87bdb2.exe

The executable 87bdb2.exe has been detected as malware by 36 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘87BDB2’.
MD5:
fe65e55a566fd7e2e963cfdb8c1c4f21

SHA-1:
e0313ec9c6a045fb965c5bb120ff0a00977aaed6

Scanner detections:
36 / 68

Status:
Malware

Analysis date:
5/22/2024 1:10:30 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Patched
7.1.1

AhnLab V3 Security
Win32/Flystudio.worm.Gen
2013.10.15

Avira AntiVirus
TR/Patched.Gen
7.11.107.146

avast!
Win32:Rootkit-gen [Rtk]
2014.9-160211

AVG
Win32/Heur
2017.0.2836

Baidu Antivirus
Trojan.Win32.Generic
4.0.3.16211

Bitdefender
GenPack:Backdoor.Generic.413198
1.0.20.210

Clam AntiVirus
Worm.FlyStudio-28
0.98/18155

Comodo Security
TrojWare.Win32.TrojanDropper.Flystud.~d01
17106

Dr.Web
Win32.HLLW.Autoruner.26035
9.0.1.042

Emsisoft Anti-Malware
GenPack:Backdoor.Generic.413198
8.16.02.11.05

ESET NOD32
Win32/FlyStudio.NYN
10.8916

Fortinet FortiGate
W32/PckdFlyStudio.gen
2/11/2016

F-Prot
W32/Nuj.A.gen
v6.4.7.1.166

F-Secure
Trojan-Dropper:W32/Peed.gen!A
11.2016-11-02_5

G Data
GenPack:Backdoor.Generic.413198
16.2.22

IKARUS anti.virus
Worm.Win32.FlyStudio
t3scan.2.0.127

K7 AntiVirus
Trojan
13.173.9866

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.676

McAfee
W32/Autorun.worm.dq
5600.6492

Microsoft Security Essentials
Backdoor:Win32/FlyAgent.F
1.163.1557.0

MicroWorld eScan
GenPack:Backdoor.Generic.413198
17.0.0.126

NANO AntiVirus
Trojan.Win32.Autoruner.beipzb
0.26.0.55366

Norman
FlyAgent.CX
11.20160211

nProtect
Trojan/W32.Agent.1414106
13.10.14.03

Panda Antivirus
Bck/Wutau.B
16.02.11.05

Quick Heal
Backdoor.FlyAgent.F
2.16.12.00

Rising Antivirus
Worm.Win32.Agent.aaq
23.00.65.16209

Sophos
Mal/EncPk-NB
4.93

SUPERAntiSpyware
Trojan.Agent/Gen-XPFraud
9330

Total Defense
Win32/Nuj.B!generic
37.0.10498

Trend Micro House Call
WORM_FLYSTUDI.B
7.2.42

Trend Micro
WORM_FLYSTUDI.B
10.465.11

Vba32 AntiVirus
TrojanDownloader.FlyStudio
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Autorun.dm
22384

ViRobot
Trojan.Win32.S.Downloader.1414106
2011.4.7.4223

File size:
1.3 MB (1,414,106 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\cb6caa\87bdb2.exe

File PE Metadata
Compilation timestamp:
5/25/2055 7:10:40 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
4.0

CTPH (ssdeep):
24576:/Srci8h5yxR5ymcXI94BuX+PQ8TRbXAQ6OVlLQC7rDT0jv1OAoFe8xi+Q4y:/Srci8haR5ymcXI94JLTRbXb6ODX7rnw

Entry address:
0x140B

Entry point:
50, F9, 56, 51, 52, 53, 57, 0F, 82, FB, FE, FF, FF, 2A, 46, 66, CD, F0, 46, 20, 23, F3, BF, D7, D8, 2F, 39, 64, 2A, 43, 46, 98, A3, B8, BF, 6E, 22, F3, C3, 53, A9, 1A, A7, E0, A2, 82, 3C, 40, F4, 40, BB, 54, 24, F0, 2F, 63, A2, F2, 0E, A5, EF, 17, 0F, 55, 9F, 2F, 3E, 19, A8, 8A, 13, E0, 92, B1, A9, 55, 9F, 6F, BB, C8, E3, BA, 0B, 59, A2, 02, 46, 9D, A7, B2, B4, 55, 1D, 67, 46, 57, A2, F2, 46, CF, A3, 5A, 8A, A6, 22, 1F, C3, 25, 8F, B3, 7D, 5D, D2, F8, 3E, 54, A0, A3, D6, BA, 2A, 3A, 3E, 17, A2, 26, 7C, 55...
 
[+]

Code size:
24 KB (24,576 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
87BDB2

Command:
C:\Windows\System32\cb6caa\87bdb2.exe


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-52-0-217-44.compute-1.amazonaws.com  (52.0.217.44:80)

Remove 87bdb2.exe - Powered by Reason Core Security