ntwk.exe

ERCAN PİRALİ

The executable ntwk.exe has been detected as malware by 10 anti-virus scanners. It runs as a windows Service named “Windows Net Work System Updater”.
Publisher:
ERCAN PİRALİ  (signed and verified)

MD5:
35abfd69dfd07559c17adcf2040f1790

SHA-1:
527b8815774f4feb9f60b60d751a1b0df9b47377

SHA-256:
ed2a38d8db4c068414133716a0726bcbeff993cfd3e87f9fa432d88787299503

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
5/8/2024 7:38:12 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.87252
605

Bitdefender
Gen:Variant.Strictor.87252
1.0.20.800

Emsisoft Anti-Malware
Gen:Variant.Strictor.87252
8.15.06.09.05

F-Secure
Gen:Variant.Strictor.87252
11.2015-09-06_3

G Data
Gen:Variant.Strictor.87252
15.6.25

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.9.2.0

McAfee
Artemis!35ABFD69DFD0
5600.6739

MicroWorld eScan
Gen:Variant.Strictor.87252
16.0.0.480

Trend Micro House Call
TROJ_GEN.R047H09EQ15
7.2.160

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
561.4 KB (574,848 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\locallow\microsoft\windows\ntwk.exe

Digital Signature
Signed by:

Authority:
E-Tuğra EBG Bilişim Teknolojileri ve Hizmetleri A.Ş.

Valid from:
4/13/2015 3:20:00 PM

Valid to:
4/13/2016 3:20:00 PM

Subject:
CN=ERCAN PİRALİ, SERIALNUMBER=13642979450, O=ERCAN PİRALİ, L=SAMSUN, S=SAMSUN, C=TR

Issuer:
CN=E-Tugra Organization Validated CA, OU=E-Tuğra Sertifikasyon Merkezi, O=E-Tuğra EBG Bilişim Teknolojileri ve Hizmetleri A.Ş., L=Ankara, C=TR

Serial number:
00BFFFA4B6693604

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:bWI7A//SazER6wqoD9qaVzj1k1qCUKZiv/Y:bP7RazER6wq1aV9kQEYvg

Entry address:
0x766BC

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 54, 63, 47, 00, E8, FF, 00, F9, FF, A1, 4C, 8B, 47, 00, 8B, 00, 8B, 10, FF, 52, 34, 8B, 0D, C8, 8D, 47, 00, A1, 4C, 8B, 47, 00, 8B, 00, 8B, 15, 38, 5C, 47, 00, 8B, 18, FF, 53, 30, A1, 4C, 8B, 47, 00, 8B, 00, 8B, 10, FF, 52, 38, 5B, E8, A1, DC, F8, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
470 KB (481,280 bytes)

Service
Display name:
Windows Net Work System Updater

Service name:
ntwk

Type:
Win32OwnProcess, InteractiveProcess


Remove ntwk.exe - Powered by Reason Core Security