boss.exe

The executable boss.exe, “Protected Application” has been detected as malware by 37 anti-virus scanners.
Description:
Protected Application

Version:
1, 0, 0, 1

MD5:
5c7cf2aa7fa0b4e3f71dc308f59bafc9

SHA-1:
5c91a3629258cf15c58badfe5a4e11e428e97fb3

SHA-256:
6234103328d774b7a5969fc98250e7d130d430671611816fb4c738afbd26dccd

Scanner detections:
37 / 68

Status:
Malware

Analysis date:
4/25/2024 12:40:12 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.5415929
889

Agnitum Outpost
Worm.Rebhip.Gen.2
7.1.1

AhnLab V3 Security
Trojan/Win32.Bifrose
2014.03.10

Avira AntiVirus
TR/Crypt.XPACK.Gen
7.11.135.228

avast!
Win32:Malware-gen
2014.9-140829

AVG
Luhe.Packed-Molebox.A
2015.0.3367

Baidu Antivirus
Trojan.Win32.Generic
4.0.3.14829

Bitdefender
Trojan.Generic.5415929
1.0.20.1205

Bkav FE
W32.Clod982.Trojan
1.3.0.4959

Comodo Security
Backdoor.Win32.Curioso.~dy02
17907

Dr.Web
Trojan.PWS.Siggen.28421
9.0.1.0241

Emsisoft Anti-Malware
Trojan.Generic.5415929
8.14.08.29.04

ESET NOD32
Win32/Packed.MoleboxUltra (variant)
8.9520

Fortinet FortiGate
W32/Refroso.BKBI!tr
8/29/2014

F-Prot
W32/VBInject.V.gen
v6.4.7.1.166

F-Secure
Trojan:W32/Agent.DQKQ
11.2014-29-08_6

G Data
Trojan.Generic.5415929
14.8.24

IKARUS anti.virus
Trojan.Win32.Llac
t3scan.2.2.29

K7 AntiVirus
Riskware
13.176.11378

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3332

Malwarebytes
Malware.Packer.Gen
v2014.08.29.04

McAfee
Artemis!5C7CF2AA7FA0
5600.7023

Microsoft Security Essentials
PWS:Win32/Fignotok.A
1.10302

MicroWorld eScan
Trojan.Generic.5415929
15.0.0.723

NANO AntiVirus
Trojan.Win32.Llac.dwakg
0.28.0.58101

Norman
Obfuscated.CL!genr
11.20140829

nProtect
Trojan/W32.Agent.372936
14.03.09.01

Panda Antivirus
Generic Trojan
14.08.29.04

Qihoo 360 Security
HEUR/Malware.QVM08.Gen
1.0.0.1015

Quick Heal
VirTool.DelfInject.AF
8.14.12.00

Rising Antivirus
PE:Trojan.Win32.Generic.12725498!309482648
23.00.65.14827

Sophos
Mal/BigMole-B
4.98

Total Defense
Win32/Bifrose.ZG!genus
37.0.10809

Trend Micro
TROJ_BRDLAB.SMEP
10.465.29

Vba32 AntiVirus
TrojanPSW.Dybalom
3.12.24.3

VIPRE Antivirus
Packed.Win32.Rebhip.a
27248

ViRobot
Trojan.Win32.A.PSW-Dybalom.372936.B
2011.4.7.4223

File size:
364.2 KB (372,936 bytes)

Product version:
1, 0, 0, 1

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\extract\boss.exe

File PE Metadata
Compilation timestamp:
5/8/2010 11:27:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
4.21

CTPH (ssdeep):
6144:oEdb0s/pDJaMyAQSEJuQaP9jp5lRcZQ/RxsUTN5zxW8XsH7qMmezLulA37BPQl:oI085JsA1Xh5lTN5zxtXsbpmILuM7Bc

Entry address:
0x1004

Entry point:
6A, 28, 68, 70, 20, 40, 00, E8, 74, 02, 00, 00, 33, FF, 57, FF, 15, 00, E0, 45, 00, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 7D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, B9, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, B9, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 7D, FC, 6A, 01, FF, 15, 34, 20, 40, 00, 59, 83, 0D, 18, 21, 40, 00, FF, 83, 0D, 1C, 21, 40, 00...
 
[+]

Entropy:
7.8129

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
324 KB (331,776 bytes)

Remove boss.exe - Powered by Reason Core Security