winentry.exe

X2Net DEMO Certificate Only

The executable winentry.exe has been detected as malware by 29 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘WinEntry’.
Publisher:
X2Net DEMO Certificate Only  (signed and verified)

MD5:
4a71caf4fe9edf787481d3d7ca5d5ee1

SHA-1:
d149c62554c7c988f84b67c070b0b0144d8ba97c

SHA-256:
3425bb91bae13cd41a1695919b9be51208527b02708aeb91a1835384118b936e

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
4/19/2024 4:15:38 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
TrojanSpy.Agent
7.1.1

AhnLab V3 Security
Trojan/Win32.Scar
2013.08.11

Avira AntiVirus
TR/Spy.940888
7.11.96.74

avast!
Win32:Kryptik-GWR [Trj]
2014.9-170305

AVG
Agent.6
2018.0.2449

Bitdefender
Gen:Variant.Zusy.651
1.0.20.320

Comodo Security
UnclassifiedMalware
16743

Dr.Web
Trojan.Belanit.2
9.0.1.064

Emsisoft Anti-Malware
Gen:Variant.Zusy.651
8.17.03.05.03

ESET NOD32
Win32/TrojanDownloader.Delf.QXP (variant)
11.8673

F-Prot
W32/Delf.BT.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Zusy.651
11.2017-05-03_1

G Data
Gen:Variant.Zusy.651
17.3.22

IKARUS anti.virus
Trojan.Win32.Belanit
t3scan.2.0.127

K7 AntiVirus
Riskware
13.170.9241

Kaspersky
Trojan.Win32.Scar
14.0.0.-1261

McAfee
Artemis!4A71CAF4FE9E
5600.6105

Microsoft Security Essentials
Trojan:Win32/Belanit.A
1.163.1557.0

MicroWorld eScan
Gen:Variant.Zusy.651
18.0.0.192

NANO AntiVirus
Trojan.Win32.Scar.jeswr
0.26.0.53954

Norman
Malware.XJFZ
11.20170305

Panda Antivirus
Trj/Genetic.gen
17.03.05.03

Quick Heal
Trojan.Scar.fvmm
3.17.12.00

Total Defense
Win32/Belanit.F
37.0.10498

Trend Micro House Call
TROJ_GEN.R4FH1CK
7.2.64

Trend Micro
TROJ_SPNR.0BCL12
10.465.05

Vba32 AntiVirus
Trojan.Scar
3.12.22.3

VIPRE Antivirus
Trojan.Win32.Generic
20370

ViRobot
Trojan.Win32.A.Scar.940888.C
2011.4.7.4223

File size:
918.8 KB (940,888 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\winentry.exe

Digital Signature
Authority:
X2Net TESTING ROOT ONLY

Valid from:
10/19/2006 8:13:09 PM

Valid to:
1/1/2040 5:29:59 AM

Subject:
CN=X2Net DEMO Certificate Only

Issuer:
CN=X2Net TESTING ROOT ONLY

Serial number:
61E959FDE00323BA432CEDA6EA0DD16B

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0xFD7E

Entry point:
68, 00, 10, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 83, C4, 08, E9, 94, CE, 3E, 00, E1, 9B, 98, 68, 93, 35, BC, 65, 70, 49, B5, F9, C5, 25, 62, 22, ED, 19, BB, FF, A4, 11, 80, D1, 80, AF, 95, 8E, AC, F8, 41, 7C, DD, 88, CB, FC, 8D, 33, C3, 80, 48, 99, B9, 9C, E4, 58, D2, 22, 0B, D9, B5, 02, F1, D6, 5B, 88, BE, EE, 65, 69, C3, FA, 6A, 13, 7C, E9, 9D, 94, 83, FD, A5, FB, 39, 8E, 74, 67, 92, 67, 11, 54, 7A, 2E, A7, D6, 33, 5F, D9, D1, C0, C3, 3E, CE, 14, 6E, D0, 6B, F4, D9...
 
[+]

Entropy:
7.9525

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
553.5 KB (566,784 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WinEntry

Command:
C:\users\{user}\appdata\local\temp\winentry.exe


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):

Remove winentry.exe - Powered by Reason Core Security