cod4newhack.dll

The module cod4newhack.dll has been detected as a potentially unwanted program by 22 anti-malware scanners. The file has been seen being downloaded from download1258.mediafire.com and multiple other hosts.
MD5:
8f86ac23051302308d6faf5c3958f253

SHA-1:
6c20b061d029cb16734972eaf235db8702402e33

SHA-256:
4f1508fe49e5e6488019265bb7b2f019df9f1c0cf826b38c85307746c7031ffc

Scanner detections:
22 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 1:06:34 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.LP.kG4@a464d7fi
957

AegisLab AV Signature
Troj.Spy
2.1.4+

Avira AntiVirus
TR/Spy.176128.140
7.11.154.8

avast!
Win32:PUP-gen [PUP]
2014.9-140622

Bitdefender
Gen:Trojan.Heur.LP.kG4@a464d7fi
1.0.20.865

Bkav FE
HW32.CDB
1.3.0.4959

Clam AntiVirus
Win.Trojan.Agent-383874
0.98/21155

Comodo Security
UnclassifiedMalware
18496

Emsisoft Anti-Malware
Gen:Trojan.Heur.LP.kG4@a464d7fi
8.14.06.22.05

F-Secure
Gen:Trojan.Heur.LP.kG4@a464d7fi
11.2014-22-06_1

G Data
Gen:Trojan.Heur.LP.kG4@a464d7fi
14.6.24

IKARUS anti.virus
Trojan.Win32.Spy
t3scan.1.6.1.0

McAfee
RDN/Generic PWS.y!xa
5600.7091

MicroWorld eScan
Gen:Trojan.Heur.LP.kG4@a464d7fi
15.0.0.519

Norman
Suspicious_Gen2.JSMVU
11.20140622

Panda Antivirus
Generic Malware
14.06.22.05

Qihoo 360 Security
Win32/Trojan.08d
1.0.0.1015

Rising Antivirus
PE:Trojan.Win32.Generic.128BE70A!311158538
23.00.65.14620

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNV.03A314
7.2.173

Trend Micro
TROJ_SPNV.03A314
10.465.22

VIPRE Antivirus
Trojan.Win32.Generic
30144

File size:
172 KB (176,128 bytes)

File type:
Dynamic link library (Win32 DLL)

File PE Metadata
Compilation timestamp:
2/8/2011 7:42:04 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:qLqjAtA0EyDJ34oPKWMRdp/IXKxbis9nckzZDREOUBfk3/DVFcD:qLhW0EcBBFMRJiY1B/WcD

Entry address:
0x36CA9

Entry point:
E9, 7A, C7, 01, 00, E9, 5E, 8D, 01, 00, 60, 9C, F5, 85, D2, 9C, E8, BF, C5, 01, 00, 6E, 10, E8, D4, D8, 8D, 92, 76, 77, 3F, 29, 0A, BF, 93, 5F, 34, 27, C5, A0, 3A, 0C, EC, D7, A6, 43, C5, 87, B8, AD, 1D, 90, 40, 6A, 94, 1E, 71, 74, 1E, 5D, A4, C0, 97, E7, 56, C6, DC, B8, AC, DA, B6, 10, 57, 51, 49, 11, E6, EC, C1, 8D, 29, F7, AF, 67, 54, E1, 10, B2, 50, E2, 72, 47, 67, 11, 69, 75, A0, 19, 9D, 3B, CD, 5D, 69, 8F, 6F, 4B, 4E, B7, 30, D4, A9, 6A, F9, C3, BB, 65, 6C, A9, CB, 55, AE, AE, 40, D0, D5, B1, F5, C3...
 
[+]

Entropy:
7.6146

Packer / compiler:
Xtreme-Protector v1.05

Code size:
68 KB (69,632 bytes)

The file cod4newhack.dll has been seen being distributed by the following 3 URLs.

http://download1258.mediafire.com/94c91h9u02zg/.../Aimbot[SimplyMods].dll

Remove cod4newhack.dll - Powered by Reason Core Security