passwords.exe

The executable passwords.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Backup’.
MD5:
7fd5a614aadbdaf79fe5c886c1f6ce84

SHA-1:
60d47fa653bc51c585676bb294146613d484228b

SHA-256:
8555f218615e6b74eb367162919cb9cd3d05c2ef4263ed261aeed35383364318

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/21/2025 12:34:31 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Trojan.FakeBackup (M)
16.9.7.16

File size:
488 KB (499,712 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
7/21/1998 3:25:50 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:m9k0lrTR4HeK6xcws9XwM3Woel8oBS5XvGJrbSEl7Y96VtxY:jYsjR42m+XvUbSpGtx

Entry address:
0x79668

Entry point:
83, 3C, 24, FE, 77, FE, 8D, 64, 24, CC, 60, 83, EC, DC, E8, 1E, 02, 00, 00, 4B, 66, 4B, 75, FC, 80, D2, 8E, F9, FF, 73, 3C, 59, 81, E9, FD, FF, FF, 7F, E9, 2D, 02, 00, 00, 1B, C0, 6A, F4, 69, D0, B3, 24, A9, CF, 18, B5, 38, 00, 00, 00, 5F, 8D, BF, D5, 99, FF, FF, FF, B5, 36, 02, 00, 00, 03, FD, 5A, C3, BA, 01, 00, 00, 8B, FF, E9, 85, 99, FF, FF, 8B, 7C, 24, 4C, 6A, 08, 54, FF, D7, FF, 54, 24, 50, FE, 0C, 24, 75, F2, F7, D1, 28, F2, 58, 6A, 01, E8, 9C, 00, 00, 00, C7, 46, 14, 0C, 00, 00, 00, 8F, 46, 1C, 8D...
 
[+]

Entropy:
5.8585

Code size:
36 KB (36,864 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Backup

Command:
C:\backup.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to win15.securedc.com  (64.8.117.67:80)

TCP (HTTP):
Connects to host176.b5.trdns.com  (77.245.148.176:80)

TCP (HTTP):
Connects to HDRedirect-LB3-890977680.us-east-1.elb.amazonaws.com  (68.168.222.206:80)

TCP (HTTP):

TCP (HTTP):
Connects to email.interbox.cz  (77.78.99.55:80)

Remove passwords.exe - Powered by Reason Core Security