vkontaktedj.exe

VKontakte DJ

The executable vkontaktedj.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘VkontakteDJ’. This file is typically installed with the program Vkontakte DJ by VkontakteDJ. While running, it connects to the Internet address static.87.54.243.136.clients.your-server.de on port 80 using the HTTP protocol.
Product:
VKontakte DJ

Description:
VKDJ, Player

Version:
3.79.0.0

MD5:
48e1e06a0f053face321efb69182f799

SHA-1:
7e7b0326a728da718d19d223fb58bd6169efd6bf

SHA-256:
5064197673475282c26aa5b84bb6ecd6dfd4536a40051e23213b8a582e844263

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
5/4/2024 2:01:11 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
17.3.3.10

File size:
4.9 MB (5,189,632 bytes)

Product version:
3.79

Copyright:
Copyright (C) 2008. All rights reserved.

Original file name:
VKontakte-DJ.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\vkontaktedj\vkontaktedj.exe

File PE Metadata
Compilation timestamp:
6/20/1992 3:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x26795C

Entry point:
55, 8B, EC, 83, C4, EC, 53, 56, 57, 33, C0, 89, 45, EC, B8, 0C, 6E, 66, 00, E8, FC, FD, D9, FF, 33, C0, 55, 68, 26, 7A, 66, 00, 64, FF, 30, 64, 89, 20, E8, F5, EC, FF, FF, 33, C0, 55, 68, CE, 79, 66, 00, 64, FF, 30, 64, 89, 20, A1, C0, D7, 67, 00, 8B, 00, E8, F7, 9E, E0, FF, B9, 98, 0C, 68, 00, A1, C0, D7, 67, 00, 8B, 00, 8B, 15, 30, BE, 62, 00, E8, F8, 9E, E0, FF, A1, C0, D7, 67, 00, 8B, 00, E8, 6C, 9F, E0, FF, 33, C0, 5A, 59, 59, 64, 89, 10, EB, 30, E9, ED, CB, D9, FF, 01, 00, 00, 00, E8, 8C, 40, 00, DF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.4 MB (2,518,016 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
VkontakteDJ

Command:
C:\users\{user}\appdata\roaming\vkontaktedj\vkontaktedj.exe \h


The file vkontaktedj.exe has been discovered within the following program.

Vkontakte DJ  by VkontakteDJ
vkontakte.dj/about
45% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to h1net188-64-172-90.h1host.ru  (188.64.172.90:80)

TCP (HTTP):
Connects to static.228.51.243.136.clients.your-server.de  (136.243.51.228:80)

TCP (HTTP):
Connects to ip-static-94-242-214-18.server.lu  (94.242.214.18:80)

TCP (HTTP):
Connects to srv82-165-240-87.vk.com  (87.240.165.82:80)

TCP (HTTP):
Connects to static.87.54.243.136.clients.your-server.de  (136.243.54.87:80)

TCP (HTTP):
Connects to s2-db.nitralabs.com  (46.28.68.78:80)

TCP (HTTP):
Connects to ip-172-26-136-19.ec2.internal  (172.26.136.19:80)

Remove vkontaktedj.exe - Powered by Reason Core Security