wconnect.exe

Winconnection 4

Winco Tecnologia e Sistemas LTDA

It runs as a separate (within the context of its own process) windows Service named “Winconnection V4.7”.
Publisher:
Winco Sistemas  (signed by Winco Tecnologia e Sistemas LTDA)

Product:
Winconnection 4

Description:
Servidor Winconnection

Version:
4.7.0.0

MD5:
56cf30383269c06d3896b1d9b14f1051

SHA-1:
043618e3722e372b695de0cee0f9334e2399138d

SHA-256:
9b4d7ef82d2bbeefb8f8cbb7aed2cc99cdd0ea3f4d1db112fcf01a63c822fa40

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/18/2024 6:16:43 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
BACKDOOR.Trojan
9.0.1.0332

File size:
1.2 MB (1,218,480 bytes)

Product version:
4.7.0.0

Copyright:
Copyright (C) 2008 - Winco Sistemas

Original file name:
wconnect.exe

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\Program Files\winco\winconnection4\wconnect.exe

Digital Signature
Authority:
VeriSign, Inc.

Subject:
CN=Winco Tecnologia e Sistemas LTDA, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Winco Tecnologia e Sistemas LTDA, L=Rio de Janeiro, S=Rio de Janeiro, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1051A128EAB42B5BE56FF92B74EF3857

File PE Metadata
Compilation timestamp:
5/25/2010 3:08:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
24576:zaSsXpqf6PJl9hCbBsmv7R5v7UWsSPdI45munKcPtTtaKS:KmdVdI45my7aKS

Entry address:
0xAC541

Entry point:
E8, 11, F9, 00, 00, E9, 40, FE, FF, FF, CC, CC, CC, CC, CC, 3B, C1, 56, 8B, F2, 74, 1F, 85, F6, 74, 1B, 53, 8D, 64, 24, 00, 8A, 19, 8A, 10, 88, 18, 83, EE, 01, 88, 11, 83, C0, 01, 83, C1, 01, 85, F6, 75, EB, 5B, 5E, C3, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, 55, 8B, 6C, 24, 0C, 3B, E9, 76, 78, 53, 8B, 5C, 24, 14, 56, 8D, 04, 19, 57, 89, 44, 24, 18, EB, 03, 8D, 49, 00, 8B, 74, 24, 18, 3B, F5, 8B, F9, 77, 1F, 8D, 9B, 00, 00, 00, 00, 57, 56, FF, 54, 24, 28, 83, C4, 08, 85, C0, 7E, 02, 8B, FE, 03, F3...
 
[+]

Code size:
964 KB (987,136 bytes)

Service
Display name:
Winconnection V4.7

Service name:
Winconnection4

Type:
Win32OwnProcess


Scan wconnect.exe - Powered by Reason Core Security