banner.exe

Vladimir Varenkov

The executable banner.exe has been detected as malware by 5 anti-virus scanners.
Publisher:
Vladimir Varenkov  (signed and verified)

MD5:
4b346ec346ceb3af35a2a5c8e7cefd80

SHA-1:
df26582639a105ff172935064bd651ce31c53177

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
4/23/2024 9:21:23 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAutoB
1.3.0.7400

Dr.Web
Trojan.Packed.22393
9.0.1.013

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48 [F]
23.00.65.16111

Trend Micro House Call
Possible_Virus
7.2.13

Trend Micro
Possible_Virus
10.465.13

File size:
622 KB (636,936 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\easy banner creator 2.3\banner.exe

Digital Signature
Authority:
StartCom Ltd.

Valid from:
3/28/2012 4:27:02 PM

Valid to:
3/29/2014 5:55:09 PM

Subject:
E=support@easyanimationtools.com, CN=Vladimir Varenkov, L=Troitsk, S=Moskva Oblast, C=RU, Description=aP8721LmpRRf5N6X

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
05A9

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:Bv5s3QIrlnXx+oax8s6LVqoxyI85gmxyKC9hUgNatFdynRROtIKJG/hA5YccbPl1:Bv5s3ais6LVvyI8CmkNqBFqRROtIKKVL

Entry address:
0x15B000

Entry point:
EB, 02, 01, 38, 50, EB, 01, AB, E8, 18, 00, 00, 00, EB, 04, 80, 7D, AF, 82, EB, 01, 02, 33, C0, EB, 05, 9C, 0E, 99, 1C, D0, 71, 61, EB, 02, F1, 4F, EB, 05, B0, 3E, 72, D0, CB, B8, 0B, 48, E5, F6, EB, 03, 92, 32, 55, EB, 01, E3, 05, F5, B7, 1A, 09, EB, 04, 95, 11, F4, 7F, 75, 3C, EB, 03, 3A, 18, 29, 64, FF, 30, EB, 03, 2F, 89, AE, 64, 89, 20, EB, 03, 00, 27, CC, EB, 01, 72, 8B, 10, EB, 04, 79, B0, 06, DD, 64, 8F, 00, EB, 01, 80, 83, C4, 04, EB, 04, 0A, A5, A0, A1, 58, EB, 03, B8, D4, CB, C3, EB, 04, A7, E7...
 
[+]

Entropy:
7.9852

Packer / compiler:
FSG v1.10 (Microsoft Visual C++ 6.0 / 7.0)

Code size:
806.5 KB (825,856 bytes)

Remove banner.exe - Powered by Reason Core Security