vcredistx86.exe

The executable vcredistx86.exe has been detected as malware by 18 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Microsoft visual C++ 2010’. While running, it connects to the Internet address ip234.208-100-26.static.steadfastdns.net on port 80 using the HTTP protocol.
MD5:
f8c601618ef455f47206d26d4439d187

SHA-1:
c9e1facae782a141be661b2605afdf29ec43a64c

Scanner detections:
18 / 68

Status:
Malware

Analysis date:
4/25/2024 7:31:26 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Blocker
2014.06.20

Avira AntiVirus
TR/Ransom.Blocker.enhb
7.11.155.200

avast!
Win32:Dropper-gen [Drp]
2014.9-141205

AVG
SHeur4
2015.0.3270

Baidu Antivirus
Trojan.Win32.CoinMiner
4.0.3.14125

Comodo Security
TrojWare.Win32.TrojanDownloader.Delf.gen
18599

Dr.Web
Trojan.MulDrop5.33052
9.0.1.0339

ESET NOD32
Win32/CoinMiner.QM
8.9970

F-Prot
W32/Trojan2.ODYO
v6.4.7.1.166

G Data
Win32.Trojan.Agent.9UY5YA
14.12.24

Kaspersky
Trojan-Ransom.Win32.Blocker
14.0.0.2845

McAfee
GenericR-AOW!F8C601618EF4
5600.6926

Panda Antivirus
Trj/OCJ.F
14.12.05.01

Qihoo 360 Security
Win32/Trojan.Ransom.be2
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Total Defense
Win32/Ransom.HMR
37.0.11009

Trend Micro House Call
TROJ_GEN.R002B01FI14
7.2.339

VIPRE Antivirus
Trojan.Win32.Generic
30462

File size:
7.9 MB (8,253,440 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Application data\vcredistx86.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:dh5il9Ei2p6dBpzNiRcX03Z82diUj/gOwHq40OMCchSjkh6M92t+HX0u7zAvovOz:piPppzoR1p82B/grK4YSWOkH4bWU1tJ

Entry address:
0x226D0

Entry point:
55, 8B, EC, 83, C4, F0, 33, C0, 89, 45, F0, B8, 28, 24, 42, 00, E8, 93, 28, FE, FF, 33, C0, 55, 68, 78, 27, 42, 00, 64, FF, 30, 64, 89, 20, 8D, 55, F0, B8, 01, 00, 00, 00, E8, 9C, 3A, FE, FF, 8B, 45, F0, BA, 8C, 27, 42, 00, E8, 7B, 0C, FE, FF, 75, 18, 6A, 00, 68, 90, 27, 42, 00, 68, 9C, 27, 42, 00, 6A, 00, E8, C2, 2B, FE, FF, E8, 99, 08, FE, FF, B2, 01, A1, C8, 06, 42, 00, E8, FD, DF, FF, FF, 8B, 15, 90, 35, 42, 00, 89, 02, A1, 90, 35, 42, 00, 8B, 00, 8B, 40, 04, E8, 62, 7B, FE, FF, A1, DC, 35, 42, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
134 KB (137,216 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Microsoft visual C++ 2010

Command:
C:\Documents and Settings\{user}\Application data\vcredistx86.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to anubisnetworks.com  (195.22.26.248:80)

TCP (HTTP):
Connects to ip234.208-100-26.static.steadfastdns.net  (208.100.26.234:80)

TCP (HTTP):
Connects to ip240.208-100-26.static.steadfastdns.net  (208.100.26.240:80)

TCP (HTTP):
Connects to beta.on-sys.net  (195.22.28.210:80)

Remove vcredistx86.exe - Powered by Reason Core Security