service.exe

The executable service.exe has been detected as malware by 11 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. While running, it connects to the Internet address static-139-235-132-188.sadecehosting.net on port 80 using the HTTP protocol.
MD5:
354ead61075f879b785db47f103c0449

SHA-1:
70185715e05ca53387606b614208374839cb73b8

SHA-256:
618636561037cf5d20e76a9d660ec7a6d459d1d2380948965ed6fa0ce44ae01e

Scanner detections:
11 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/27/2024 3:54:57 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160216-0

AVG
Win32/Sality
2015.0.4530

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/MoonLight.worm
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.215.312.0

Norman
Win32.Sality.3
29.02.2016 05:46:54

Sophos
Virus 'Mal/Sality-D'
5.23

File size:
135.5 KB (138,748 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\microsoft\windows\templates\o74857z\service.exe

File PE Metadata
Compilation timestamp:
3/8/2004 7:27:36 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:WlpO1Ek93yAgfkvNIAzkTOuyhpQ+SvJrgwh71Nk8lGXtf4Z3BFVqN:WZkAbfklIAgTYpQrvJo8UZozV

Entry address:
0x118C

Entry point:
69, DA, D0, 00, 85, 90, B6, D6, B4, F3, 87, F0, 8D, 05, 0C, 9D, 88, E8, 40, 0F, AF, F1, 89, D0, 85, DD, 76, 06, C7, C3, DF, FF, 62, 64, BF, AB, CB, 87, D0, 0F, AF, E9, E8, 80, 00, 00, 00, C6, C4, C9, B9, 41, C2, D4, F3, 81, EB, 2D, E2, 69, 4D, 85, C6, 46, 85, F7, 8D, 2D, 84, 4C, 06, 00, 8B, DE, 2D, 10, DA, 2A, 21, 8A, CC, 81, ED, FA, 3F, 06, 00, 32, F5, 0F, BE, CC, FF, CB, C7, C3, 4E, 58, 0B, 00, 81, FB, 2C, 3C, 00, 00, 72, 04, 85, F3, 84, F9, 8D, 05, 58, BF, A5, 0B, F3, 8D, 0D, 83, F8, FF, FF, 28, E8, 8B...
 
[+]

Entropy:
6.3968

Code size:
72 KB (73,728 bytes)

User Start Menu Item
Name:
sql.cmd


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to static-139-235-132-188.sadecehosting.net  (188.132.235.139:80)

TCP (HTTP):
Connects to fm.interiowo.pl  (217.74.66.160:80)

TCP (HTTP):
Connects to 213.202.229.103.static.rdns-uclo.net  (213.202.229.103:80)

Remove service.exe - Powered by Reason Core Security