1372.exe

The executable 1372.exe has been detected as malware by 31 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.weebly.com.
MD5:
32a91f53218736ac3c319459547f7bfd

SHA-1:
de412838d360dcb1cda7bfec61350f361781c3f8

SHA-256:
cb6ef262aa9cdf10babd57ddf517e1be73bc72bd7d49282d852e3bfd77dd1170

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
4/26/2024 5:26:18 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.38373
316

Agnitum Outpost
Trojan.DR.Injector
7.1.1

AhnLab V3 Security
Dropper/Win32.Injector
2015.04.04

avast!
Win32:Evo-gen [Susp]
2014.9-160324

AVG
Dropper.Generic8
2017.0.2794

Baidu Antivirus
Trojan.Win32.Inject
4.0.3.16324

Bitdefender
Gen:Variant.Symmi.38373
1.0.20.420

Comodo Security
UnclassifiedMalware
21637

Dr.Web
BackDoor.Poison.16049
9.0.1.084

Emsisoft Anti-Malware
Gen:Variant.Symmi.38373
8.16.03.24.03

ESET NOD32
Win32/Injector.APLL (variant)
10.11422

Fortinet FortiGate
W32/Injector.JCNI!tr
3/24/2016

F-Secure
Gen:Variant.Symmi.38373
11.2016-24-03_5

G Data
Gen:Variant.Symmi.38373
16.3.25

IKARUS anti.virus
Trojan-Dropper.Win32.Injector
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.202.15480

Kaspersky
Trojan.Win32.Inject
14.0.0.467

McAfee
Artemis!32A91F532187
5600.6450

Microsoft Security Essentials
VirTool:Win32/VBInject
1.1.11502.0

MicroWorld eScan
Gen:Variant.Symmi.38373
17.0.0.252

NANO AntiVirus
Trojan.Win32.Inject.ctkhyl
0.30.8.659

Norman
Troj_Generic.PMCQL
11.20160324

Panda Antivirus
Generic Malware
16.03.24.03

Qihoo 360 Security
HEUR/Malware.QVM11.Gen
1.0.0.1015

Quick Heal
Trojan.Inject.r3
3.16.14.00

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNR.30D114
7.2.84

Trend Micro
TROJ_SPNR.30D114
10.465.24

Vba32 AntiVirus
Backdoor.DarkKomet
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
39028

Zillya! Antivirus
Backdoor.DarkKomet.Win32.12876
2.0.0.2126

File size:
566.6 KB (580,167 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\1372.exe

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:XJr8CrW1KuPMnZy2hWvG/Mx3y+eRAaWdlZFa+dVA/WZ:ZrVrRuEnZNhqQMde1QFn5

Entry address:
0x1E8E60

Entry point:
60, BE, 00, 90, 57, 00, 8D, BE, 00, 80, E8, FF, C7, 87, 9C, 10, 19, 00, 0E, 44, 48, B7, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
452 KB (462,848 bytes)

The file 1372.exe has been seen being distributed by the following URL.

Remove 1372.exe - Powered by Reason Core Security