wgetx.exe

MD5:
b18bb6106813560de61b2d5a767ff343

SHA-1:
c4fd830b965151870d59ebc73fdae4b079bfa330

SHA-256:
7920cb1960726d151279de38bd9e94153f116c7b6adb31cd01d224565f0d1895

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/23/2024 3:11:34 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Backdoor.LQS
7.1.1

McAfee
RDN/Generic.dx
5600.6537

Trend Micro
TROJ_GEN.R047C0OKU15
10.465.28

VIPRE Antivirus
Trojan.Win32.Generic
45608

File size:
347 KB (355,328 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
4/25/2009 4:09:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
7.10

CTPH (ssdeep):
6144:X7/yb+l/Wp+qI55kfGg98DTz5UxYcjFGVWpSID5NzUP9nGDj1PI3KoS:X76bCuM5kfmDTVUxVh4EzMn8SKoS

Entry address:
0xED920

Entry point:
60, BE, 00, 80, 49, 00, 8D, BE, 00, 90, F6, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, C3, BA, 0E, 00, 57, 83, C3, 04, 53, 68, 12, 59, 05, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
348 KB (356,352 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to host-213.158.175.59.tedata.net  (213.158.175.59:80)

TCP (HTTP):

TCP (HTTP):
Connects to 179.185.57.24.static.adsl.gvt.net.br  (179.185.57.24:80)

TCP (HTTP):
Connects to ppp-51-208.21-151.wind.it  (151.21.208.51:80)

TCP (HTTP):
Connects to host-62-24-201-202.as13285.net  (62.24.201.202:80)

TCP (HTTP):
Connects to host-213.158.175.112.tedata.net  (213.158.175.112:80)

TCP (HTTP):
Connects to cpng-r2-b211.time.net.my  (203.121.59.211:80)

TCP (HTTP):
Connects to bb24c188.virtua.com.br  (187.36.193.136:80)

TCP (HTTP):
Connects to b1232098.virtua.com.br  (177.35.32.152:80)

TCP (HTTP):
Connects to a92-122-46-185.deploy.akamaitechnologies.com  (92.122.46.185:80)

TCP (HTTP):
Connects to a88-221-103-47.deploy.akamaitechnologies.com  (88.221.103.47:80)

TCP (HTTP):
Connects to a72-247-182-82.deploy.akamaitechnologies.com  (72.247.182.82:80)

TCP (HTTP):
Connects to a72-246-64-114.deploy.akamaitechnologies.com  (72.246.64.114:80)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):
Connects to a173-222-108-104.deploy.static.akamaitechnologies.com  (173.222.108.104:80)

TCP (HTTP):
Connects to a104-67-178-56.deploy.static.akamaitechnologies.com  (104.67.178.56:80)

TCP (HTTP):
Connects to a104-121-32-42.deploy.static.akamaitechnologies.com  (104.121.32.42:80)

Scan wgetx.exe - Powered by Reason Core Security