流量专家9.361.exe

The executable 流量专家9.361.exe has been detected as malware by 11 anti-virus scanners.
MD5:
c3333e78b0a214af0b21c47a30005cb7

SHA-1:
c9b7114f9b39fa980920c04f76c3349235ec7e9a

SHA-256:
34e05772f7bd179dee6fbc662a81c72764ae03f0772d0f24cf05ee5c3896e150

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
4/27/2024 2:52:19 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Strictor.1331.4
3.6.1.96

avast!
Win32:Dropper-gen [Drp]
2014.9-151009

Comodo Security
UnclassifiedMalware
21625

Fortinet FortiGate
W32/Tfr.ED!tr
10/9/2015

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.9.0

McAfee
RDN/Generic.tfr!ed
5600.6618

NANO AntiVirus
Trojan.Win32.Strictor.dnyuvq
0.30.8.659

Panda Antivirus
Trj/CI.A
15.10.09.10

Trend Micro House Call
TROJ_GEN.R002C0EJG14
7.2.282

Trend Micro
TROJ_GEN.R002C0EJG14
10.465.09

VIPRE Antivirus
FraudTool.Win32.FakeVimes!delf
38998

File size:
737.5 KB (755,200 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\????9.361\????9.361.exe

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:q5Nv8Dw9+GKWKwRydD3Q+TwvkENZT7A2HiqCohSGP1AaS1t4+U:o+/G7KwQdD3Pwvlj7JHiqDMQAbt4+

Entry address:
0xA0B1C

Entry point:
55, 8B, EC, 83, C4, EC, 53, 33, C0, 89, 45, EC, B8, 2C, 08, 4A, 00, E8, FA, 5C, F6, FF, 33, C0, 55, 68, 4C, 0C, 4A, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, BB, 23, F6, FF, 83, 7D, EC, 00, 75, 76, 68, 5C, 0C, 4A, 00, 6A, 00, 6A, 00, E8, 4B, 5F, F6, FF, 8B, D8, E8, 3C, 60, F6, FF, 85, C0, 79, 05, E8, F7, 2B, F6, FF, 3D, B7, 00, 00, 00, 74, 49, A1, 2C, 32, 4A, 00, 8B, 00, E8, C4, BA, FC, FF, 68, 80, 00, 00, 00, 6A, EC, A1, 2C, 32, 4A, 00, 8B, 00, 8B, 40, 30, 50, E8, 39, 69, F6, FF, 8B...
 
[+]

Entropy:
6.6379

Developed / compiled with:
Microsoft Visual C++

Code size:
639.5 KB (654,848 bytes)

Remove 流量专家9.361.exe - Powered by Reason Core Security