iivksggogy.exe

Viatlio Corporation

The application iivksggogy.exe by Viatlio has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Microsoft Windows Servicen’. The file has been seen being downloaded from awo-omamma.com.
Publisher:
Viatlio Corporation  (signed and verified)

Version:
0.0.0.0

MD5:
2be472151156811f8e0f10b9ea40c2e4

SHA-1:
adc84414570b6a0c268a8bc69060ad7e7b41e249

SHA-256:
68ba6812ff9e6e6fffbc830c542eaa748aa71d54a1f036362941f3aa936cade9

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
7/13/2025 8:06:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ViatlioC (M)
16.7.1.17

File size:
95.5 KB (97,800 bytes)

Product version:
0.0.0.0

Original file name:
TxZu6tMyINftXieMVykTPJR0SMD8vGeh252fQfE4JO.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\iivksggogy.exe

Digital Signature
Authority:
Viatlio Corporation

Valid from:
4/3/2016 1:02:53 AM

Valid to:
4/4/2017 1:02:53 AM

Subject:
E=viat@lio.com, CN=Viat Lio, OU=NAS Dept., O=Viatlio Corporation, L=Sydney, S=New South Wales, C=AU

Issuer:
E=viat@lio.com, CN=Viat Lio, OU=NAS Dept., O=Viatlio Corporation, L=Sydney, S=New South Wales, C=AU

Serial number:
00F2C8FB738509EF37

File PE Metadata
Compilation timestamp:
4/14/2016 12:36:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:MRAFkjX7vCVW5zY/D2GjHyt/Pkih40s8IEu7Q6VU6wLVB63ger3B58:/yf6VKs/D1jHyNkih40tyQ6VU6wLn63N

Entry address:
0x17EBE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.2889

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
88 KB (90,112 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Microsoft Windows Servicen

Command:
C:\windows\m-5050245506457483030076277654202405\winsvca.exe


The file iivksggogy.exe has been seen being distributed by the following URL.

Remove iivksggogy.exe - Powered by Reason Core Security