api_redirection1.exe

The executable api_redirection1.exe has been detected as malware by 19 anti-virus scanners.
MD5:
54dc56e1cac88d00533fbcc5a6fcbc08

SHA-1:
0248de4dcaf004e1988379b2286f769925081767

SHA-256:
7814ec52dd0d764be305a03c115eefeb6731172b26fca27c503f3affbdac2ea9

Scanner detections:
19 / 68

Status:
Malware

Analysis date:
4/19/2024 12:14:41 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Packer.PESpin.A.cqWaaC7mzui
1017

Agnitum Outpost
Packed/PeSpin
7.1.1

Avira AntiVirus
HEUR/Crypted
7.11.145.10

Bitdefender
Gen:Packer.PESpin.A.cqWaaC7mzui
1.0.20.565

Bkav FE
HW32.CDB
1.3.0.4959

Comodo Security
TrojWare.Win32.Banbra.sl
18157

Emsisoft Anti-Malware
Gen:Packer.PESpin.A.cqWaaC7mzui
8.14.04.23.08

F-Prot
W32/Patched.R.gen
v6.4.7.1.166

F-Secure
Gen:Packer.PESpin.A.cqWaaC7mzui
11.2014-23-04_4

G Data
Gen:Packer.PESpin.A.cqWaaC7mzui
14.4.24

IKARUS anti.virus
Packer.PESpin
t3scan.1.6.1.0

MicroWorld eScan
Gen:Packer.PESpin.A.cqWaaC7mzui
15.0.0.339

Norman
Packed_PeSpin.B
11.20140423

Quick Heal
(Suspicious) - DNAScan
4.14.12.00

Rising Antivirus
PE:Trojan.Win32.Crypt.agl!1075334316
23.00.65.14421

Sophos
Mal/Packer
4.98

Trend Micro House Call
Cryp_PESpin
7.2.113

Trend Micro
Cryp_PESpin
10.465.23

VIPRE Antivirus
Trojan.Win32.Packer.PESpinv1.32
28550

File size:
35.5 KB (36,352 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

CTPH (ssdeep):
384:XB+TzPSRIYvSj1+8KrmF69yIRJezvXj3bqtSv0FvEmiRrcNsERjLOg+yZtAPcgpj:x+nQIYR8/MJAyW0FvJicmvyvQpq/Dgp

Entry address:
0xB0D4

Entry point:
EB, 01, 68, 60, E8, 00, 00, 00, 00, 8B, 1C, 24, 83, C3, 12, 81, 2B, E8, B1, 06, 00, FE, 4B, FD, 82, 2C, 24, 17, E6, 46, 00, 0B, E4, 74, 9E, 75, 01, C7, 81, 73, 04, D7, 7A, F7, 2F, 81, 73, 19, 77, 00, 43, B7, F6, C3, 6B, B7, 00, 00, F9, FF, E3, C9, C2, 08, 00, A3, 68, 72, 01, FF, 5D, 33, C9, 41, E2, 17, EB, 07, EA, EB, 01, EB, EB, 0D, FF, E8, 01, 00, 00, 00, EA, 5A, 83, EA, 0B, FF, E2, EB, 04, 9A, EB, 04, 00, EB, FB, FF, E8, 02, 00, 00, 00, A0, 00, 5A, 81, EA, 45, B1, 00, 00, 83, EA, FE, 89, 95, A9, 57, 40...
 
[+]

Entropy:
7.8760

Packer / compiler:
PE Spin v0.4x

Code size:
20 KB (20,480 bytes)

Remove api_redirection1.exe - Powered by Reason Core Security