winseven.exe

The executable winseven.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘WinShell’. While running, it connects to the Internet address 210.151.74.137.fr.axspace.com on port 80 using the HTTP protocol.
MD5:
9f9bb11f6b05afe5e93dba0cf58ef412

SHA-1:
33568b4dd7bd82d26d15936eed3143c6853fd93b

SHA-256:
de068f764404d1b9a3f255edee6edb20250805b7de3c3d999ad634b07fbe0131

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
1/13/2025 4:48:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Trojan.Agent.SVN
17.3.3.10

File size:
127.1 KB (130,136 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
10/6/2012 4:11:08 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

Entry address:
0x1240

Entry point:
0F, AF, EB, 23, D9, 02, E7, 85, C8, 75, 07, 87, EE, B9, D9, 5D, 1D, 43, C7, C6, CE, 80, 7F, C3, 0F, AF, C7, 84, FF, 69, D1, 11, 49, 60, 7E, 42, 46, F2, 4B, F2, 8D, 45, 00, 86, EB, 0F, AF, C8, 8D, 35, B2, EF, 6A, DC, 84, CF, 41, 8D, 28, F2, C6, C0, 15, 2B, FD, 77, 02, B3, 2F, C7, C0, 03, 4F, 04, 30, 86, F0, 0B, D5, 0F, BE, D0, 84, E4, 0F, AF, F6, E8, 36, 00, 00, 00, 85, C0, 74, 0E, 88, FE, 69, F9, 4D, FE, 89, 8A, F7, C0, 3C, EB, 97, B0, 0D, 5D, CE, 27, 08, F7, C2, DD, D3, 3D, C2, F3, 81, ED, 3F, F9, FF, FF...
 
[+]

Entropy:
7.1717

Code size:
4 KB (4,096 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WinShell

Command:
C:\winshell\winseven.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to mailserver40.mylittledatacenter.com  (144.76.167.153:80)

TCP (HTTP):
Connects to 93-89-224-9.fbs.com.tr  (93.89.224.9:80)

TCP (HTTP):
Connects to 210.151.74.137.fr.axspace.com  (137.74.151.210:80)

Remove winseven.exe - Powered by Reason Core Security