winsvc.exe

Miranda IM

The executable winsvc.exe has been detected as malware by 12 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from mariaclaret.edu.pe and multiple other hosts.
Publisher:
Miranda IM

Product:
Miranda IM

Version:
0.10.24.0

MD5:
13b218ff170e7f289e573d928a90ed79

SHA-1:
d5fd79072ae00e40d595baf1fa1dfaef4b581263

SHA-256:
a8367e6569431f3b6e284b2518f47d72f5dc734caff3a258e3a092b084b0cbd6

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
11/15/2024 2:33:35 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2260781
347

AVG
BackDoor.Ircbot
2017.0.2825

Bitdefender
Trojan.GenericKD.2260781
1.0.20.265

Emsisoft Anti-Malware
Trojan.GenericKD.2260781
8.16.02.22.08

ESET NOD32
Win32/Injector.BXGJ (variant)
10.11402

F-Secure
Trojan.Delf.QDR
11.2016-22-02_2

G Data
Trojan.GenericKD.2260781
16.2.25

K7 AntiVirus
Trojan
13.202.15432

Kaspersky
Trojan-Dropper.Win32.Sysn
14.0.0.621

MicroWorld eScan
Trojan.GenericKD.2260781
17.0.0.159

Panda Antivirus
Generic Suspicious
16.02.22.08

Sophos
Troj/DarkCom-Z
4.98

File size:
1.1 MB (1,107,456 bytes)

Product version:
0.10.24.0

Copyright:
Copyright © 2000-2014 Miranda IM Project. This software is licensed under the terms of the GNU General Public License.

Original file name:
miranda32.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\m-5050756432604649683503740\winsvc.exe

File PE Metadata
Compilation timestamp:
6/19/1992 10:50:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:EVTvRaeKGlHiM4lKD13YxWnVZunCAEJYQHxw88o878jsfRJ/kkkkckkkkbkkkhkd:+vbvlZVRhnbVAEa1YYJVk

Entry address:
0xA4CBC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 74, 4A, 4A, 00, E8, 5C, 20, F6, FF, A1, 78, E6, 4A, 00, 8B, 00, E8, 90, 52, FB, FF, 8B, 0D, D4, E7, 4A, 00, A1, 78, E6, 4A, 00, 8B, 00, 8B, 15, 78, 40, 4A, 00, E8, 90, 52, FB, FF, A1, 78, E6, 4A, 00, 8B, 00, E8, 04, 53, FB, FF, E8, AB, F8, F5, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
655.5 KB (671,232 bytes)

Windows Firewall Allowed Program
Name:
C:\Windows\M-5050756432604649683503740\winsvc.exe


The file winsvc.exe has been seen being distributed by the following 2 URLs.

http://mariaclaret.edu.pe/wrk.exe

Remove winsvc.exe - Powered by Reason Core Security