temp4092498918.exe

The application temp4092498918.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘NetworkChecker’. While running, it connects to the Internet address host-176-36-223-16.la.net.ua on port 80 using the HTTP protocol.
MD5:
1405fd732258784f9789627f651222f2

SHA-1:
2c3969325fead8835f43aba5e7b0c05eb6b05e00

SHA-256:
dcda7f72ad87c394b674de8666fd35148c8ec93848bb661ecbdcf1fd69118e91

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/25/2024 9:23:15 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Updater.Startup
17.2.16.16

File size:
1 MB (1,089,339 bytes)

File type:
Executable application (Win64 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\appdata\local\temp\temp4092498918.exe

File PE Metadata
Compilation timestamp:
1/9/2017 10:50:19 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x33DD

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9362  (probably packed)

Code size:
12 KB (12,289 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NetworkChecker

Command:
C:\users\{user}\appdata\local\temp\temp4092498918.exe


The executing file has been seen to make the following network communications in live environments.

TCP (SMTP):
Connects to uk4.eyezonline.net  (84.22.177.39:25)

TCP (SMTP):
Connects to mail179.messagelabs.com  (85.158.139.35:25)

TCP (SMTP):
Connects to mta-v5.mail.vip.gq1.yahoo.com  (63.250.192.45:25)

TCP (SMTP):
Connects to mta-v3.mail.vip.gq1.yahoo.com  (98.136.217.202:25)

TCP (SMTP):
Connects to mta-v2.mail.vip.gq1.yahoo.com  (98.136.216.25:25)

TCP (SMTP):
Connects to mta-v1.mail.vip.ne1.yahoo.com  (98.138.112.38:25)

TCP (SMTP):
Connects to mta-v4.mail.vip.gq1.yahoo.com  (98.136.217.203:25)

TCP (SMTP):
Connects to mta-v4.mail.vip.bf1.yahoo.com  (66.196.118.35:25)

TCP (SMTP):
Connects to mta-v3.mail.vip.ne1.yahoo.com  (98.138.112.34:25)

TCP (SMTP):
Connects to mta-v6.mail.vip.ne1.yahoo.com  (98.138.112.32:25)

TCP (SMTP):
Connects to mta-v5.mail.vip.ne1.yahoo.com  (98.138.112.37:25)

TCP (SMTP):
Connects to mta-v4.mail.vip.ne1.yahoo.com  (98.138.112.35:25)

TCP (SMTP):
Connects to mta-v3.mail.vip.bf1.yahoo.com  (66.196.118.36:25)

TCP (SMTP):
Connects to mta-v2.mail.vip.bf1.yahoo.com  (66.196.118.34:25)

TCP (SMTP):
Connects to mta-v6.mail.vip.bf1.yahoo.com  (66.196.118.240:25)

TCP (SMTP):
Connects to mta-v2.mail.vip.ne1.yahoo.com  (98.138.112.33:25)

TCP (SMTP):
Connects to mta-v1.mail.vip.bf1.yahoo.com  (66.196.118.33:25)

TCP (SMTP):
Connects to mta-v6.mail.vip.gq1.yahoo.com  (63.250.192.46:25)

TCP (SMTP):
Connects to mta-v5.mail.vip.bf1.yahoo.com  (66.196.118.37:25)

TCP (SMTP):
Connects to mx1.hotmail.com  (65.55.92.168:25)

Remove temp4092498918.exe - Powered by Reason Core Security