网络嗅探器5.5.0.exe

V5.5

www.wlxtq.com

The application 网络嗅探器5.5.0.exe has been detected as a potentially unwanted program by 20 anti-malware scanners. While running, it connects to the Internet address 107.154.131.7.ip.incapdns.net on port 443.
Publisher:
www.wlxtq.com

Product:
V5.5

Description:
网络嗅探器(影音神探)

Version:
5.5.0.0

MD5:
b27e3ed0131cf5b7faed426c97279719

SHA-1:
a5b2caef1b1457cd79dedf9476536a788f587d39

SHA-256:
00a42ae30a6e065ef0a242ebf81c7332e2f2c81741135646cc1a9f22c5730172

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
4/28/2024 1:45:42 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
FakeAlert.Gen
2.1.4+

Agnitum Outpost
Trojan.Kryptik
7.1.1

AVG
FakeAlert
2016.0.3171

Bkav FE
HW32.Packed
1.3.0.6379

Comodo Security
UnclassifiedMalware
20937

Dr.Web
Trojan.DownLoad3.25022
9.0.1.072

Fortinet FortiGate
W32/Redosdru.ID!tr
3/13/2015

F-Secure
Packed:W32/PeCan.A
11.2015-13-03_6

IKARUS anti.virus
Worm.Win32.Nuj
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.193.14835

McAfee
Artemis!B27E3ED0131C
5600.6827

NANO AntiVirus
Trojan.Win32.DownLoad3.cysgwy
0.30.0.65070

Norman
Redosdru.LS
11.20150313

nProtect
Trojan/W32.Agent.1673240
15.01.30.01

Panda Antivirus
Generic Malware
15.03.13.09

Sophos
Mal/Generic-L
4.98

Total Defense
Win32/Etap
37.0.11417

Trend Micro House Call
TROJ_GEN.R0C1C0ELT14
7.2.72

Trend Micro
TROJ_GEN.R0C1C0ELT14
10.465.13

VIPRE Antivirus
Trojan-Dropper.Win32.Resdro.b
37192

File size:
1.6 MB (1,673,240 bytes)

Product version:
?????(????)

Copyright:
www.wlxtq.com

Trademarks:
E-Mail:wlxtq@163.com QQ:757838

Original file name:
网络嗅探器5.5.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\网络嗅探器5.5\网络嗅探器5.5.0.exe

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:Y+uqMSNKiGfq/bOxNsMUXrhM7bXFjFN3xROj:Y+u3TfqTOxiVibXFZROj

Entry address:
0x2A3F03

Entry point:
E8, 01, 00, 00, 00, 20, 87, 0C, 24, 8D, 89, DE, FA, FF, FF, 87, 0C, 24, E9, CC, FA, FF, FF, 28, E6, 5B, E9, 29, F9, FF, FF, 03, D0, E9, F0, F7, FF, FF, CD, 84, 36, CF, 11, 40, 00, FF, FF, 80, FC, 05, E9, DD, FD, FF, FF, E3, 1F, 8B, 5D, F8, E9, 22, FA, FF, FF, AE, 2B, D8, E9, B0, FD, FF, FF, 04, 36, 03, FE, E9, C9, F6, FF, FF, 06, 6A, 40, E9, 72, F7, FF, FF, 40, 0F, 87, 95, F5, FF, FF, E9, E5, FB, FF, FF, 66, C7, 45, EC, 73, 73, E9, 74, F9, FF, FF, 28, 14, 8B, 75, 08, E9, 43, F5, FF, FF, E0, 8D, 04, 50, E9...
 
[+]

Entropy:
7.6685

Code size:
1.8 MB (1,901,568 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-52-20-231-250.compute-1.amazonaws.com  (52.20.231.250:80)

TCP (HTTP SSL):
Connects to 107.154.131.7.ip.incapdns.net  (107.154.131.7:443)

Remove 网络嗅探器5.5.0.exe - Powered by Reason Core Security