ymikndss.exe

The executable ymikndss.exe has been detected as malware by 2 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ymikndss’. While running, it connects to the Internet address static-139-235-132-188.sadecehosting.net on port 80 using the HTTP protocol.
MD5:
0f0262d9b79cf5422bb8d01ccf7b7c14

SHA-1:
25648232c1cd254693720c0d88139f9d18e91270

SHA-256:
77b7bc7c4c22c2be114a9fba8d628e51ce74a18fa35d5a5a7507b01ab08308f3

Scanner detections:
2 / 68

Status:
Malware

Analysis date:
11/30/2024 2:46:53 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.Proxy.27808
9.0.1.05190

Microsoft Security Essentials
TrojanDownloader:Win32/Cutwail.BF
1.235.2528.0

File size:
131.5 KB (134,656 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\ymikndss.exe

File PE Metadata
Compilation timestamp:
9/8/2000 1:38:13 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xF8E4

Entry point:
8A, EA, 0F, AF, C1, 71, 0C, 8D, 2D, 39, 14, 06, 55, 81, D3, 55, 81, 21, CD, 0F, B6, DD, FF, CD, 8A, E1, 4E, C6, C7, CC, F2, 42, 89, DE, 8D, 3D, 64, C9, 00, 00, F3, 81, EF, E8, 01, 00, 00, F7, C2, FD, 42, D6, 2D, 0F, AF, C3, C6, C4, 32, 33, CF, C6, C6, 42, FE, CA, 8A, E1, 78, 08, 87, CE, 0F, B6, D4, 0F, AF, CE, 33, F6, 81, FD, E5, CF, 00, 00, 73, 07, 87, EA, F6, C0, CC, 0A, E0, 80, D8, 1D, F3, 77, 02, 8B, C5, 81, C6, 01, 00, 00, 00, F3, C7, C3, F0, F0, 80, B3, 3B, FB, F6, C1, 3D, C6, C5, C6, 81, FE, DD, 0B...
 
[+]

Entropy:
7.8859  (probably packed)

Code size:
5.5 KB (5,632 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ymikndss

Command:
C:\Windows\System32\ymikndss.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to fm.interiowo.pl  (217.74.66.160:80)

TCP (HTTP):
Connects to static-139-235-132-188.sadecehosting.net  (188.132.235.139:80)

TCP (HTTP):
Connects to srv12024.hostingserver.nl  (91.142.252.26:80)

TCP (HTTP):

TCP (HTTP):
Connects to 213.202.229.103.static.rdns-uclo.net  (213.202.229.103:80)

Remove ymikndss.exe - Powered by Reason Core Security