newhostcrypted.exe

{5A84487E-52EC-44FA-93C1-52C2DCFE2456}

The executable newhostcrypted.exe has been detected as malware by 13 anti-virus scanners.
Publisher:

MD5:
d26f21660e56337a439e10c06fe858e3

SHA-1:
ad339ffc14198d49fe76096db8b6a1ce70bfecc1

SHA-256:
62c5f758bf3d5da652691a6fc30304674b0aa5acfdf923082ea352eccdee8b3d

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
4/25/2024 8:57:57 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.MSIL.43675
7.11.154.86

avast!
Win32:Malware-gen
2014.9-170216

AVG
Zbot
2018.0.2466

ESET NOD32
MSIL/Injector.DJL (variant)
11.9926

Fortinet FortiGate
MSIL/Injector.DEN!tr
2/16/2017

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-1176

McAfee
PWSZbot-FXD!D26F21660E56
5600.6122

Panda Antivirus
Trj/OCJ.F
17.02.16.05

Qihoo 360 Security
Win32/Trojan.670
1.0.0.1015

Sophos
Mal/Cleaman-B
4.98

Trend Micro House Call
TROJ_GEN.R00JC0PFA14
7.2.47

Trend Micro
TROJ_GEN.R00JC0PFA14
10.465.16

VIPRE Antivirus
Trojan.MSIL.Injector.cvj
30178

File size:
1.1 MB (1,151,008 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\datawork\newhostcrypted.exe

Digital Signature
Authority:
{5A84487E-52EC-44FA-93C1-52C2DCFE2456}

Valid from:
4/10/2014 11:24:48 AM

Valid to:
4/10/2015 5:24:48 PM

Subject:
CN={5A84487E-52EC-44FA-93C1-52C2DCFE2456}

Issuer:
CN={5A84487E-52EC-44FA-93C1-52C2DCFE2456}

Serial number:
6DB8BC1AE91B0D9041D4181B8FB471D0

File PE Metadata
Compilation timestamp:
4/15/2014 5:46:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0xBFE2E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.1589

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
760 KB (778,240 bytes)

User Start Menu Item
Name:
newhostcrypted.exe


Remove newhostcrypted.exe - Powered by Reason Core Security