{blocked}.exe

The application {blocked}.exe has been detected as a potentially unwanted program by 17 anti-malware scanners. The file has been seen being downloaded from download1667.mediafire.com.
Version:
1.8.0.0

MD5:
df0d96dce4eb3f1d14efbea4b4844a7d

SHA-1:
67b465987549a9ffbf82b14e8c24fe8cff08d1f5

SHA-256:
3f028666ab37450588a92779e3c2d64ceacd59c9d0ffba3729e0899d19a256f8

Scanner detections:
17 / 68

Status:
Potentially unwanted

Explanation:
The software cotains keystroke monitoring/logging capablities which may or may not be installed without the user's knowledge.

Analysis date:
12/14/2017 12:10:59 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
HackTool.CheatEngine
7.1.1

AVG
Skodna.GameHack
2017.0.2812

Baidu Antivirus
Hacktool.Win32.CheatEngine
4.0.3.1636

Bkav FE
W32.LeepicoB.Trojan
1.3.0.4959

Clam AntiVirus
Trojan.Dropper-26973
0.98/21411

Comodo Security
ApplicUnwnt.Win32.HTool.A
20061

Dr.Web
Trojan.KillFiles.14799
9.0.1.066

ESET NOD32
Win32/HackTool.CheatEngine.AB (variant)
10.10710

Fortinet FortiGate
Riskware/CheatEngine
3/6/2016

F-Prot
W32/Trojan2.NMHW
v6.4.7.1.166

F-Secure
Trojan:W32/Agent.DSOA
11.2016-06-03_1

Malwarebytes
HackTool.GamesCheat.Gen
v2016.03.06.09

Norman
Obfuscated.I
11.20160306

SUPERAntiSpyware
Trojan.Agent/Gen-CheatEngine
9281

The Hacker
Trojan/Spy.Keylogger.fh
6.8.0.5.496

Total Defense
Win32/CheatEngine.A!genus
37.0.11275

VIPRE Antivirus
Trojan.Win32.Delf.abt
34726

File size:
691 KB (707,573 bytes)

Product version:
1.2

File type:
Executable application (Win32 EXE)

Language:
Dutch (Netherlands)

Common path:
C:\users\{user}\downloads\programs\css wallhack by.oneparty-4rt.exe

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:9EDCJJDXb8qWvvMyesvleMkWzChpBTfgYvVtcgwSuLnKtT6:9mQGbvNvjkJPKuMlXP

Entry address:
0x93BBC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 34, 39, 49, 00, E8, 18, 29, F7, FF, A1, F0, 9D, 49, 00, 8B, 00, E8, 60, 57, FC, FF, A1, F0, 9D, 49, 00, 8B, 00, C6, 40, 5B, 00, 8B, 0D, FC, 9C, 49, 00, A1, F0, 9D, 49, 00, 8B, 00, 8B, 15, CC, 36, 49, 00, E8, 55, 57, FC, FF, A1, F0, 9D, 49, 00, 8B, 00, E8, C9, 57, FC, FF, E8, 08, 06, F7, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5835

Developed / compiled with:
Microsoft Visual C++

Code size:
587.5 KB (601,600 bytes)

The file {blocked}.exe has been seen being distributed by the following URL.

Remove {blocked}.exe - Powered by Reason Core Security