winplus.exe

X2Net DEMO Certificate Only

The executable winplus.exe has been detected as malware by 5 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘WinPlus’.
Publisher:
X2Net DEMO Certificate Only  (signed and verified)

MD5:
7cd43f76fb713368165bab944d2baa50

SHA-1:
9eef66467d59258476691892035c8cd86bc66114

SHA-256:
35977fa429c18f5beaf20c639e17597417cb68340e8f4ff95a8c6c0ab9b58126

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
4/26/2024 10:51:58 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160917-0

Clam AntiVirus
Win.Trojan.Agent-345114
0.98/23166

Dr.Web
Trojan.Belanit.3
9.0.1.05190

ESET NOD32
Win32/TrojanDownloader.Delf.QXP trojan
6.3.12010.0

F-Secure
Variant.Zusy.651
5.16.24

File size:
918.8 KB (940,888 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\winplus.exe

Digital Signature
Authority:
X2Net TESTING ROOT ONLY

Valid from:
10/19/2006 8:13:09 PM

Valid to:
1/1/2040 5:29:59 AM

Subject:
CN=X2Net DEMO Certificate Only

Issuer:
CN=X2Net TESTING ROOT ONLY

Serial number:
61E959FDE00323BA432CEDA6EA0DD16B

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x21BB

Entry point:
68, 00, 10, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 83, C4, 08, E9, 87, A9, 3F, 00, 4B, D0, D4, FB, 4D, 78, F5, EC, 68, 64, 46, 13, 80, 8F, FC, 26, B1, B4, 0A, 7F, D4, 6D, C5, 7A, FC, 00, 0C, 9B, 53, 7F, 47, 99, E5, 35, D7, 9E, A6, 32, B3, F4, 76, 16, C0, 80, F6, 6D, 4C, 93, A9, 50, 81, 1A, A1, 7F, 3F, D5, C4, DA, A1, B1, D1, 05, 6A, 00, B7, 88, 98, A2, FD, F5, 31, D7, DA, 61, E9, AD, AE, 6F, 2B, 60, E7, 78, 10, BC, 88, 7E, CC, A9, 05, A3, 1C, A2, F4, DA, CE, 19, 0F, 22...
 
[+]

Entropy:
7.9515

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
553.5 KB (566,784 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WinPlus

Command:
C:\users\{user}\appdata\local\temp\winplus.exe


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):

Remove winplus.exe - Powered by Reason Core Security