googleupdatecomregistershell64.exe

MD5:
90f3d0bf7354887fe3c7708884efe747

SHA-1:
295bf0bd4a6354d6aea391506a034fd95b47a146

SHA-256:
dc903628c30bd4f6b95079173caeff0f3a7a6d6b6857b488082c771c64d2efb7

Scanner detections:
8 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/19/2024 4:24:30 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Worm/Win32.Runouce
2015.05.03

Bitdefender
Win32.Worm.Nimda.O
1.0.20.940

Fortinet FortiGate
W32/Runouce.B@mm
7/7/2015

G Data
Win32.Worm.Nimda
15.7.25

IKARUS anti.virus
Email-Worm.Win32.Runouce
t3scan.1.8.9.0

Panda Antivirus
W32/Chir.P.worm
15.07.07.03

Rising Antivirus
PE:Worm.Runouce!1.9DC6
23.00.65.15705

Sophos
W32/Chir-B
4.98

File size:
112.8 KB (115,528 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\googleupdatecomregistershell64.exe

File PE Metadata
Compilation timestamp:
1/21/2015 5:21:22 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:CUA0reNTIy74Wu7qULumLJCKEiuxgbi3a:CUA0WTn74Wu7VjLJCTY+a

Entry address:
0x5658

Entry point:
48, 83, EC, 28, E8, 7B, 2B, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, E9, CF, 01, 00, 00, CC, CC, CC, 40, 57, 48, 83, EC, 20, 4D, 8B, D0, 45, 33, C0, 4D, 85, C9, 75, 04, 33, C0, EB, 5F, 48, 85, C9, 75, 15, E8, 75, 0F, 00, 00, BF, 16, 00, 00, 00, 89, 38, E8, C9, 0A, 00, 00, 8B, C7, EB, 45, 4D, 85, D2, 74, 13, 49, 3B, D1, 72, 0E, 4F, 8D, 04, 09, 49, 8B, D2, E8, D7, 01, 00, 00, EB, CA, 48, 85, D2, 74, 0D, 48, 8B, F9, 41, 0F, B7, C0, 48, 8B, CA, 66, F3, AB, 4D, 85, D2, 74, BC, 49, 3B, D1, 73, 0C, E8...
 
[+]

Entropy:
6.1895

Code size:
68 KB (69,632 bytes)

Scan googleupdatecomregistershell64.exe - Powered by Reason Core Security