{336f3799-5fa7-560a-fe43-e4f2ef85a821}-icobome.exe

The executable {336f3799-5fa7-560a-fe43-e4f2ef85a821}-icobome.exe has been detected as malware by 14 anti-virus scanners.
MD5:
f669b31d7ea39f38ea5223e26c570a86

SHA-1:
97cc8a3ca7df4fd9e79d5c4c7b4aeab2d39d61d1

SHA-256:
900d036af53adf64018c8eeb29ee5c28f19bcd42274b9191b41d649ae6b65384

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
5/7/2024 8:40:44 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12167569
5829361

Avira AntiVirus
TR/Crypt.ZPACK.103868
7.11.188.92

AVG
Win32/Cryptor
2014.0.4189

Bitdefender
Trojan.Generic.12167569
1.0.20.1635

Dr.Web
Trojan.PWS.Panda.7719
9.0.1.05190

Emsisoft Anti-Malware
Trojan.Generic.12167569
9.0.0.4570

F-Secure
Trojan.Generic.12167569
11.2014-23-11_1

G Data
Trojan.Generic.12167569
14.11.24

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.2900

McAfee
MysticCompressor!5217756F82A4
5600.6937

MicroWorld eScan
Trojan.Generic.12167569
15.0.0.981

NANO AntiVirus
Trojan.Win32.Panda.diycru
0.28.6.63474

nProtect
Trojan.Generic.12167569
14.11.21.01

Quick Heal
FraudTool.Security
11.14.14.00

File size:
275 KB (281,650 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\ProgramData\microsoft\microsoft antimalware\localcopy\{336f3799-5fa7-560a-fe43-e4f2ef85a821}-icobome.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
6144:O2a3q2ed6lr9x6vbD9II25QWGYlOvo0UjhFM4HvYcb5LRvAu1XFfVDg:OV3q2uq9oDVWNlOvNIvMmvtb31X9S

Entry point:
B2, A5, 6F, FF, FC, FF, FF, FF, FB, FF, FF, FF, 00, 00, FF, FF, 47, FF, FF, FF, FF, FF, FF, FF, BF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FE, FF, FF, F1, E0, 45, F1, FF, 4B, F6, 32, DE, 47, FE, B3, 32, DE, AB, 97, 96, 8C, DF, 8F, 8D, 90, 98, 8D, 9E, 92, DF, 9C, 9E, 91, 91, 90, 8B, DF, 9D, 9A, DF, 8D, 8A, 91, DF, 96, 91, DF, BB, B0, AC, DF, 92, 90, 9B, 9A, D1, F2, F2, F5, DB, FF, FF, FF, FF, FF, FF, FF...
 
[+]

Entropy:
7.8822  (probably packed)