mirc.exe

mIRC

mIRC Co. Ltd.

The application mirc.exe has been detected as a potentially unwanted program by 20 anti-malware scanners. While running, it connects to the Internet address maki.mog422.net on port 7777.
Publisher:
mIRC Co. Ltd.

Product:
mIRC

Version:
6.2

MD5:
11f022dde69fa8b121cfe7848a4cc8f2

SHA-1:
e42cf1f0e9d8ed223b6574144c9ba706050eb782

SHA-256:
3e6c3d24c129672dd62ccc0276e7eab2896fc1718263d84b495c0669968aa448

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 4:10:51 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
IRC-Worm.Generic.15662
858

Agnitum Outpost
Worm.Agent
7.1.1

Avira AntiVirus
Worm/Agent.15662
7.11.152.210

avast!
Win32:Mirc-Z [PUP]
2014.9-140929

Bitdefender
IRC-Worm.Generic.15662
1.0.20.1360

Dr.Web
Program.mIRC.60
9.0.1.0272

Emsisoft Anti-Malware
IRC-Worm.Generic.15662
8.14.09.29.12

F-Secure
IRC-Worm.Generic.15662
11.2014-29-09_2

G Data
IRC-Worm.Generic.15662
14.9.24

IKARUS anti.virus
not-a-virus:Client-IRC.Win32.mIRC
t3scan.1.6.1.0

Kaspersky
not-a-virus:Client-IRC.Win32.mIRC
14.0.0.3177

McAfee
Artemis!11F022DDE69F
5600.6992

MicroWorld eScan
IRC-Worm.Generic.15662
15.0.0.816

NANO AntiVirus
Riskware.Win32.MIRC.kimgo
0.28.0.60100

Norman
Suspicious_Gen2.UWKPB
11.20140929

nProtect
IRC-Worm.Generic.15662
14.06.03.01

Panda Antivirus
Trj/CI.A
14.09.29.12

Qihoo 360 Security
Win32/Virus.IRC.43b
1.0.0.1015

Quick Heal
Client-IRC.mIRC.g4 (Not a Virus)
9.14.14.00

VIPRE Antivirus
Trojan.Win32.Generic
29902

File size:
2 MB (2,084,864 bytes)

Product version:
6.2

Copyright:
Copyright © 1995-2006 mIRC Co. Ltd.

Trademarks:
mIRC® is a Registered Trademark of mIRC Co. Ltd.

Original file name:
mirc.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
7/29/2006 5:11:11 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.0

CTPH (ssdeep):
24576:bgRD6WLAdhW904DHn6Y6WiSvQQODd+UNw9cwFdwJEs+KetILNucBNFzPfDzAaygg:43FyOKetA9VzHad7tXT7

Entry address:
0x195E68

Entry point:
6A, 60, 68, 50, 5E, 5B, 00, E8, 54, 22, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 60, C7, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 64, 41, 5A, 00, 8B, 4E, 10, 89, 0D, 7C, 95, 60, 00, 8B, 46, 04, A3, 88, 95, 60, 00, 8B, 56, 08, 89, 15, 8C, 95, 60, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 80, 95, 60, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 80, 95, 60, 00, C1, E0, 08, 03, C2, A3, 84, 95, 60, 00, 33, F6, 56, 8B, 3D, C0, 42, 5A, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Entropy:
6.4917

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
1.6 MB (1,716,224 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP:
Connects to maki.mog422.net  (52.79.45.234:6664)

TCP (HTTP):
Connects to unknown.prolexic.com  (72.52.4.120:80)

Remove mirc.exe - Powered by Reason Core Security