xfwqygu.exe

StproW

The application xfwqygu.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. While running, it connects to the Internet address static.vnpt.vn on port 80 using the HTTP protocol.
Product:
StproW

Version:
1.0.7.0

MD5:
acfb3ca30c539d636b4659f24560967b

SHA-1:
fc43d0b782136dd69b1342eca09e5535c7015004

SHA-256:
9efcd0b77a2690a257d32a35843e8a3780140383a8d810d320f2d25e61f8d5fc

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 4:58:56 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.39610
681

Agnitum Outpost
Trojan.Agent
7.1.1

AhnLab V3 Security
Trojan/Win32.MDA
2015.03.20

Avira AntiVirus
TR/Dropper.Gen
7.11.218.152

avast!
Win32:Malware-gen
2014.9-150325

Baidu Antivirus
Adware.MSIL.Linkury
4.0.3.15325

Bitdefender
Gen:Variant.Strictor.39610
1.0.20.420

Clam AntiVirus
Win.Trojan.Agent-1283778
0.98/22391

Emsisoft Anti-Malware
Gen:Variant.Strictor.39610
8.15.03.25.03

ESET NOD32
MSIL/Toolbar.Linkury.H potentially unwanted application
6.3.12010.0

F-Secure
Gen:Variant.Strictor.39610
11.2015-25-03_4

G Data
Gen:Variant.Strictor.39610
15.3.25

K7 AntiVirus
Trojan
13.202.15319

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.2292

McAfee
Artemis!ACFB3CA30C53
5600.6815

MicroWorld eScan
Gen:Variant.Strictor.39610
16.0.0.252

Sophos
Generic PUA PM
4.98

Trend Micro House Call
TROJ_GEN.R08NH07CH15
7.2.84

VIPRE Antivirus
Trojan.Win32.Generic
38588

File size:
497.2 KB (509,120 bytes)

Product version:
1.0.7.0

Copyright:
Copyright © 2014

Original file name:
StproW.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\rgmservice\qxebe\xfwqygu.exe

File PE Metadata
Compilation timestamp:
2/17/2015 12:54:19 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:uFPx5yZIpT/qI7Eog7OepA48N0IGtPVMpzi7bS3Zq9ztG:0PXT/qIgogqepi6tSpzgbSJ

Entry address:
0x4EEF2

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
308 KB (315,392 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to static.vnpt.vn  (113.171.238.20:80)

TCP (HTTP):
Connects to a92-123-180-186.deploy.akamaitechnologies.com  (92.123.180.186:80)

TCP (HTTP):
Connects to w04.ttms.eu  (46.105.156.76:80)

TCP (HTTP):
Connects to lb1.forsetup.com  (108.163.213.235:80)

TCP (HTTP):
Connects to ip-50-63-202-62.ip.secureserver.net  (50.63.202.62:80)

TCP (HTTP):
Connects to CableLink-200-188-128-136.Hosts.Cablevision.com.mx  (200.188.128.136:80)

TCP (HTTP):
Connects to yesup.com  (199.21.148.198:80)

TCP (HTTP):
Connects to ec2-54-243-167-203.compute-1.amazonaws.com  (54.243.167.203:80)

TCP (HTTP):
Connects to 94.31.29.64.IPYX-077437-ZYO.above.net  (94.31.29.64:80)

TCP (HTTP):
Connects to waws-prod-bay-003.cloudapp.net  (137.117.17.70:80)

TCP (HTTP):
Connects to server-54-192-11-160.lhr3.r.cloudfront.net  (54.192.11.160:80)

TCP (HTTP):
Connects to ec2-54-225-239-132.compute-1.amazonaws.com  (54.225.239.132:80)

TCP (HTTP):
Connects to ec2-54-225-148-173.compute-1.amazonaws.com  (54.225.148.173:80)

TCP (HTTP):
Connects to ec2-184-72-255-181.compute-1.amazonaws.com  (184.72.255.181:80)

TCP (HTTP):
Connects to 37-97-195-205.colo.transip.net  (37.97.195.205:80)

TCP (HTTP):
Connects to 151.bm-nginx-loadbalancer.mgmt.sin1.adnexus.net  (103.243.221.87:80)

Remove xfwqygu.exe - Powered by Reason Core Security