temp3501895252.exe

The application temp3501895252.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘NetworkNotifyer’. While running, it connects to the Internet address 88.204.225.102.dial.online.kz on port 80 using the HTTP protocol.
MD5:
e7babb1ec3e491d31651442da5fe4f7f

SHA-1:
66612f27cacd754b01f9759b9d23acbb635c2464

SHA-256:
6367e88fe1da09c926af811c94e09757a60650fd0fd1a978ba2f2c733d9bd6f6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
7/5/2024 9:06:19 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Updater.Startup
17.3.3.12

File size:
1 MB (1,097,404 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\temp3501895252.exe

File PE Metadata
Compilation timestamp:
10/15/2016 5:17:25 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x852F

Entry point:
55, 8B, EC, 6A, FF, 68, 88, A5, 20, 00, 68, BC, 90, 20, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, E0, 94, 20, 00, 59, 83, 0D, 50, D0, 20, 00, FF, 83, 0D, 54, D0, 20, 00, FF, FF, 15, 94, 94, 20, 00, 8B, 0D, 44, D0, 20, 00, 89, 08, FF, 15, E8, 94, 20, 00, 8B, 0D, 40, D0, 20, 00, 89, 08, A1, E4, 94, 20, 00, 8B, 00, A3, 4C, D0, 20, 00, E8, 1D, 01, 00, 00, 39, 1D, 30, CF, 20, 00, 75, 0C, 68, B8, 86, 20, 90, FF, 15, D4, 94...
 
[+]

Entropy:
7.9626

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
96 KB (98,304 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NetworkNotifyer

Command:
C:\users\{user}\appdata\local\temp\temp3377406550.exe


The executing file has been seen to make the following network communications in live environments.

TCP (SMTP):
Connects to mx2.nifty.com  (210.131.2.29:25)

TCP (SMTP):
Connects to mx1.naver.com  (125.209.238.100:25)

TCP (SMTP):
Connects to mx1.hotmail.com  (104.44.194.231:25)

TCP (SMTP):
Connects to mx.vgs.untd.com  (64.136.52.37:25)

TCP (SMTP):
Connects to mx.dca.untd.com  (64.136.44.37:25)

TCP (SMTP):
Connects to mx.centurylink.net  (205.219.233.5:25)

TCP (SMTP):
Connects to mx.bt.lon5.cpcloud.co.uk  (65.20.0.49:25)

TCP (SMTP):
Connects to mx.b.hostedemail.com  (64.98.36.4:25)

TCP (SMTP):
Connects to mta-v6.mail.vip.bf1.yahoo.com  (66.196.118.240:25)

TCP (SMTP):
Connects to mta-v5.mail.vip.bf1.yahoo.com  (66.196.118.37:25)

TCP (SMTP):
Connects to mta-v2.mail.vip.bf1.yahoo.com  (66.196.118.34:25)

TCP (SMTP):
Connects to mta-v1.mail.vip.sg3.yahoo.com  (106.10.166.52:25)

TCP (SMTP):
Connects to mta-v1.mail.vip.ne1.yahoo.com  (98.138.112.38:25)

TCP (SMTP):
Connects to mtain-a-mtc-c.mx.aol.com  (64.12.91.195:25)

TCP (SMTP):
Connects to mtain-a-mtc-a.mx.aol.com  (64.12.88.131:25)

TCP (SMTP):
Connects to mta703.mail.vip.djm.yahoo.co.jp  (183.79.16.117:25)

TCP (SMTP):
Connects to mailin-05.mail.aol.com  (64.12.88.163:25)

TCP (SMTP):
Connects to mail4.mckesson.com  (143.112.68.13:25)

TCP (SMTP):
Connects to imscm07.netvigator.com  (218.102.23.147:25)

TCP (SMTP):
Connects to hd-exchange2.hdisp.org  (12.197.176.131:25)

Remove temp3501895252.exe - Powered by Reason Core Security