recycled.exe

abc

The application recycled.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named 18246977 triggered to execute each time a user logs in. While running, it connects to the Internet address hosted-by.instantdedicated.com on port 80 using the HTTP protocol.
Product:
abc

Version:
1.0.0.0

MD5:
92da9047145d90174df8dac79fb8ea26

SHA-1:
975b67f43006510e7dca48d5f5c85951ffed6b59

SHA-256:
c4d668a638218db8436b08f67e39c43f69ede35fc242656ab20fb614d1883c07

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
4/7/2025 1:53:58 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Dotdo.120
9.0.1.05190

ESET NOD32
MSIL/Adware.Dotdo.AP application
6.3.12010.0

Reason Heuristics
Adware.Dotdo.ET (M)
17.1.28.20

File size:
10.5 KB (10,752 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2016

Original file name:
recycled.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\recycled.exe

File PE Metadata
Compilation timestamp:
12/24/2016 4:09:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x3F0E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.2347

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
8 KB (8,192 bytes)

Scheduled Task
Task name:
18246977

Trigger:
Logon (Runs on logon)

Description:
1824697718246977


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to static.hosted-by.miamidedicated.com  (162.222.193.86:80)

TCP (HTTP):
Connects to r1-srp13-0.wan.hcvlny.cv.net  (167.206.12.113:80)

TCP (HTTP):
Connects to lga25s41-in-f238.1e100.net  (216.58.219.238:80)

TCP (HTTP):
Connects to hosted-by.instantdedicated.com  (188.95.50.96:80)

TCP (HTTP):
Connects to ec2-54-236-87-23.compute-1.amazonaws.com  (54.236.87.23:80)

TCP (HTTP):
Connects to ec2-52-6-27-111.compute-1.amazonaws.com  (52.6.27.111:80)

TCP (HTTP):
Connects to ec2-52-206-162-106.compute-1.amazonaws.com  (52.206.162.106:80)

TCP (HTTP):
Connects to cdce.nym011.internap.com  (63.251.19.13:80)

Remove recycled.exe - Powered by Reason Core Security