downloader.exe

eScriptionDownloader

Axiom Technologies

The executable downloader.exe has been detected as malware by 11 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from sharp.escriptionasp.com.
Publisher:
Axiom Technologies

Product:
eScriptionDownloader

Version:
10.08

MD5:
fdaeae4606f62f9e1b9a0aa81f0038ee

SHA-1:
7b540f3d30cfd15036a9fe199b758503389d3fe8

SHA-256:
a63be24ee25157e1d1cbdb414d361d1e218c71838409284c0f7b169f9a2a32f1

Scanner detections:
11 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
7/17/2025 2:24:11 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
150717-0

AVG
Win32/Sality
2015.0.4355

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Trojan.Artemis!F415CF9520D7
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.217.1672.0

Norman
Win32.Sality.3
02.04.2016 17:35:19

VIPRE Antivirus
Threat.4721115
47854

File size:
348.1 KB (356,425 bytes)

Product version:
10.08

Original file name:
eScriptionDownloader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\downloader.exe

File PE Metadata
Compilation timestamp:
11/7/2012 12:31:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:n+3oVgE5u9iHzubHh6Z4AcgvlsBNv1w2NO3w08B91EcBsp1scViwzmjfum8aM3Un:+44W1/aChhxfEfr

Entry address:
0x72DC

Entry point:
C7, C1, 46, 93, 60, 5C, 86, C0, 8A, E2, 68, FF, 4E, 2B, 00, 68, 71, EA, 65, 00, 69, DF, 4F, 52, 35, 4D, 49, 0F, AF, EE, 45, 68, BD, 1F, 51, 00, 55, 8D, 15, 1A, E8, 59, 88, 84, FA, 86, DD, 0B, FA, C7, C6, 8C, 2B, 25, 26, 69, C7, EA, 1D, 77, 0B, E8, 00, 00, 00, 00, 0F, AF, F2, 70, 02, FE, C1, 80, D6, A8, 3A, FB, 3D, 5C, 24, 00, 00, 5B, 88, E1, 89, D6, 13, EB, 0F, AF, C0, 8D, 35, 3C, EE, 2D, BA, 89, DF, 87, D7, F3, 86, C5, BD, 55, F1, 00, 00, 69, FA, CB, E4, 6E, 2C, 81, F5, 90, 28, 00, 00, 3D, DA, E5, 00, 00...
 
[+]

Entropy:
6.3332

Code size:
256 KB (262,144 bytes)

The file downloader.exe has been seen being distributed by the following URL.

Remove downloader.exe - Powered by Reason Core Security