webshot.exe

WebShot

Nathan Moinvaziri

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.websitescreenshots.com.
Publisher:
Nathan Moinvaziri

Product:
WebShot

Version:
1.9.3.0

MD5:
74de68adbab1deac57e003c2b95fb267

SHA-1:
c3bacce89c1bd8107a8c1c95a29160e220bc6501

SHA-256:
5811992d38329316c51a14cbdd98310dfdac2db0840170fd7767e10cc2cc94c0

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/19/2024 7:01:25 PM UTC  (today)

Scan engine
Detection
Engine version

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
17.8 MB (18,670,407 bytes)

Product version:
1.9.3.0

Copyright:
Nathan Moinvaziri

Original file name:
webshot.exe

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\webshot.exe.part

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:FAj3HVhkMAly1oO1bWTmZFuxipCmMR6LllLzkjcxj9h6h8BmOVsV/m:GzkMAlgoBipqARlHkjcxn6h8Bbmm

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9971

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file webshot.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 11.81.36a9.ip4.static.sl-reverse.com  (169.54.129.17:80)

Scan webshot.exe - Powered by Reason Core Security