cachemgr.exe

The executable cachemgr.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘StubPath’. While running, it connects to the Internet address techdays2008.net on port 80 using the HTTP protocol.
MD5:
a478249afa080ac6c14f355031c1e610

SHA-1:
5738c5a80c9aec06fea33fe5436b45daa2216c01

SHA-256:
2d83e454eef1d98afd585168c3458127c24ff065576a1a005750ae5296415f0b

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
7/5/2025 10:11:12 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Trojan.Installer (M)
16.4.25.14

File size:
169.5 KB (173,568 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\cachemgr.exe

File PE Metadata
Compilation timestamp:
9/5/1997 7:17:07 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:dOhXzHjHmMfL8sgeGibbc8pc1Eg6H/JyiVDDZyIJFLgNWsWvZRqQVgx5:GDNgfcc8i1iHByiVp9JFLVtZRqLx

Entry address:
0x12EFC

Entry point:
E8, 82, 27, 00, 00, E9, 79, FE, FF, FF, CC, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 78, BD, 41, 00, 89, 0D, 74, BD, 41, 00, 89, 15, 70, BD, 41, 00, 89, 1D, 6C, BD, 41, 00, 89, 35, 68, BD, 41, 00, 89, 3D, 64, BD, 41, 00, 66, 8C, 15, 90, BD, 41, 00, 66, 8C, 0D, 84, BD, 41, 00, 66, 8C, 1D, 60, BD, 41, 00, 66, 8C, 05, 5C, BD, 41, 00, 66, 8C, 25, 58, BD, 41, 00, 66, 8C, 2D, 54, BD, 41, 00, 9C, 8F, 05, 88, BD, 41, 00, 8B, 45, 00, A3, 7C, BD, 41, 00, 8B, 45, 04, A3, 80, BD, 41, 00, 8D, 45, 08, A3, 8C, BD...
 
[+]

Entropy:
6.4129

Code size:
95 KB (97,280 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
StubPath

Command:
"C:\ProgramData\cachemgr.exe" -as


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to techdays2008.net  (207.46.232.182:80)

TCP (HTTP):
Connects to windowsnt.name  (207.46.197.32:80)

Remove cachemgr.exe - Powered by Reason Core Security