vkontaktedj.exe

VKontakte DJ

The executable vkontaktedj.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘VkontakteDJ’. This file is typically installed with the program Vkontakte DJ by VkontakteDJ. While running, it connects to the Internet address h1net188-64-172-90.h1host.ru on port 80 using the HTTP protocol.
Product:
VKontakte DJ

Description:
VKDJ, Player

Version:
3.76.0.0

MD5:
593d8107b773c957e276cccaa2ef7910

SHA-1:
b739130b8b805540b12996ac29d0ced9c17021be

SHA-256:
b29931f61f5c86e4a6c6780f2b4e7378d31a9797a224a737f0f0fcb0e77f31b3

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/27/2024 6:46:52 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.9.13.11

File size:
4.9 MB (5,182,464 bytes)

Product version:
3.76

Copyright:
Copyright (C) 2008. All rights reserved.

Original file name:
VKontakte-DJ.exe

File type:
Executable application (Win32 EXE)

Language:
Tiê´ng Anh (My~)

Common path:
C:\users\{user}\appdata\roaming\vkontaktedj\vkontaktedj.exe

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:HhEwQ5Vjeq2Uz/KTNgPkDTOokIQvFRdyWExYfcmeuvN:HewQ5VjJ2Uz/KTTDTOEQvFFESknuV

Entry address:
0x266164

Entry point:
55, 8B, EC, 83, C4, EC, 53, 56, 57, 33, C0, 89, 45, EC, B8, 1C, 56, 66, 00, E8, F4, 15, DA, FF, 33, C0, 55, 68, 2E, 62, 66, 00, 64, FF, 30, 64, 89, 20, E8, AD, E9, FF, FF, 33, C0, 55, 68, D6, 61, 66, 00, 64, FF, 30, 64, 89, 20, A1, B4, C7, 67, 00, 8B, 00, E8, 9F, B6, E0, FF, B9, 90, FC, 67, 00, A1, B4, C7, 67, 00, 8B, 00, 8B, 15, 1C, 7E, 62, 00, E8, A0, B6, E0, FF, A1, B4, C7, 67, 00, 8B, 00, E8, 14, B7, E0, FF, 33, C0, 5A, 59, 59, 64, 89, 10, EB, 30, E9, E5, E3, D9, FF, 01, 00, 00, 00, E8, 8C, 40, 00, E7...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.4 MB (2,511,872 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
VkontakteDJ

Command:
C:\users\{user}\appdata\roaming\vkontaktedj\vkontaktedj.exe \h


The file vkontaktedj.exe has been discovered within the following program.

Vkontakte DJ  by VkontakteDJ
vkontakte.dj/about
45% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to h1net188-64-172-90.h1host.ru  (188.64.172.90:80)

TCP (HTTP):
Connects to static.228.51.243.136.clients.your-server.de  (136.243.51.228:80)

TCP (HTTP SSL):
Connects to srv82-165-240-87.vk.com  (87.240.165.82:443)

TCP (HTTP):
Connects to s2-db.nitralabs.com  (46.28.68.78:80)

TCP (HTTP):
Connects to lab.mn  (82.118.16.253:80)

TCP (HTTP):
Connects to ip-static-94-242-214-18.server.lu  (94.242.214.18:80)

Remove vkontaktedj.exe - Powered by Reason Core Security