app.exe

The executable app.exe has been detected as malware by 28 anti-virus scanners. The file has been seen being downloaded from jyotirmay.com.
MD5:
869c9e83389c139399f9f259be0f48ff

SHA-1:
bb5432ef545d4346f680eaa35dc1c94c94d9aaff

SHA-256:
fe0de217e7941a436c8fc4d99674f8ecc67af5ca791418b61dd274d3bfd7f66a

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/24/2024 3:23:43 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Spy.Gen
7.11.105.184

avast!
Win32:KadrBot [Trj]
2014.9-130824

AVG
Win32/DH
2014.0.3643

Baidu Antivirus
Trojan.Win32.Generic
4.0.3.131126

Bitdefender
Gen:Trojan.Heur.FU.cmW@aihOE0c
1.0.20.1180

Comodo Security
UnclassifiedMalware
17043

Dr.Web
Trojan.Siggen5.49142
9.0.1.0330

Emsisoft Anti-Malware
Gen:Trojan.Heur.FU.cmW@aihOE0c
8.13.08.24.02

ESET NOD32
Win32/Agent.PVU
7.8872

Fortinet FortiGate
W32/Kryptik.AHSH!tr
8/24/2013

F-Secure
Gen:Trojan.Heur.FU.cmW@aihOE0c
11.2013-24-08_7

G Data
Gen:Trojan.Heur.FU.cmW@aihOE0c
13.8.22

IKARUS anti.virus
Trojan.Win32.Spy
t3scan.2.0.127

K7 AntiVirus
Trojan
13.173.9757

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3773

Malwarebytes
Trojan.Malex
v2013.11.26.01

McAfee
Artemis!869C9E83389C
5600.7177

Microsoft Security Essentials
Trojan:Win32/Malex.gen!E
1.163.1557.0

MicroWorld eScan
Gen:Trojan.Heur.FU.cmW@aihOE0c
14.0.0.708

Norman
Troj_Generic.OMQAY
11.20131126

Panda Antivirus
Generic Malware
13.08.24.02

Reason Heuristics
Unnamed.Threat.55
14.3.1.0

Sophos
Mal/Generic-S
4.93

Trend Micro House Call
TROJ_GEN.R0CCZ07HV13
7.2.330

Trend Micro
TROJ_GEN.R0CCZ07HV13
10.465.26

Vba32 AntiVirus
BScope.P2P-Worm.Palevo
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
22058

ViRobot
Trojan.Win32.S.Agent.45056.DK
2011.4.7.4223

File size:
44 KB (45,056 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\app.exe

File PE Metadata
Compilation timestamp:
8/22/2013 2:31:33 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
384:yNbaLF0L2RiDTeTpar5F2vCPjdjuqTLeyaF/kttGiv/NKgxvN2WvpAoYBPrA6TrM:2Ns8NEGYGyF/k6w1HcbP4SOgBG

Entry address:
0x7950

Entry point:
E8, 7B, E7, FF, FF, 84, C0, 75, 06, B8, 01, 00, 00, 00, C3, E8, 0C, E9, FF, FF, E8, 17, E5, FF, FF, 33, C0, C3, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.1307

Code size:
28 KB (28,672 bytes)

The file app.exe has been seen being distributed by the following URL.

Remove app.exe - Powered by Reason Core Security