explorer.exe

The executable explorer.exe has been detected as malware by 3 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘d61f7fcf03ebfbca9c8260a6ac24371e’. Although this file uses the name explorer.exe, this is NOT the File Explorer program distributed with the Windows OS that is found in C:\Windows.
MD5:
2a8c00132d1f949b57c18cb2b81a4a3f

SHA-1:
8781706f100869bc4ab42f8a43fa9c5925f7950f

SHA-256:
59b013ac8c53a19e2dce1dc0b027e610de894663d1dfb1c133437c89be1aa609

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
5/2/2024 2:13:02 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Trojan.B-468
0.98/23209

Dr.Web
BackDoor.Bladabindi.13678
9.0.1.05190

ESET NOD32
MSIL/Bladabindi.BC trojan
6.3.12010.0

File size:
23.5 KB (24,064 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\explorer.exe

File PE Metadata
Compilation timestamp:
3/15/2017 10:34:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x747E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
21.5 KB (22,016 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
d61f7fcf03ebfbca9c8260a6ac24371e

Command:
"C:\users\{user}\appdata\local\temp\explorer.exe"..


Remove explorer.exe - Powered by Reason Core Security