crazyhacker_wallhack.exe

Ezoric1

The executable crazyhacker_wallhack.exe has been detected as malware by 29 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from rghost.net.
Product:
Ezoric1

Version:
1.0.0.0

MD5:
e14f20b43f64d8fc135edd64ed89c5ba

SHA-1:
4c8fd9c31961230ac8bdf977d9e520d7b6cc5d56

SHA-256:
6700beae5ef07bca14b4be0ff9ca350a451532646f15ffe31f67d372f1895b9d

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
4/26/2024 8:32:06 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKDZ.28903
599

Agnitum Outpost
Trojan.Agent
7.1.1

AhnLab V3 Security
Trojan/Win32.Ranos
2015.06.16

Avira AntiVirus
TR/Inject.sbbeijv
8.3.1.6

Arcabit
Trojan.Generic.D70E7
1.0.0.425

avast!
MSIL:Crypt-YJ [Trj]
2014.9-150616

AVG
MSIL8
2016.0.3077

Baidu Antivirus
Trojan.MSIL.Injector
4.0.3.15616

Bitdefender
Trojan.GenericKDZ.28903
1.0.20.835

Dr.Web
Trojan.Packed.29758
9.0.1.0167

Emsisoft Anti-Malware
Trojan.GenericKDZ.28903
8.15.06.16.08

ESET NOD32
MSIL/Injector.JVY (variant)
9.11789

Fortinet FortiGate
W32/Generic!tr
6/16/2015

F-Prot
W32/MSIL_Injector.T.gen
v6.4.7.1.166

F-Secure
Trojan.GenericKDZ.28903
11.2015-16-06_3

G Data
Trojan.GenericKDZ.28903
15.6.25

IKARUS anti.virus
Trojan.MSIL.Injector
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.205.16249

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.1878

Malwarebytes
Trojan.Injector.RBX
v2015.06.16.08

McAfee
Artemis!E14F20B43F64
5600.6733

Microsoft Security Essentials
Backdoor:MSIL/Noancooe.C
1.1.11701.0

MicroWorld eScan
Trojan.GenericKDZ.28903
16.0.0.501

nProtect
Trojan.GenericKDZ.28903
15.06.15.01

Panda Antivirus
Trj/CI.A
15.06.16.08

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R047H07FA15
7.2.167

VIPRE Antivirus
Trojan.Win32.Generic
41158

File size:
380.5 KB (389,632 bytes)

Product version:
1.0.0.0

Copyright:
Copyright ©Ezoric1 2015

Original file name:
Ezoric1.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
6/4/2015 1:15:19 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:N8SnhLAOnXmulebWizwUJL9Gr2afh/pBIcCJt10aqvK1rjCDYJ7qNy4lNk7ICREs:xnhHnWul0cUJLbEhHIDnVBPCDYgN5q7b

Entry address:
0x606BE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
378 KB (387,072 bytes)

The file crazyhacker_wallhack.exe has been seen being distributed by the following URL.

Remove crazyhacker_wallhack.exe - Powered by Reason Core Security