ap.exe

MD5:
fbc93840a270cd45eeb527837e27e260

SHA-1:
271175c38ce0cca90c6f1d44da98e720ee313586

SHA-256:
3e730bc0901621d101b4d26763a9b0ecc34fa1600a5246be31a4cc9cd14676e2

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
5/23/2018 10:22:31 PM UTC  (today)

Scan engine
Detection
Engine version

F-Prot
W32/Banker.T.gen
4.6.5.141

IKARUS anti.virus
Trojan-Banker.Win32.Banbra
t3scan.1.9.5.0

File size:
1.5 MB (1,597,952 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ap.exe

File PE Metadata
Compilation timestamp:
2/16/2012 1:53:12 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:LnOz8Re0ER0A1T9OjQzBNSNnDMRtsA6AbWJQA7lbaebuglxBCkYm:Cz8EUSPSgsKubae6glDCkY

Entry address:
0x1417E0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 7C, 83, 53, 00, E8, 6C, 8D, EC, FF, A1, 30, 72, 54, 00, 8B, 00, E8, B4, 7F, F7, FF, A1, 30, 72, 54, 00, 8B, 00, B2, 01, E8, 9A, 9C, F7, FF, 8B, 0D, 74, 6E, 54, 00, A1, 30, 72, 54, 00, 8B, 00, 8B, 15, 40, 7D, 53, 00, E8, A6, 7F, F7, FF, A1, 30, 72, 54, 00, 8B, 00, E8, EA, 80, F7, FF, E8, 1D, 4E, EC, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5420

Developed / compiled with:
Microsoft Visual C++

Code size:
1.2 MB (1,310,208 bytes)

The file ap.exe has been seen being distributed by the following 15 URLs.

http://download1772.mediafire.com/a3ge9s84mf5g/.../AP.exe

http://download1772.mediafire.com/34bftu46c8jg/.../AP.exe

http://download636.mediafire.com/wb8mtm79gusg/.../AP.exe

http://download1017.mediafire.com/9dsgai6om3tg/.../AP.exe

http://download636.mediafire.com/p5ddsertm5lg/.../AP.exe

http://download999.mediafire.com/dj5pno56bnrg/.../AP.exe

Scan ap.exe - Powered by Reason Core Security