통합매크로(창모드).exe

The application 통합매크로(창모드).exe has been detected as a potentially unwanted program by 15 anti-malware scanners. While running, it connects to the Internet address netikus.net on port 80 using the HTTP protocol.
Version:
1.1.23.05

MD5:
7e28df407c3d0a1f3aedc47cff0f93a3

SHA-1:
ec4ed0aa49db6616d0b1e02166c12078d0370524

SHA-256:
6977acd888408ba3e7d9a678dc96f2a844c1a847e4bef31424d1aeb4208ddc3b

Scanner detections:
15 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 8:48:26 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.RP.uD0@aubrwBki
17.01.25

Avira AntiVirus
TR/Black.Gen2
8.3.3.4

Arcabit
Trojan.Heur.RP.ED3F0C
1.0.0.779

AVG
Win32/Heur
2018.0.2487

Bitdefender
Gen:Trojan.Heur.RP.uD0@aubrwBki
1.0.20.125

Bkav FE
HW32.Packed
1.3.0.8455

Emsisoft Anti-Malware
Gen:Trojan.Heur.RP.uD0@aubrwBki
8.17.01.25.02

ESET NOD32
Win32/Packed.VMProtect.ABO (variant)
11.14305

F-Secure
Gen:Trojan.Heur.RP.uD0@aubrwBki
11.2017-25-01_4

G Data
Gen:Trojan.Heur.RP.uD0@aubrwBki
17.1.25

IKARUS anti.virus
PUA.AHK
t3scan.2.1.16.0

MicroWorld eScan
Gen:Trojan.Heur.RP.uD0@aubrwBki
18.0.0.75

Qihoo 360 Security
HEUR/QVM16.0.0000.Malware.Gen
1.0.0.1120

Sophos
Mal/VMProtBad-A
4.98

VIPRE Antivirus
VirTool.Win32.Obfuscator.XZ
53150

File size:
1.3 MB (1,377,792 bytes)

Product version:
1.1.23.05

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
4/28/2016 7:48:12 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x23195E

Entry point:
68, B1, EF, FC, BD, E8, 37, 75, 00, 00, 12, C7, 69, 87, A1, D1, 20, 0E, 9F, 45, E5, 3D, 7C, E1, 36, 6B, 83, DA, B1, 29, A7, BF, 81, 58, 07, 1E, 8D, 14, 7F, 27, 5D, 83, A7, BD, D4, DB, CB, ED, 1A, F4, 70, 9B, 2F, 35, 29, 6F, 9F, C5, 71, D5, 2A, 44, 73, 09, 40, 0B, 2C, E5, 74, 69, 39, A0, 36, E0, 46, CA, 0A, 57, A3, B6, 0A, A1, 30, 72, E8, 09, FF, D3, 49, 34, 35, 57, D8, 26, 68, 6F, 52, 41, 1E, AF, 61, 79, 88, 06, C7, CE, AE, 78, 17, 0F, 25, 95, 2E, 90, 7D, 74, 52, F9, 50, 1D, 8F, 07, 9E, 9C, B2, 90, 46, FD...
 
[+]

Entropy:
7.9816  (probably packed)

Code size:
626.5 KB (641,536 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to netikus.net  (216.92.199.161:80)

Remove 통합매크로(창모드).exe - Powered by Reason Core Security