Rc7.exe

The executable Rc7.exe has been detected as malware by 12 anti-virus scanners. While running, it connects to the Internet address xo5.x10hosting.com on port 80 using the HTTP protocol.
Version:
0.0.0.0

MD5:
e8964cfac5f74aaebd12126c09241a15

SHA-1:
2f0b326b905e22cdef14983ab05444f70d35961f

SHA-256:
fe76bd2b8175fc903bc8ece8d9fe32df27106e5b1bc058386b4d1551e1130804

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
7/2/2025 11:37:22 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.MSILKrypt.19
-28

Avira AntiVirus
TR/Dropper.Gen
8.3.3.4

Arcabit
Trojan.MSILKrypt.19
1.0.0.795

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.1734

Bitdefender
Gen:Variant.MSILKrypt.19
1.0.20.315

Emsisoft Anti-Malware
Gen:Variant.MSILKrypt.19
8.17.03.04.11

ESET NOD32
MSIL/Agent.RRQ (variant)
11.15029

F-Secure
Gen:Variant.MSILKrypt.19
11.2017-04-03_7

G Data
Gen:Variant.MSILKrypt.19
17.3.25

K7 AntiVirus
Trojan
13.10.3.22613

MicroWorld eScan
Gen:Variant.MSILKrypt.19
18.0.0.189

Qihoo 360 Security
HEUR/QVM03.0.0000.Malware.Gen
1.0.0.1120

File size:
2.2 MB (2,309,120 bytes)

Product version:
0.0.0.0

Original file name:
Rc7.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
3/3/2017 11:07:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x2083E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
0.6941

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
122.5 KB (125,440 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to xo5.x10hosting.com  (198.91.81.6:80)

Remove Rc7.exe - Powered by Reason Core Security