wcrash.exe

Cherbury

IKARUS Security Software GmbH

The executable wcrash.exe has been detected as malware by 1 anti-virus scanner. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in.
Publisher:
Truckload  (signed by IKARUS Security Software GmbH)

Product:
Cherbury

Description:
Sydney0

Version:
1.08.0009

MD5:
69dd5c6c1d7b0cb20f3ae8227790e02d

SHA-1:
f4e03eb6da0d6870921a93db24253dba1c773f64

SHA-256:
a64c93ac8c1a5327a1a02dbad1c31fef4d3a54499b19f18598edca90d5024043

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/5/2025 5:51:51 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.2.24.1

File size:
206.6 KB (211,536 bytes)

Product version:
1.08.0009

Copyright:
gimlets

Trademarks:
Chancre

Original file name:
Djagatay.exe

File type:
Executable application (Win32 EXE)

Language:
Albanian (Albania)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\wcrash.exe

Digital Signature
Authority:
StartCom Ltd.

Valid from:
8/13/2012 8:06:12 PM

Valid to:
8/15/2014 9:25:56 PM

Subject:
E=support@ikarus.at, CN=IKARUS Security Software GmbH, O=IKARUS Security Software GmbH, L=Wien, S=Wien, C=AT, Description=QgrbF2jp00Tp0hOn

Issuer:
CN=StartCom Class 3 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
06F1

File PE Metadata
Compilation timestamp:
12/20/2014 1:04:03 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:YT0gIO9tHeL4vlFX2nVYtBDCObwEKjaEsx7JdenqTPId3Fh37:YUO9kwlFqm/hbPBx9M2cX

Entry address:
0x1420

Entry point:
68, 38, 7C, 42, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, C5, 4B, E4, 28, 47, 99, BB, 4E, A1, 4D, 19, 1E, BF, 50, 25, 5F, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 31, 42, 2D, 41, 46, 43, 63, 6F, 70, 65, 6D, 69, 73, 68, 00, 41, 38, 44, 41, 37, 7D, 23, 00, 00, 00, 00, FF, CC, 31, 00, 05, 84, 02, F1, 44, 80, 65, 31, 4F, A4, 77, D9, 0F, 3B, 06, D5, 31, 2B, 18, 7B, BB, B4, 74, 64, 4C, A6, 0E, B8, D5, 17, EC, 50, 2A, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
7.5056

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
184 KB (188,416 bytes)

Scheduled Task
Task name:
Windows Update Check - 0x5F7B0788

Trigger:
Logon (Runs on logon)


Remove wcrash.exe - Powered by Reason Core Security