.08

ESET NOD32
MSIL/Agent.RSK (variant)
11.15094

F-Secure
Gen:Heur.MSIL.Krypt.2
11.2017-15-03_4

G Data
Gen:Heur.MSIL.Krypt
17.3.A:25.11195B:25.9090

Malwarebytes
Backdoor.Agent.PGen
v2017.03.15.08

MicroWorld eScan
Gen:Heur.MSIL.Krypt.2
18.0.0.222

Qihoo 360 Security
HEUR/QVM03.0.0000.Malware.Gen
1.0.0.1120

File size:
188 KB (192,512 bytes)

Product version:
0.0.0.0

Original file name:
stub.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\rc7cracked.exe

File PE Metadata
Compilation timestamp:
3/15/2017 11:46:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x1FC8E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.5880

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
119.5 KB (122,368 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to xo5.x10hosting.com  (198.91.81.6:80)

Remove rc7cracked.exe - Powered by Reason Core Security