swk1as1gw95owe.exe

League of Legends Cache

Riot Games

The executable swk1as1gw95owe.exe has been detected as malware by 9 anti-virus scanners. While running, it connects to the Internet address mailrelay.203.website.ws on port 15000.
Publisher:
Riot Games

Product:
League of Legends Cache

Description:
LolCache

Version:
1.1.5.5

MD5:
16faebb5044f51ea785f410cc7c74f43

SHA-1:
3e2bea1b7674debdb0d5555e505a3337e9760127

SHA-256:
5571884d7cf88b3dafdf5fac2a4df021caa7297d91ca7cac4ab483b285050306

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
4/18/2024 8:51:23 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.MSIL.172943
8.3.1.6

avast!
Win32:Malware-gen
2014.9-150801

Baidu Antivirus
Hacktool.MSIL.Confuser
4.0.3.1581

ESET NOD32
MSIL/Packed.Confuser.J suspicious (variant)
9.11979

Fortinet FortiGate
Riskware/Flooder
8/1/2015

Kaspersky
HEUR:HackTool.MSIL.Flooder
14.0.0.1646

McAfee
Artemis!16FAEBB5044F
5600.6686

Panda Antivirus
Generic Suspicious
15.08.01.08

Qihoo 360 Security
Win32/Trojan.Flooder.211
1.0.0.1015

File size:
50 KB (51,200 bytes)

Product version:
1.1.5.5

Copyright:
Riot Games© 2015

Trademarks:
Riot Games™

Original file name:
LolCache.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\swk1as1gw95owe.exe

File PE Metadata
Compilation timestamp:
7/20/2015 11:45:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:DbCIw1hDFV4B2iw2Is3x3Uh0T8tFD8su+lm5ALJ0mBbH1eDMk:fCdjJVU7ww3BUmItFDrlmUJpbVeDMk

Entry address:
0xDB8E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.1685

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
47 KB (48,128 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP:
Connects to mailrelay.203.website.ws  (64.70.19.203:15000)

Remove swk1as1gw95owe.exe - Powered by Reason Core Security