errornuker.exe

Setup

TrekEight LLC

The executable errornuker.exe has been detected as malware by 8 anti-virus scanners. The file has been seen being downloaded from www.errornuker.com. While running, it connects to the Internet address s02.trekdata.com on port 80 using the HTTP protocol.
Publisher:
TrekEight LLC  (signed and verified)

Product:
Setup

Version:
1, 3, 0, 0

MD5:
4fa3321deb5880c6711b6b64a35dee95

SHA-1:
aea5a7ecf79c7893355a56dd0bb3424f3af1206d

SHA-256:
9b9408e920a67f3cadf9dcaf001483651d4ac09e18c446d76442ec9515dde173

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
5/6/2024 6:02:13 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clodcf6.Trojan
1.3.0.4959

Malwarebytes
Rogue.Installer
v2014.08.31.08

SUPERAntiSpyware
Trojan.Malware
10388

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

XVirus List
Win32.Detected
2.8.31

File size:
53.6 KB (54,856 bytes)

Product version:
1, 3, 0, 0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/20/2005 7:00:00 PM

Valid to:
12/20/2006 6:59:59 PM

Subject:
CN=TrekEight LLC, OU=IT Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=TrekEight LLC, L=La Costa, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3778139F5AB532D759C69AF5FD9802CA

File PE Metadata
Compilation timestamp:
3/9/2004 6:29:42 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:FCzdyC6+duNYSTesaIkRDzsqkhUZZZ3DIr7ibMyL3zbh:Ft+dzSURDwqkSZZZ3g7ibMyTh

Entry address:
0x1800

Entry point:
83, EC, 44, 56, 6A, 00, FF, 15, 34, 40, 40, 00, 8B, F0, 8D, 44, 24, 04, 50, FF, 15, 30, 40, 40, 00, F6, 44, 24, 30, 01, 74, 0B, 8B, 44, 24, 34, 25, FF, FF, 00, 00, EB, 05, B8, 0A, 00, 00, 00, 50, FF, 15, 2C, 40, 40, 00, 50, 6A, 00, 56, E8, 60, 01, 00, 00, 5E, 83, C4, 44, C3, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 8B, 44, 24, 04, 8B, 0D, 40, 54, 40, 00, 53, 56, 57, 25, FF, FF, 00, 00, 68, 14, 51, 40, 00, 50, 51, FF, 15, 44, 40, 40, 00, 8B, F8, 85, FF, 75, 09, 5F, 5E, B8, 94, 54, 40, 00, 5B, C3, 8B, 15...
 
[+]

Entropy:
5.4022

Code size:
12 KB (12,288 bytes)

The file errornuker.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to s02.trekdata.com  (72.44.67.8:80)

Remove errornuker.exe - Powered by Reason Core Security