winentry.exe

X2Net DEMO Certificate Only

The executable winentry.exe has been detected as malware by 28 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘WinEntry’.
Publisher:
X2Net DEMO Certificate Only  (signed and verified)

MD5:
5166d9aa7b41f254c42c6b85293d34ff

SHA-1:
4b1000474bab0f0a73f79e4990d0a26049e103a7

SHA-256:
e331113ff9cf2ed0f895bbd526aedc5fc1cfa42fe80f3ca6cc4eed0a5522924f

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/26/2024 7:23:08 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.DL.Delf
7.1.1

AhnLab V3 Security
Trojan/Win32.Scar
2013.08.17

Avira AntiVirus
TR/Belanit.A.9
7.11.97.22

avast!
Win32:Malware-gen
2014.9-160212

AVG
Agent.6
2017.0.2835

Bitdefender
Gen:Variant.Zusy.651
1.0.20.215

Comodo Security
Heur.Suspicious
16780

Dr.Web
Trojan.Belanit.2
9.0.1.043

Emsisoft Anti-Malware
Gen:Variant.Zusy.651
8.16.02.12.09

ESET NOD32
Win32/TrojanDownloader.Delf.QXP
10.8697

F-Prot
W32/Delf.BT.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Zusy.651
11.2016-12-02_6

G Data
Gen:Variant.Zusy.651
16.2.22

IKARUS anti.virus
Trojan.Win32.Belanit
t3scan.2.0.127

K7 AntiVirus
Trojan
13.170.9312

Kaspersky
Trojan.Win32.Scar
14.0.0.671

McAfee
Artemis!5166D9AA7B41
5600.6491

Microsoft Security Essentials
Trojan:Win32/Belanit.A
1.163.1557.0

NANO AntiVirus
Trojan.Win32.Scar.iaqjl
0.26.0.53954

Norman
Troj_Generic.IQZF
11.20160212

Panda Antivirus
Trj/Genetic.gen
16.02.12.09

Quick Heal
Trojan.Scar.fvte
2.16.12.00

Sophos
Mal/Belanit-A
4.91

Total Defense
Win32/Belanit.F
37.0.10498

Trend Micro House Call
TROJ_GEN.R4FH1BS
7.2.43

Trend Micro
TROJ_GEN.R0CBC0EFE13
10.465.12

Vba32 AntiVirus
Trojan.Scar
3.12.22.3

VIPRE Antivirus
Trojan.Win32.Generic
20592

File size:
918.8 KB (940,888 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\winentry.exe

Digital Signature
Authority:
X2Net TESTING ROOT ONLY

Valid from:
10/19/2006 8:13:09 PM

Valid to:
1/1/2040 5:29:59 AM

Subject:
CN=X2Net DEMO Certificate Only

Issuer:
CN=X2Net TESTING ROOT ONLY

Serial number:
61E959FDE00323BA432CEDA6EA0DD16B

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:TAFVTLRczusxlt4gz45I8jWtJ839U/4RUrqhykP6bVEGbMv1W5JGafTzMoT7s:T8+uCtB4ktf/XUP6bV89W5JGaXMYs

Entry address:
0x1486C

Entry point:
68, 00, 10, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 83, C4, 08, E9, 5E, 83, 3E, 00, 8E, 16, 00, B9, 37, 5A, B8, 0D, 54, A4, AE, A8, 65, EB, D4, C9, AE, B4, 2E, 6A, 29, 1A, F5, A9, B4, EC, 3E, 79, C2, C0, 01, C4, 27, 69, FE, DB, B1, A5, ED, 99, E7, 6C, BD, 00, B0, 66, 50, F0, EF, 32, 4B, 01, 7A, 13, FB, 0A, 53, 3F, 90, 94, 1F, E8, A1, F3, 94, 54, 04, 0C, 2A, E2, 1A, 29, 01, C4, 67, DB, 5E, FD, AE, 76, 1E, 0D, 39, 42, 51, 18, 5F, 8E, CB, E9, 47, 1D, CC, B7, 57, 07, 7F, 1E...
 
[+]

Entropy:
7.9519

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
553.5 KB (566,784 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WinEntry

Command:
C:\users\{user}\appdata\local\temp\winentry.exe


Remove winentry.exe - Powered by Reason Core Security