sеrvices.exe

The executable sеrvices.exe has been detected as malware by 30 anti-virus scanners. While running, it connects to the Internet address dev.ucoz.net on port 80 using the HTTP protocol.
MD5:
eef0a7884481940e1f5a87765875c4ef

SHA-1:
85182937bb2dfc5cff540404bf8707d1e4a7aee1

SHA-256:
0a4600b9b31b42600a51a57805711e0c9dca5873d92244f52376bb2215be4569

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
11/17/2024 1:34:25 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.17051
364

Agnitum Outpost
Trojan.Strictor
7.1.1

AhnLab V3 Security
HEUR/Fakon.mwf
2015.02.10

Avira AntiVirus
TR/Vorsluga.A.1
7.11.209.22

avast!
Win32:Malware-gen
2014.9-160205

AVG
Luhe.Fiha.A
2017.0.2842

Baidu Antivirus
Worm.Win32.Delf
4.0.3.1625

Bitdefender
Gen:Variant.Strictor.17051
1.0.20.180

Comodo Security
Worm.Win32.Agent.~dy89
21015

Dr.Web
Trojan.Siggen5.61088
9.0.1.036

Emsisoft Anti-Malware
Gen:Variant.Strictor.17051
8.16.02.05.03

ESET NOD32
Win32/Delf.NJG (variant)
10.11147

Fortinet FortiGate
W32/Delf.RXM!tr.dldr
2/5/2016

F-Prot
W32/SelfStarterInternetTrojan!M
v6.4.7.1.166

F-Secure
Gen:Variant.Strictor.17051
11.2016-05-02_6

G Data
Gen:Variant.Strictor.17051
16.2.25

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.194.14904

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.707

McAfee
Artemis!EEF0A7884481
5600.6498

Microsoft Security Essentials
Trojan:Win32/Vorsluga.A
1.1.11302.0

MicroWorld eScan
Gen:Variant.Strictor.17051
17.0.0.108

NANO AntiVirus
Trojan.Win32.Siggen5.cubkjf
0.30.0.65070

Norman
Obfuscated.H!genr
11.20160205

Panda Antivirus
Generic Malware
16.02.05.03

Qihoo 360 Security
Win32/Trojan.b3b
1.0.0.1015

Quick Heal
Trojan.Vorsluga.r8
2.16.14.00

Sophos
Mal/Generic-S
4.98

Total Defense
Win32/FakeFLDR_i
37.0.11431

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
37390

File size:
354.5 KB (363,008 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:PKTIZkrgIWHhoDlo1fu31V0YYYDrfyhTsUOS9tSh66maLTRcNLEeRDs:c1WbA0YYUyhwo9tSU6maRSr

Entry address:
0x495EC

Entry point:
55, 8B, EC, 83, C4, F0, 33, C0, 89, 45, F0, B8, 1C, 92, 44, 00, E8, 17, C4, FB, FF, 33, C0, 55, 68, 94, 96, 44, 00, 64, FF, 30, 64, 89, 20, 8D, 55, F0, B8, 01, 00, 00, 00, E8, CC, DF, FB, FF, 8B, 45, F0, BA, A8, 96, 44, 00, E8, 7B, 9F, FB, FF, 75, 18, 6A, 00, 68, AC, 96, 44, 00, 68, B8, 96, 44, 00, 6A, 00, E8, 0E, C9, FB, FF, E8, 99, 9B, FB, FF, B2, 01, A1, 40, 4F, 44, 00, E8, 55, B9, FF, FF, 8B, 15, 1C, D0, 44, 00, 89, 02, A1, 1C, D0, 44, 00, 8B, 00, 8B, 40, 04, E8, 6E, 56, FC, FF, A1, 50, D0, 44, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
290 KB (296,960 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to vh74.sweb.ru  (77.222.42.238:80)

TCP (HTTP):
Connects to dev.ucoz.net  (193.109.246.62:80)

TCP (HTTP SSL):
Connects to 2ip.ru  (178.63.151.224:443)

Remove sеrvices.exe - Powered by Reason Core Security