Clientless arena.exe

Clientless arena

3DProgrammer

The executable Clientless arena.exe has been detected as malware by 20 anti-virus scanners. While running, it connects to the Internet address ns390469.ip-188-165-244.eu on port 15884.
Publisher:
3DProgrammer

Product:
Clientless arena

Version:
2.2.0.0

MD5:
943d620ba7f74d3e218844268cc981be

SHA-1:
381454b12bad025fb182253fc2f93e0d07224b21

SHA-256:
622dd40c29e5207d05e6e80e4e0f90f2adc593426852649a6d98a6c3ddeea9e5

Scanner detections:
20 / 68

Status:
Malware

Analysis date:
5/17/2024 3:25:11 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.RP.yz0aaK8Fnem
290

Avira AntiVirus
TR/Spy.Agent.1444352
8.3.1.6

Arcabit
Trojan.Heur.RP.yz0aaK8Fnem
1.0.0.425

avast!
Win32:Malware-gen
2014.9-160420

AVG
Generic12_c
2017.0.2768

Baidu Antivirus
Hacktool.Win32.Packed.Themida
4.0.3.16420

Bitdefender
Gen:Trojan.Heur.RP.yz0aaK8Fnem
1.0.20.555

Bkav FE
W32.HfsAutoB
1.3.0.7062

Comodo Security
UnclassifiedMalware
23021

Emsisoft Anti-Malware
Gen:Trojan.Heur.RP.yz0aaK8Fnem
8.16.04.20.12

ESET NOD32
Win32/Packed.Themida suspicious (variant)
10.12103

Fortinet FortiGate
PossibleThreat
4/20/2016

F-Secure
Gen:Trojan.Heur.RP.yz0aaK8Fnem
11.2016-20-04_4

G Data
Gen:Trojan.Heur.RP.yz0aaK8Fnem
16.4.25

K7 AntiVirus
Trojan
13.2016902

MicroWorld eScan
Gen:Trojan.Heur.RP.yz0aaK8Fnem
17.0.0.333

Qihoo 360 Security
HEUR/QVM19.1.Malware.Gen
1.0.0.1015

Sophos
Generic PUA DI (PUA)
4.98

Trend Micro
TROJ_GEN.R01TC0VF315
10.465.20

VIPRE Antivirus
Trojan.Win32.Generic
42952

File size:
1.4 MB (1,444,352 bytes)

Product version:
2.2.0.0

Copyright:
Copyright © 3DProgrammer

Original file name:
Clientless arena.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\compressed\clientless arena.exe

File PE Metadata
Compilation timestamp:
3/24/2015 5:36:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:14ZBcf2eXq2Nwmr8S6voUbr+krypKfRrgfCTczyS2Tvrgye/tTNZcss8wKrGNz4k:uXceexrbkoU/+h0Rcfd8fgJQn8wOG/f

Entry address:
0x3AA000

Entry point:
56, 50, 53, E8, 01, 00, 00, 00, CC, 58, 89, C3, 40, 2D, 00, A0, 15, 00, 2D, 00, 82, 0C, 10, 05, F7, 81, 0C, 10, 80, 3B, CC, 75, 19, C6, 03, 00, BB, 00, 10, 00, 00, 68, 86, 6E, ED, 0E, 68, 02, C0, CB, 6C, 53, 50, E8, 0A, 00, 00, 00, 83, C0, 00, 89, 44, 24, 08, 5B, 58, C3, 55, 89, E5, 50, 53, 51, 56, 8B, 75, 08, 8B, 4D, 0C, C1, E9, 02, 8B, 45, 10, 8B, 5D, 14, 85, C9, 74, 0A, 31, 06, 01, 1E, 83, C6, 04, 49, EB, F2, 5E, 59, 5B, 58, C9, C2, 10, 00, 01, 37, 92, B6, 00, 65, 6D, D1, 6E, E0, 43, CB, E1, 21, C4, 67...
 
[+]

Entropy:
7.9357  (probably packed)

Code size:
60.5 KB (61,952 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP:
Connects to ns390469.ip-188-165-244.eu  (188.165.244.8:15884)

Remove Clientless arena.exe - Powered by Reason Core Security