rc7.exe

The executable rc7.exe has been detected as malware by 15 anti-virus scanners. While running, it connects to the Internet address xo5.x10hosting.com on port 80 using the HTTP protocol.
Version:
0.0.0.0

MD5:
8ab5f1cb3caf51cfca336a9225770265

SHA-1:
39457696ca796b2aa78a092115b1f09e336b9dc2

SHA-256:
c8f7787e3b5378b2d0663b1f6e96bac10b3145a0a1c39775f197703ae39f86a9

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
7/2/2025 11:52:05 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.MSILKrypt.19
-29

Avira AntiVirus
TR/Dropper.Gen
8.3.3.4

Arcabit
Trojan.MSILKrypt.19
1.0.0.795

avast!
Win32:Malware-gen
2014.9-170305

AVG
MSIL11
2018.0.2449

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.1735

Bitdefender
Gen:Variant.MSILKrypt.19
1.0.20.320

Emsisoft Anti-Malware
Gen:Variant.MSILKrypt.19
8.17.03.05.06

ESET NOD32
MSIL/Agent.RRQ (variant)
11.15031

F-Secure
Gen:Variant.MSILKrypt.19
11.2017-05-03_1

G Data
Gen:Variant.MSILKrypt.19
17.3.25

K7 AntiVirus
Trojan
13.10.3.22613

McAfee
Artemis!8AB5F1CB3CAF
5600.6105

MicroWorld eScan
Gen:Variant.MSILKrypt.19
18.0.0.192

Qihoo 360 Security
HEUR/QVM03.0.0000.Malware.Gen
1.0.0.1120

File size:
2.2 MB (2,309,120 bytes)

Product version:
0.0.0.0

Original file name:
rc7.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\rc7.exe

File PE Metadata
Compilation timestamp:
3/4/2017 2:03:29 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x2080E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
122.5 KB (125,440 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to xo5.x10hosting.com  (198.91.81.6:80)

Remove rc7.exe - Powered by Reason Core Security