viber.exe

The executable viber.exe has been detected as malware by 29 anti-virus scanners. While running, it connects to the Internet address ir2.fp.vip.ir2.yahoo.com on port 443.
MD5:
e880736cccc83bdf813664124c6fa79b

SHA-1:
6646841b9fb3f154bf5721a50b931e1b3125bd32

SHA-256:
c9e161391997f6ea2126483ea21b62abc41b192eb717f50d19a0e58461260395

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
5/22/2024 1:31:38 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win32/Brontok.worm.45551
2012.05.14

Avira AntiVirus
Worm/Brontok.D.3.A
7.11.29.212

avast!
Win32:Brontok-CE [Wrm]
2014.9-160914

AVG
I-Worm/Brontok.X
2017.0.2621

Bitdefender
Win32.Worm.Brontok.BP
1.0.20.1290

Clam AntiVirus
PUA.Packed.MEW-1
0.98/18155

Comodo Security
Packed.Win32.Packer.~GEN
12315

Dr.Web
BackDoor.Generic.3162
9.0.1.0258

Emsisoft Anti-Malware
Email-Worm.Win32.Brontok!IK
8.16.09.14.11

ESET NOD32
Win32/Brontok.CM worm
6.3.12010.0

F-Prot
W32/Brontok.AC@mm
v6.4.6.5.141

F-Secure
Win32.Worm.Brontok.BP
11.2016-14-09_4

G Data
Win32.Worm.Brontok.BP
16.9.22

IKARUS anti.virus
Email-Worm.Win32.Brontok
t3scan.1.1.118.0

K7 AntiVirus
EmailWorm
13.138.6854

Kaspersky
Email-Worm.Win32.Brontok
14.0.0.-402

McAfee
W32/Rontokbro.gen@MM
5600.6277

Microsoft Security Essentials
Worm:Win32/Brontok.N@mm
1.163.1557.0

Norman
W32/Rontokbro
11.20160914

nProtect
Win32.Worm.Brontok.BP
12.05.12.01

Panda Antivirus
W32/Brontok.O.worm
16.09.14.11

Quick Heal
W32.Brontok.Q
9.16.12.00

Rising Antivirus
Trojan.Win32.Mnless.dyr
23.00.65.16912

Sophos
W32/Brontok-K
4.77

SUPERAntiSpyware
Trojan.Agent/Gen-FakeSec
8898

Trend Micro House Call
WORM_RONTKBR.GEN
7.2.258

Trend Micro
WORM_RONTKBR.GEN
10.465.14

Vba32 AntiVirus
Email-Worm.Win32.Brontok.q
3.12.16.4

VIPRE Antivirus
Email-Worm.Win32.Brontok.ik
11914

File size:
44.5 KB (45,551 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\viber\viber.exe

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
768:YAJX/e2Ibr9dp1uUeEunVruxS+r/GiNfdzHToJAsv35BMCx:nJPSr9d7uvEusjGiN1zHs5l

Entry address:
0x32FD6

Entry point:
E9, 79, D1, FC, FF, 0C, 80, 02, 00, 00, 00, 00, 00, 00, 00, 00, 00, AD, 2F, 03, 00, 0C, 80, 02, 00...
 
[+]

Entropy:
7.3453

Packer / compiler:
RLPack FullEdition V1.1X

Code size:
512 Bytes (512 bytes)

Windows Firewall Allowed Program
Name:
viber


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to ats.sbs.vip.dc11.lumsb.com  (8.12.146.61:443)

TCP (HTTP SSL):
Connects to ir2.fp.vip.bf1.yahoo.com  (98.139.183.24:443)

TCP (HTTP SSL):
Connects to ir2.fp.vip.ir2.yahoo.com  (46.228.47.114:443)

TCP (HTTP SSL):
Connects to ir1.fp.vip.ir2.yahoo.com  (46.228.47.115:443)

TCP (HTTP):
Connects to unknown.prolexic.com  (72.52.4.121:80)

Remove viber.exe - Powered by Reason Core Security