fritzrenew.exe

FritzReConnect

The executable fritzrenew.exe has been detected as malware by 8 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download2061.mediafire.com.
Product:
FritzReConnect

Version:
1.0.0.0

MD5:
e0f4693851fb88b2eb47fca44de8eb20

SHA-1:
9138d71dd993f4f4cb24d3e77e8f4744492b6e0b

SHA-256:
cda69a7b97616a323a8aef3783b3b4587612aaf339b5ed611b09628115a209ca

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
4/25/2024 1:26:05 PM UTC  (today)

Scan engine
Detection
Engine version

Fortinet FortiGate
W32/Malware_fam.NB
1/25/2014

McAfee
Generic.dx!E0F4693851FB
5600.7239

Norman
Suspicious_Gen2.ONUWC
11.20140125

nProtect
Trojan/W32.Agent.32768.ATP
14.01.15.01

Panda Antivirus
Trj/CI.A
14.01.25.03

Reason Heuristics
Unnamed.Threat.21
14.2.24.7

Rising Antivirus
PE:Trojan.Win32.Generic.11EFF8CE!300939470
23.00.65.14123

VIPRE Antivirus
Trojan.Win32.Generic
25450

File size:
32 KB (32,768 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2007

Original file name:
FritzReConnect.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
1/19/2007 10:31:00 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
192:y6Bxf6MymfuIvePuhKjD4cyxZmILKnloYU45vzFIhfrBC3yv8ZVgfKG:y6BxfrKPuY2PLf45RQfrk3q8vgyG

Entry address:
0x50CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16 KB (16,384 bytes)

The file fritzrenew.exe has been seen being distributed by the following URL.

Remove fritzrenew.exe - Powered by Reason Core Security