redbotpro212.exe

Cfgport

Vitalwerks Internet Solutions, Inc.

The executable redbotpro212.exe has been detected as malware by 11 anti-virus scanners.
Publisher:
Vitalwerks Internet Solutions, Inc.  (signed and verified)

Product:
Cfgport

Version:
1.00

MD5:
095d10c7dba17c52cc05d0172fcea103

SHA-1:
d7e0dd421c7daeeb360e6a280e86be4c3f979400

SHA-256:
9b97eabe265c252d4bff460926358120e936046c55ddb042b78f46969882730f

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
12/26/2024 4:12:14 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.VB.teog
8.3.3.4

AVG
Dropper.Generic9
2017.0.2627

Baidu Antivirus
Win32.Trojan.WisdomEyes.151026.9950
4.0.3.1698

Bkav FE
HW32.Packed
1.3.0.8021

ESET NOD32
Win32/Injector.CYNA (variant)
10.13507

Fortinet FortiGate
W32/Injector.CYLW!tr
9/8/2016

IKARUS anti.virus
Trojan.Dropper
t3scan.2.0.9.0

McAfee
Artemis!095D10C7DBA1
5600.6283

Panda Antivirus
Trj/Genetic.gen
16.09.08.06

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1120

VIPRE Antivirus
Trojan.Win32.Generic
49466

File size:
3.8 MB (3,955,856 bytes)

Product version:
1.00

Original file name:
internet process protected.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\redbotpro212.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
10/22/2013 10:00:01 AM

Valid to:
2/10/2016 10:00:00 AM

Subject:
E=DUC@No-IP.com, CN="Vitalwerks Internet Solutions, Inc.", O="Vitalwerks Internet Solutions, Inc.", L=Reno, S=Nevada, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
08987B15170A5C6DE6E18FD6A23BD938

File PE Metadata
Compilation timestamp:
5/10/2016 1:18:26 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:BGm5nknMN6FqtBxLmhkpPV2Oa14xJSjkp1tOjAv1d:Qmen/AtB5ykpV2Oa14D7qeL

Entry address:
0x11FC

Entry point:
68, 40, B0, 7B, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 4D, 2D, DF, 18, 7C, 0D, 79, 47, 84, 00, F1, 9E, 11, 4E, 28, E0, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 31, 44, 32, 2D, 41, 39, 43, 72, 65, 69, 72, 67, 69, 73, 74, 31, 00, 34, 44, 41, 31, 7D, 00, 00, 00, 00, FF, CC, 31, 00, 03, 43, BE, 76, 9A, 59, 4D, 66, 4C, 95, 4D, B8, 49, 94, 96, FE, EF, D9, 6F, 12, F3, AD, 28, A6, 4A, 82, C2, 05, FB, 41, DE, AE, 6C, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
3.8 MB (3,932,160 bytes)

Remove redbotpro212.exe - Powered by Reason Core Security