1ff92840-sample

Downloader

AND LLC

The file 1ff92840-sample by AND has been detected as adware by 26 anti-malware scanners.
Publisher:
AND LLC  (signed and verified)

Product:
Downloader

Version:
1, 0, 0, 0

MD5:
44b3188e4994083158cc48c46e79a2d6

SHA-1:
c3a8352fe4967c08c6d223227208a07adbab2f8e

SHA-256:
d96b252e666bdd160c604e33fddc0edc02b45c7c01cfd7ddd0a2a3b6bb019d0d

Scanner detections:
26 / 68

Status:
Adware

Analysis date:
4/23/2024 9:05:56 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.307598
765

AhnLab V3 Security
Trojan/Win32.LoadMoney
2014.10.29

Avira AntiVirus
TR/Dldr.Ogimant.A.224
7.11.181.246

AVG
Win32/Heur
2015.0.3243

Baidu Antivirus
Trojan.Win32.Kryptik
4.0.3.141231

Bitdefender
Gen:Variant.Kazy.307598
1.0.20.1825

Bkav FE
W32.HfsAutoB
1.3.0.6185

Comodo Security
MalCrypt.Indus!
19930

Dr.Web
Trojan.LoadMoney.224
9.0.1.0365

Emsisoft Anti-Malware
Gen:Variant.Kazy.307598
8.14.12.31.01

ESET NOD32
Win32/Kryptik.BOZR (variant)
8.10636

F-Secure
Gen:Variant.Kazy.307598
11.2014-31-12_4

G Data
Gen:Variant.Kazy.307598
14.12.24

IKARUS anti.virus
Virus.Win32.Heur
t3scan.1.7.8.0

K7 AntiVirus
Trojan
13.185.13827

Kaspersky
not-a-virus:HEUR:Downloader.Win32.LMN
14.0.0.2712

Malwarebytes
PUP.Optional.LoadMoney
v2014.12.31.01

McAfee
PUP-FEL
5600.6899

Microsoft Security Essentials
TrojanDownloader:Win32/Ogimant.gen!A
1.11104

MicroWorld eScan
Gen:Variant.Kazy.307598
15.0.0.1095

NANO AntiVirus
Trojan.Win32.LMN.cyegur
0.28.6.62995

Qihoo 360 Security
Win32/Trojan.835
1.0.0.1015

Quick Heal
Trojan.Monder.A2
12.14.14.00

Reason Heuristics
PUP.AND.P
14.12.31.13

Sophos
Troj/LdMon-D
4.98

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
34332

File size:
75.5 KB (77,304 bytes)

Product version:
1, 0, 0, 0

Copyright:
Copyright 2013

Original file name:
Downloader.exe

Language:
Russian (Russia)

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/10/2013 3:30:00 AM

Valid to:
10/11/2014 3:29:59 AM

Subject:
CN=AND LLC, O=AND LLC, STREET="Marshala Fedorenko street, 7", L=Moscow, S=Moscow, PostalCode=125599, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
77019A082385E4B73F569569C9F87BB8

File PE Metadata
Compilation timestamp:
11/6/2013 1:28:27 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
1.70

CTPH (ssdeep):
1536:6uLUxTQqLTNCz3UsI7PVEuDOEkbV14iJG08cbr2s/:1LwVLTNq3UpxE7EYX4ik08cfL/

Entry address:
0x8000

Entry point:
81, DA, B3, 80, 97, 8C, F5, 31, EA, C1, C3, 11, 47, 1B, 7C, 24, 10, 81, C7, 0A, 02, AC, 7A, 39, 64, 24, F0, C1, C0, 1F, C1, E2, 15, 81, CA, E3, 1D, 45, C6, F7, 05, A4, 94, 40, 00, 71, A3, EF, 4F, C1, F8, 19, 03, 7C, 24, 0C, C1, CD, 13, C1, E1, 03, 0B, 2D, 62, 6D, 40, 00, C1, CD, 17, C1, E7, 0D, 31, D0, 11, C3, 43, C1, FA, 1D, 45, 39, 3D, 07, 40, 40, 00, 01, D0, 13, 2D, A0, 69, 40, 00, 0B, 5C, 24, 04, C1, E1, 03, C1, C2, 12, 1B, 05, 9C, 37, 40, 00, 33, 54, 24, 14, 4A, 87, ED, C1, FF, 11, 33, 7C, 24, EC, C1...
 
[+]

Entropy:
7.1028

Remove 1ff92840-sample - Powered by Reason Core Security