e-deklaracje-wtyczka.exe

Wtyczka e-Deklaracje

Ministerstwo Finansów

The executable e-deklaracje-wtyczka.exe, “Wtyczka e-Deklaracje do programu Adobe Reader/Acrobat ” has been detected as malware by 9 anti-virus scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from www.finanse.mf.gov.pl.
Publisher:
Ministerstwo Finansów

Product:
Wtyczka e-Deklaracje

Description:
Wtyczka e-Deklaracje do programu Adobe Reader/Acrobat

Version:
4.1.0.0

MD5:
113312b7269ee8fea605dba39bb24813

SHA-1:
d6bd94fede68dee168d289d3d37e95cef7bca734

SHA-256:
7a38a90fb6e0f41da9b6829e261495c3312b1eeb28a7965beffdc6ae095a0979

Scanner detections:
9 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 6:36:52 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160215-2

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.215.1434.0

VIPRE Antivirus
Threat.4721115
47848

File size:
1.3 MB (1,383,456 bytes)

Product version:
4.1.0

Copyright:
© Ministerstwo Finansów

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\documents and settings\admn\moje dokumenty\downloads\e-deklaracje-wtyczka.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:VnaiSMoCAFYIaY3QHga1glhDR9PC+rbEXhjO5mfKAZ6k17HR6vWaie:VaV/CAFTFQHgaGJrbEXhjtiN8HR6Oa3

Entry address:
0x9C40

Entry point:
0F, B6, C7, 80, F9, AE, 8A, F0, 71, 0B, 8D, 15, 2D, FE, FF, F1, 0F, AF, CB, FF, C8, 69, DA, 6A, 51, 17, 83, F7, C3, B0, 6E, 15, CB, 87, F6, 88, C1, 8B, DA, 15, 68, 6C, A4, 84, B8, 4A, A3, 88, AF, F2, 0F, B7, FB, 69, C5, 18, 75, C4, 28, 8D, 1D, D7, 7E, 00, 00, 86, CD, 8B, F1, 0F, AF, F7, 81, C3, CB, 0A, 00, 00, 78, 0B, 0F, AF, F5, C6, C6, B1, BE, 17, 4E, C9, EE, 33, EB, 8D, 3D, D9, 87, 03, 5C, 0F, AF, D9, C7, C1, 56, AA, 5A, F6, C7, C0, 4F, E9, 7D, 7C, EB, 03, 0F, AF, C6, 83, E0, 00, 45, 69, D3, B3, DB, A9...
 
[+]

Code size:
37 KB (37,888 bytes)

The file e-deklaracje-wtyczka.exe has been seen being distributed by the following URL.

Remove e-deklaracje-wtyczka.exe - Powered by Reason Core Security