24bf.tmp

The file 24bf.tmp has been detected as malware by 18 anti-virus scanners.
MD5:
a25cbd1afe1cecd96d95a6486a4c66a7

SHA-1:
6764f4da97ad8ae4120a7880b7685a740c4b7685

SHA-256:
b2b1b40d4b04e306e2293289d09d563ddc1d4747fe04754b5f66ec559becdaa8

Scanner detections:
18 / 68

Status:
Malware

Analysis date:
4/24/2024 10:11:08 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.82397
577

Agnitum Outpost
Trojan.CL.Tiny
7.1.1

AhnLab V3 Security
Trojan/Win32.Miuref
2015.06.16

Avira AntiVirus
TR/Downloader.Gen
8.3.1.6

Arcabit
Trojan.Zusy.D141DD
1.0.0.425

AVG
Generic13_c
2016.0.3055

Bitdefender
Gen:Variant.Zusy.82397
1.0.20.940

Emsisoft Anti-Malware
Gen:Variant.Zusy.82397
8.15.07.07.03

ESET NOD32
Win32/TrojanClicker.Tiny.NAK (variant)
9.11788

Fortinet FortiGate
W32/TrojanClicker_Tiny.NAK!tr
7/7/2015

F-Secure
Gen:Variant.Zusy.82397
11.2015-07-07_3

G Data
Gen:Variant.Zusy.82397
15.7.25

MicroWorld eScan
Gen:Variant.Zusy.82397
16.0.0.564

NANO AntiVirus
Trojan.Win32.Tiny.doizrg
0.30.24.2086

Sophos
Mal/Behav-242
4.98

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
41156

Zillya! Antivirus
Trojan.Tiny.Win32.2052
2.0.0.2225

File size:
1.5 KB (1,536 bytes)

Common path:
C:\users\{user}\appdata\local\temp\24bf.tmp

File PE Metadata
Compilation timestamp:
6/14/2015 6:36:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24:ev1GSHCR4KWl1Ul1Ul1Ul1Ul1Ul1Ul1Ul1Ul1Ul1Ul1Ul1Ul1UIoH2H3K/yB0sWf:qDYYYYYYYYYYYYNoHq39BQf

Entry address:
0x122C

Entry point:
55, 8B, EC, 81, EC, D8, 05, 00, 00, 53, 56, 57, 6A, 7B, 59, BE, 3C, 10, 40, 00, 8D, BD, 10, FE, FF, FF, F3, A5, 66, A5, A4, 33, F6, 56, 56, 56, 56, 56, FF, 15, 10, 10, 40, 00, 56, 56, 56, 56, 8B, D8, 68, 1C, 10, 40, 00, 53, FF, 15, 0C, 10, 40, 00, 8B, 3D, 14, 10, 40, 00, 50, FF, D7, 53, FF, D7, 8D, 85, 10, FE, FF, FF, 50, 8D, 85, 28, FA, FF, FF, 50, FF, 15, 00, 10, 40, 00, 56, FF, 15, 04, 10, 40, 00, 5F, 5E, 33, C0, 5B, C9, C2, 10, 00, CC, CC, D8, 12, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 0E, 13, 00, 00...
 
[+]

Entropy:
4.1535

Developed / compiled with:
Microsoft Visual C++

Remove 24bf.tmp - Powered by Reason Core Security