remoto.simco.exe

The application remoto.simco.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from simcocloud.no-ip.info.
MD5:
8e202691d4ef76b559a7ec33fcd125f8

SHA-1:
9ae726bc3373b495aeeb8be18d6f4ad96a17b281

SHA-256:
49d8bc4b23217fc6b7535c8021ee02a9e57a8acd59c556b0a0621e70a7b16964

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 4:37:31 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Detection.Undefined
7.0.302.0

F-Prot
W32/VB-Backdoor-PEK-based!Maxim (not disinfectable)
4.6.5.141

Kaspersky
not-a-virus:RemoteAdmin.Win32.WinVNC
15.0.0.562

File size:
2.9 MB (2,990,790 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\remoto.simco.exe

File PE Metadata
Compilation timestamp:
7/9/2002 5:00:25 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
1.3

CTPH (ssdeep):
49152:eWK3DXTZzybn5nlFkp875P7FMtBf+ghC3qpYkts5rVtV09bugz4fL8GQ/H2iw:S3DXTZmb5nlplatBRhC6Fs5rVLgygELH

Entry address:
0x30A50

Entry point:
60, BE, 15, 70, 42, 00, 8D, BE, EB, 9F, FD, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
40 KB (40,960 bytes)

The file remoto.simco.exe has been seen being distributed by the following URL.

Remove remoto.simco.exe - Powered by Reason Core Security