aaa logo_by engkiko.exe

AAA Logo: Logo Design Software

SWGSOFT.COM

This is a setup program which is used to install the application. The file has been seen being downloaded from doc-0k-1o-docs.googleusercontent.com and multiple other hosts.
Publisher:
SWGSOFT.COM

Product:
AAA Logo: Logo Design Software

Version:
2.0

MD5:
bd1cca45a2cb19f5ad1a872b7f106509

SHA-1:
cd6fff67a1cd63a230e4b7b761b8f64cf8723450

SHA-256:
146ed6ca11ffea90c27d3e30b8dcc15b118fa18fa135b3ccc048a71286b8a298

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/3/2024 5:18:19 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Trojan.Win32.Undef
4.0.3.131224

Bkav FE
W32.DropperNeglemirE.Trojan
1.3.0.4562

Comodo Security
TrojWare.Win32.TrojanDropper.Binder.v
17283

Malwarebytes
Malware.Binder.Gen
v2013.12.24.09

File size:
8.8 MB (9,253,359 bytes)

Product version:
2.0

Copyright:
Copyright (C) 2001-2008 SWGSOFT.COM

Trademarks:
Copyright (C) 2001-2008 SWGSOFT.COM

Original file name:
LDE.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\aaa logo_by engkiko.exe

File PE Metadata
Compilation timestamp:
1/21/2010 12:52:04 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:2njPzBEM3FAdxEDJGwuJaWSmdDh3S7Al7nXQmjis9uMsE:2nDa7dxEVaJqmf3XZnXQyuFE

Entry address:
0x136F

Entry point:
9C, 60, 68, 53, 74, 41, 6C, 68, 54, 68, 49, 6E, E8, 00, 00, 00, 00, 58, BB, 80, 13, 00, 00, 2B, C3, 50, 68, 00, 00, 20, 46, 68, 00, 60, 00, 00, 68, 24, 01, 00, 00, E8, 63, FC, FF, FF, E9, CC, FC, FF, FF, 55, 8B, EC, 83, EC, 10, 53, 56, 57, 8B, 7D, 08, 8B, 47, 3C, 8D, 5C, 38, 78, 8B, 03, 85, C0, 0F, 84, 92, 00, 00, 00, 83, 7B, 04, 28, 0F, 82, 88, 00, 00, 00, 8D, 34, 38, 8B, 4E, 18, 85, C9, 74, 7E, 8B, 56, 20, 3B, D0, 72, 77, 8D, 14, 8A, 8B, 4B, 04, 03, C8, 3B, CA, 72, 6B, 8B, 46, 20, 83, 65, 08, 00, 03, C7...
 
[+]

Code size:
24 KB (24,576 bytes)

The file aaa logo_by engkiko.exe has been seen being distributed by the following 5 URLs.

https://doc-0k-1o-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/8dnds74dgcijkkp8qr8gi8etod3njafn/1455544800000/06166183036817460376/.../0B3WRwEgg_Ab2b1JZdTlTc3M0XzQ?e=download

Scan aaa logo_by engkiko.exe - Powered by Reason Core Security