6_offer_3.exe

Product

Company

The application 6_offer_3.exe has been detected as a potentially unwanted program by 7 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dl.revenyou.com and multiple other hosts.
Publisher:
Company

Product:
Product

Version:
1.0.0.0

MD5:
240e49b6007a0beef76db377ecb26575

SHA-1:
48c9ad023af0287f173ff92339ef9d18701d2863

SHA-256:
cafecb68f91fc82a870856669bb44202f4f9b39dbace8f9c3beaf98e5b3449af

Scanner detections:
7 / 68

Status:
Potentially unwanted

Analysis date:
5/11/2025 1:59:12 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Agent
4.0.3.1427

Comodo Security
UnclassifiedMalware
17738

K7 AntiVirus
Riskware
13.175.11086

Kaspersky
not-a-virus:HEUR:AdWare.MSIL.Agent
14.0.0.4347

Rising Antivirus
PE:Trojan.Win32.Generic.134F9893!323983507
23.00.65.14205

Trend Micro House Call
TROJ_GEN.R0CBH07B314
7.2.38

Vba32 AntiVirus
AdWare.MSIL.Agent
3.12.24.3

File size:
3.7 MB (3,831,296 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Company 2011

Original file name:
SoftwareWrapper.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\6_offer_3.exe

File PE Metadata
Compilation timestamp:
3/26/2012 8:51:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:2ww2/zxR1FNk3pvQ3OsManew258VhxmHJVLCURUp:Tr/V33uYeaGyYpVLm

Entry address:
0x3A763E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9669

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
3.6 MB (3,823,616 bytes)

The file 6_offer_3.exe has been seen being distributed by the following 2 URLs.

Remove 6_offer_3.exe - Powered by Reason Core Security