winseven.exe

The executable winseven.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘WinShell’. While running, it connects to the Internet address host176.b5.trdns.com on port 80 using the HTTP protocol.
MD5:
c9b366e52880c33e28ce7fd72f80dd2f

SHA-1:
2aefe5d9e1841ac3799744e60f1c4d6fd08e500a

SHA-256:
90028416e485774f2e9dd8ed3c59b883b7e42189d4afbb0ff979d2f385d87aa6

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/21/2025 12:33:19 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Trojan.Agent.Bibin
17.2.20.5

File size:
117.7 KB (120,507 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
11/22/2012 6:46:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

Entry address:
0x1240

Entry point:
87, FB, 30, D6, 13, CE, 0F, AF, C1, 80, CE, 4B, BA, E9, 7A, 2D, 4E, FF, CD, 8D, 35, 0E, FF, 8A, 69, 8B, EA, B8, 7D, 0E, F8, 1C, 01, DD, 0F, AF, FF, 80, F6, 32, C6, C5, EE, 43, E8, 00, 00, 00, 00, 59, 8A, D7, 85, C0, 8A, D9, 0B, F8, 46, 89, DF, 21, CA, 8B, D7, 0F, AF, DE, F2, 09, DF, 85, FB, 74, 04, 88, D7, 00, D3, F7, C3, 73, 8A, B5, 9A, 0F, BE, F2, 8D, 05, 1B, 54, 74, D9, 0F, AF, EB, 81, E6, 5C, C8, BC, 37, 6B, D2, 00, 86, F8, B4, 0E, 81, F2, BD, 72, 00, 00, 81, FA, 1A, 6F, 00, 00, 78, 07, F3, 69, C6, 0F...
 
[+]

Entropy:
7.0266

Code size:
5 KB (5,120 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WinShell

Command:
C:\winshell\winseven.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to win15.securedc.com  (64.8.117.67:80)

TCP (HTTP):
Connects to host176.b5.trdns.com  (77.245.148.176:80)

Remove winseven.exe - Powered by Reason Core Security