winseven.exe

The executable winseven.exe has been detected as malware by 1 anti-virus scanner. While running, it connects to the Internet address fm.interiowo.pl on port 80 using the HTTP protocol.
MD5:
9ed36bd7d8e5a933a2b52615b77009e0

SHA-1:
3171b7ba94556317d043caf16a610b973833d84f

SHA-256:
40397ce3c62360198d173d03580e55420797c89d88f1d181408aae62fb5a6ce2

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/27/2024 3:49:23 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Trojan.Agent.Bibin
16.10.19.10

File size:
117.7 KB (120,507 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
11/22/2012 6:46:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
1536:XIX23i6EBXlLOUpJthWtch4LmUeOJAr7WqFt0sA8Yi3NWi6gX+p1B8:XIXtLOUpDEG6UlA8RwK6f8

Entry address:
0x1240

Entry point:
69, EB, 62, B9, 38, 16, 71, 02, 89, D2, BE, 9E, 6A, 9F, C0, 47, 11, DB, 0F, AF, D3, 89, CF, 8D, 2D, CB, 70, 99, 3E, F3, 80, FA, ED, 80, C7, 55, 69, EE, 7A, 82, DB, DE, FF, CD, 32, DD, 8D, 15, 3A, 78, 00, 00, C6, C3, 4A, 81, EA, 28, 2B, 00, 00, 69, FD, 6B, 88, B0, 49, 88, C3, 8B, F2, 20, DF, 81, C6, 22, 0F, 00, 00, 0F, BE, D9, F6, C4, E5, 6A, 00, 58, 08, FA, 8D, 3D, EA, E8, B3, 73, 0F, C1, F0, 85, C6, 8A, D0, 35, 8C, 04, 00, 00, 0F, AF, D6, 8A, FA, 6B, C9, 00, 69, F2, 06, B3, 06, 26, 89, F3, 69, DF, 2C, 01...
 
[+]

Entropy:
7.0253

Code size:
5 KB (5,120 bytes)

All Users Start Menu Item
Name:
taskhost.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to fm.interiowo.pl  (217.74.66.160:80)

TCP (HTTP):
Connects to 213.202.229.103.static.rdns-uclo.net  (213.202.229.103:80)

Remove winseven.exe - Powered by Reason Core Security