dotnetfx.exe

.Net Framework 1.1 SP1 ESN + Updates

Windows uE

The executable dotnetfx.exe, “.Net Framework 1.1” has been detected as malware by 3 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dantha300.com.
Publisher:
Windows uE

Product:
.Net Framework 1.1 SP1 ESN + Updates

Description:
.Net Framework 1.1

Version:
1, 1, 1, 3

MD5:
0534bdbed2d97b68c2b0ec28fe215aff

SHA-1:
c37bf3c4d2b12dcfac19f4725d63bbd6e8faba4e

SHA-256:
34e7c18bb8af9815c5128d5425d9bfe467b3932dbfb56ff1ca9168690ee77e82

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
10/11/2025 5:20:26 PM UTC  (today)

Scan engine
Detection
Engine version

F-Prot
W32/MalwareS.ACEQ
v6.4.7.1.166

Malwarebytes
Trojan.Dropped
v2014.08.10.11

ViRobot
Trojan.Win32.Buzus.147456.N
2011.4.7.4223

File size:
11.5 MB (12,054,095 bytes)

Product version:
1, 1, 1, 3

Copyright:
Copyright (C) 2007 WinuE

Original file name:
dotnetfx.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
3/6/2005 8:06:25 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
196608:x6PQndAuab6lfYmVNWLb4LGtF1CFo1Yn4PuyTRtbWIgkjQQFIFjmzg196xQbpH49:xwkCN2fYYWIKC6O4PuiWkjoj8wO9

Entry address:
0x11D36

Entry point:
6A, 60, 68, E8, 8B, 41, 00, E8, 4E, 03, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 62, FF, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 70, 81, 41, 00, 8B, 4E, 10, 89, 0D, 48, E1, 41, 00, 8B, 46, 04, A3, 54, E1, 41, 00, 8B, 56, 08, 89, 15, 58, E1, 41, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 4C, E1, 41, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 4C, E1, 41, 00, C1, E0, 08, 03, C2, A3, 50, E1, 41, 00, 33, F6, 56, 8B, 3D, 64, 81, 41, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
92 KB (94,208 bytes)

The file dotnetfx.exe has been seen being distributed by the following URL.

Remove dotnetfx.exe - Powered by Reason Core Security