coolhackv1.exe

The executable coolhackv1.exe has been detected as malware by 29 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download1423.mediafire.com.
MD5:
125eaa5f87d094b346ee83690634d14c

SHA-1:
2de541e48712a49c42678592b872b771b4142470

SHA-256:
aea982beb90238d0bcd1ac82bbb346794aa0cd3815409cba249c0d218e5b875e

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
4/16/2024 8:07:27 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Zapchast
7.1.1

Avira AntiVirus
TR/Kazy.33587216
7.11.144.62

avast!
Win32:Malware-gen
2014.9-140420

AVG
Pakes_c.AUMR.dropper
2015.0.3499

Baidu Antivirus
Trojan.MSIL.Zapchast
4.0.3.14420

Bkav FE
W32.BeloseaC.Trojan
1.3.0.4959

Comodo Security
Backdoor.Win32.Agent.CEP_svr23
18127

ESET NOD32
MSIL/Injector.BWZ (variant)
8.9697

Fortinet FortiGate
W32/FlyStudio_Packed.A
4/20/2014

F-Secure
Gen:Variant.Kazy.254771
11.2014-20-04_1

G Data
Win32.Trojan.Agent.WKMDRD
14.4.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.176.11806

Kaspersky
Trojan.MSIL.Zapchast
14.0.0.3989

Malwarebytes
Trojan.MSIL
v2014.04.20.02

McAfee
Artemis!125EAA5F87D0
5600.7155

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi.gen!B
1.10502

NANO AntiVirus
Trojan.Win32.Kazy.cudcvq
0.28.0.59288

Norman
Bladabindi.II
11.20140420

Panda Antivirus
VBS/Autorun.BC.worm
14.04.20.02

Quick Heal
Trojan.Comrerop
4.14.12.00

Sophos
Mal/Generic-S
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Bladabindi
10655

Total Defense
Win32/Armax.OVKTQIB
37.0.10885

Trend Micro House Call
TROJ_SPNR.10BC14
7.2.110

Trend Micro
TROJ_SPNR.10BC14
10.465.20

Vba32 AntiVirus
Trojan.MSIL.Zapchast
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
28372

ViRobot
Backdoor.Win32.A.Bifrose.40448.L
2011.4.7.4223

File size:
2.5 MB (2,654,432 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
3/17/2005 12:31:50 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:K1dlZozI6QbVZS/zMQh/qp0Rhd0Xs59rOiZog9xpyq0ljKNVyocTKnNtTO1lGVBv:K1dl2LQbV4hCO08/rOcPEqk6VyocTKnL

Entry address:
0x7481

Entry point:
55, 8B, EC, 6A, FF, 68, F0, E7, 40, 00, 68, C4, AD, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 84, E0, 40, 00, 33, D2, 8A, D4, 89, 15, E0, 52, 41, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, DC, 52, 41, 00, C1, E1, 08, 03, CA, 89, 0D, D8, 52, 41, 00, C1, E8, 10, A3, D4, 52, 41, 00, 33, F6, 56, E8, F6, 23, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, 16, 02, 00, 00, FF, 15, 80, E0, 40, 00, A3, E4, 69, 41, 00, E8...
 
[+]

Entropy:
7.9180

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
52 KB (53,248 bytes)

The file coolhackv1.exe has been seen being distributed by the following URL.

Remove coolhackv1.exe - Powered by Reason Core Security