ddwrt-quicksetup.exe

The executable ddwrt-quicksetup.exe has been detected as malware by 5 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from torguard.net.
Version:
4.0.0.0

MD5:
79e0fa683a6b9df6e5693feddd33fc83

SHA-1:
34c4626a093ee3889ac27d222ebcc3bd6affc356

SHA-256:
b197ccaa60fd1234bb1a27c8ac83d4ba6b476a8c7cff97308df700801419ba0f

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
4/25/2024 11:03:27 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Agent.10756558
8.3.1.6

avast!
Win32:Malware-gen
150707-1

Dr.Web
Trojan.DownLoader11.24145
9.0.1.05190

McAfee
Artemis!79E0FA683A6B
5600.6703

Qihoo 360 Security
Win32/Trojan.b77
1.0.0.1015

File size:
10.3 MB (10,756,558 bytes)

Product version:
4.0.0.0

Copyright:
Copyright © 2012

Original file name:
Bot.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ddwrt-quicksetup.exe

File PE Metadata
Compilation timestamp:
6/23/2014 8:17:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
196608:o7c3KPgooPJxcKbLfhVJJpnGs03/ryc82bK2n7tXXLKGVAH+0:o7c3KP5AcK/fLDpny3/ryqK87tX7Y7

Entry address:
0x64F8A2

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8621

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
6.3 MB (6,609,408 bytes)

The file ddwrt-quicksetup.exe has been seen being distributed by the following URL.

Remove ddwrt-quicksetup.exe - Powered by Reason Core Security