sevenkingdomsiisetup-dm.exe

The executable sevenkingdomsiisetup-dm.exe has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from files.downloadnow.com. While running, it connects to the Internet address 195.34.13.149.zylom.net on port 80 using the HTTP protocol.
MD5:
6ca9de9806c9f2a93bf9a2cbd946540d

SHA-1:
2b2dee3789755ccd5bbaf7372fb720b2ad1106e6

SHA-256:
2f8ba055729bf4606719cf74e8e3a2a4ed1b784c7f0a32ee56d24db2d6ae6afd

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
4/25/2024 12:25:01 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.2.15.5

File size:
208 KB (212,992 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\sevenkingdomsiisetup-dm.exe

File PE Metadata
Compilation timestamp:
4/19/2005 1:17:43 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:4to2HyJt6oobhLgaMCLgfl8wofyNqPcJCXTrJroZVGv9fKZ+3jnHo3hQ1bWpbT6j:4PHy/6TyaMCLgt8ty0OYlu7GE9o

Entry address:
0x1079D

Entry point:
55, 8B, EC, 6A, FF, 68, 58, 8B, 41, 00, 68, 4C, FD, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, B8, 80, 41, 00, 33, D2, 8A, D4, 89, 15, 84, FC, 41, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 80, FC, 41, 00, C1, E1, 08, 03, CA, 89, 0D, 7C, FC, 41, 00, C1, E8, 10, A3, 78, FC, 41, 00, 6A, 01, E8, 73, 0F, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 3F, 0B, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
84.5 KB (86,528 bytes)

The file sevenkingdomsiisetup-dm.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 195.34.13.149.zylom.net  (149.13.34.195:80)

Remove sevenkingdomsiisetup-dm.exe - Powered by Reason Core Security