winrmhmut.exe

The executable winrmhmut.exe has been detected as malware by 3 anti-virus scanners.
MD5:
0e038572521b47a9782a5b7c6852e7f4

SHA-1:
801c9c68a926a463cc80e959b60ebf4d70f99aa3

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
5/2/2024 4:52:19 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160917-0

Clam AntiVirus
Win.Trojan.Mazben-22
0.98/23207

F-Secure
Trojan-Proxy:W32/Pramro.D
5.16.24

File size:
85.7 KB (87,722 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\winrmhmut.exe

File PE Metadata
Compilation timestamp:
1/5/2017 12:08:18 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x70B30

Entry point:
FE, CE, 0F, BE, D7, 84, E7, 20, D2, 86, EA, 8A, C1, 8B, C6, BB, 24, 64, 08, 1C, 33, E8, 24, 0A, 8D, 15, 0E, 70, D9, BB, 0F, AF, D9, 80, D8, 66, 88, F4, 0F, BF, CF, 68, 8B, E2, B6, 00, 8B, D9, 0F, AF, D1, E8, 2A, 00, 00, 00, 8A, C2, 87, FA, 80, E6, AC, C7, C6, C5, 73, E9, 1B, 69, F5, 3E, 9A, A1, 18, F3, C6, C3, E3, 33, C0, 46, 33, C0, 85, EE, F6, C5, CB, 30, DA, FF, CD, 33, C8, 0F, AF, E9, 3B, D6, 78, 06, 2A, D0, 09, D3, 8B, FA, 73, 02, 2B, D8, 84, C5, 0F, BF, FE, 0F, B7, EA, 81, F6, F9, 27, 00, 00, F6, C4...
 
[+]

Entropy:
7.7872  (probably packed)

Code size:
12 KB (12,288 bytes)

Windows Firewall Allowed Program
Name:
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winrmhmut.exe


Remove winrmhmut.exe - Powered by Reason Core Security