{800e6ae9-2934-8564-b224-bab1800e6ae9}.exe

The executable {800e6ae9-2934-8564-b224-bab1800e6ae9}.exe has been detected as malware by 7 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from chaosium.com.
MD5:
aa2e6830e6d77c64080d6abc5b5ebf66

SHA-1:
8fafb5610470f71e11cca57de8da830188716f45

SHA-256:
81ffe0e17e8a86be36048968c02e517666ef0710d675b6e777fb5d637d0c86cd

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
11/14/2018 4:03:51 AM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Baidu Antivirus
HackTool.Win32.Packer
4.0.3.14128

Bkav FE
HW32.CDB
1.3.0.4923

Kaspersky
Trojan.Win32.Agent
14.0.0.4396

Qihoo 360 Security
HEUR/Malware.QVM19.Gen
1.0.0.1015

Reason Heuristics
Unnamed.Threat.36
14.3.6.13

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.14126

Trend Micro House Call
TROJ_GEN.F47V0128
7.2.28

File size:
161.1 KB (164,966 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\microsoft\windows\start menu\programs\startup\{800e6ae9-2934-8564-b224-bab1800e6ae9}.exe

File PE Metadata
Compilation timestamp:
11/30/2005 2:26:46 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:sBMMvzbx2VeLRbWNjIQCbIEEKyX9ifQnQTH0G188sc5Lc3ehRNoWrLSfCpYzNg2G:seM7dCJI60ZHL18GxRyPlnbBFKt7BHAi

Entry address:
0x24CDB

Entry point:
8B, FF, 55, 8B, EC, A0, D4, 3E, 42, 00, 83, EC, 14, 56, 0F, BE, C0, 8A, 80, D4, 3E, 42, 00, 33, F6, 83, 7D, 0C, 01, 57, 74, 16, 83, 7D, 0C, 03, 0F, 86, B2, 00, 00, 00, 39, 35, 78, 40, 42, 00, 0F, 85, A6, 00, 00, 00, 39, 35, C4, 3F, 42, 00, 75, 0D, 56, FF, 15, 40, 10, 40, 00, 50, E8, 9A, 00, 00, 00, 68, 69, 4F, 42, 00, FF, 15, 28, 10, 40, 00, 85, C0, 74, 3E, 68, 04, 3F, 42, 00, E8, 5A, FE, FF, FF, A3, B4, 5C, 42, 00, A1, 6C, 3F, 42, 00, 89, 45, F0, 8D, 45, EC, BF, 95, 11, 40, 00, 50, C7, 45, F8, 98, 40, 42...
 
[+]

Code size:
148.5 KB (152,064 bytes)

User Start Menu Item
Name:
{800e6ae9-2934-8564-b224-bab1800e6ae9}.exe


The file {800e6ae9-2934-8564-b224-bab1800e6ae9}.exe has been seen being distributed by the following URL.

Remove {800e6ae9-2934-8564-b224-bab1800e6ae9}.exe - Powered by Reason Core Security