winactive.exe

X2Net DEMO Certificate Only

The executable winactive.exe has been detected as malware by 29 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘WinActive’.
Publisher:
X2Net DEMO Certificate Only  (signed and verified)

MD5:
d1a65cef26d41c01dd11fc9ae13d65f5

SHA-1:
2f7aabf5a287adbc6dc4ddc0346ea6a7074aa744

SHA-256:
693bbc14dc896c16c1a72b1eae876b4571d2f52213d33690d490ce22966b0dc0

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
4/26/2024 6:15:39 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.DL.Delf
7.1.1

AhnLab V3 Security
Trojan/Win32.Scar
2013.08.20

Avira AntiVirus
TR/Belanit.A.10
7.11.97.100

avast!
Win32:Spyware-gen [Spy]
2014.9-160212

AVG
Agent.6
2017.0.2835

Bitdefender
Trojan.Generic.7178678
1.0.20.215

Comodo Security
Heur.Suspicious
16795

Dr.Web
Trojan.Belanit.2
9.0.1.043

Emsisoft Anti-Malware
Trojan.Generic.7178678
8.16.02.12.09

ESET NOD32
Win32/TrojanDownloader.Delf.QXP
10.8706

F-Prot
W32/Delf.BT.gen
v6.4.7.1.166

F-Secure
Trojan.Generic.7178678
11.2016-12-02_6

G Data
Trojan.Generic.7178678
16.2.22

IKARUS anti.virus
Trojan.Win32.Belanit
t3scan.2.0.127

K7 AntiVirus
Riskware
13.170.9324

Kaspersky
Trojan.Win32.Scar
14.0.0.671

McAfee
Artemis!D1A65CEF26D4
5600.6491

Microsoft Security Essentials
Trojan:Win32/Belanit.A
1.163.1557.0

MicroWorld eScan
Trojan.Generic.7178678
17.0.0.129

NANO AntiVirus
Trojan.Win32.Scar.jbpns
0.26.0.53954

Norman
Suspicious_Gen4.CWKG
11.20160212

Panda Antivirus
Trj/Genetic.gen
16.02.12.09

Sophos
Mal/Belanit-A
4.91

Total Defense
Win32/Belanit.F
37.0.10498

Trend Micro House Call
TROJ_GEN.R4FH1C3
7.2.43

Trend Micro
TROJ_GEN.R0CBC0EGQ13
10.465.12

Vba32 AntiVirus
Trojan.Scar
3.12.22.3

VIPRE Antivirus
Trojan.Win32.Generic
20692

ViRobot
Trojan.Win32.A.Scar.940612
2011.4.7.4223

File size:
918.8 KB (940,888 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\winactive.exe

Digital Signature
Authority:
X2Net TESTING ROOT ONLY

Valid from:
10/19/2006 8:13:09 PM

Valid to:
1/1/2040 5:29:59 AM

Subject:
CN=X2Net DEMO Certificate Only

Issuer:
CN=X2Net TESTING ROOT ONLY

Serial number:
61E959FDE00323BA432CEDA6EA0DD16B

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:vrQXYnC1XxGgi4ktemhd0d8pWR7er9r+KiXTp:vrQ8vh7hdk8pWRK1iX

Entry address:
0x23D6

Entry point:
68, 00, 10, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 83, C4, 08, E9, 38, A7, 3F, 00, 89, 30, 60, 6A, 9B, 15, 30, A4, 15, 5E, 52, E7, 9B, 78, AA, 7B, 50, C2, CC, EF, 3B, 1A, 28, 69, 92, 01, 88, 63, 6B, 35, A6, 87, E9, 03, 3B, 40, 0E, 87, D8, A4, 8C, A6, C0, 68, 8F, 4B, EC, FD, DB, 27, 2E, 5B, 19, 66, ED, 69, 1B, EC, 94, E0, 9C, A5, 35, 1A, 2E, 29, 8D, A3, 51, A4, 71, FA, 92, 68, 8D, FE, FD, 0E, 80, 43, 0A, 2D, 0F, 35, 70, 1A, 4E, D2, 40, 7B, BB, DF, C3, 35, 10, 6F, DD, 70...
 
[+]

Entropy:
7.9514

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
553.5 KB (566,784 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WinActive

Command:
C:\users\{user}\appdata\local\temp\winactive.exe


Remove winactive.exe - Powered by Reason Core Security