msn.exe

The executable msn.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘apo5’. While running, it connects to the Internet address host176.b5.trdns.com on port 80 using the HTTP protocol.
MD5:
8be56205b3a3b6027463de0b684e29dd

SHA-1:
c401e95c379509ab064fc6dbad8460f52622e358

SHA-256:
6358fae9d01114415b6aee18caf8290ad25708a99ecb6b936a125c633b6aac59

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/21/2025 12:33:05 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Worm.Macoute (H)
17.3.2.10

File size:
484.5 KB (496,128 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
4/19/2006 11:29:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.20

Entry address:
0x12C0

Entry point:
60, 87, FA, 51, 0F, BF, F5, 4D, 0F, AF, FA, 8D, 35, 5E, B2, 16, 14, 88, D5, F6, C6, 59, B0, 07, F7, C6, E5, 99, 71, 11, 8D, 08, 11, C6, 78, 01, 42, 8B, D9, F7, C7, 00, 77, A2, D1, 81, CD, 04, 23, DC, 70, 75, 06, 8D, 3D, F0, 10, FF, 47, 80, FB, 7E, 0D, 5C, DA, 0D, 8D, 8B, CD, 04, 8C, 0C, 0E, 8D, 15, 15, B0, 39, 22, 8D, 3D, 92, 28, 7D, 45, E8, 52, 00, 00, 00, EB, 05, 28, EC, 0C, 14, F2, 4D, 4F, 75, 0C, F7, C0, FC, E4, 4D, 0C, F7, C2, B4, DB, 74, C3, 88, FB, F7, C5, D1, 21, 40, 93, 85, FF, 6A, 00, 58, 02, FC...
 
[+]

Code size:
232 KB (237,568 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
apo5

Command:
C:\win\msn.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to win15.securedc.com  (64.8.117.67:80)

TCP (HTTP):
Connects to host176.b5.trdns.com  (77.245.148.176:80)

Remove msn.exe - Powered by Reason Core Security