easy_resize_jpegs_by_folder.exe

Win

Microsoft

The executable easy_resize_jpegs_by_folder.exe has been detected as malware by 9 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from h.nawrocki.free.fr.
Publisher:
Microsoft

Product:
Win

Version:
1.00

MD5:
826e40428bd40bf55465714e14067b2f

SHA-1:
04f22aa325a0110865912985393257c8db759952

SHA-256:
9b5f704f37bb40242c34a599508c5f02f1b015817b4633e1e8457a6882fb23c1

Scanner detections:
9 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
5/30/2024 3:26:26 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160518-2

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.96

Kaspersky
Virus.Win32.Sality
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.223.1286.0

Norman
Win32.Sality.3
22.05.2016 07:18:28

File size:
2.1 MB (2,207,218 bytes)

Product version:
1.00

Original file name:
Win.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
6/15/2011 2:01:16 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:I5xolYQY6s5LOJFh6Q+5djnNPbkhtd9hn2EldibD3qRz1bu0kX1sA7SIhWmQcTmq:jY7O+ahdS3AzkIA73TAIcqE0PNhF

Entry address:
0x3670

Entry point:
22, C4, 41, 87, E8, 56, 69, DD, E5, 76, 19, 28, 3B, FB, 8B, C5, F6, C2, 13, FF, CF, FF, C8, 8B, E9, F7, C2, 92, 59, 6F, CE, 00, FE, E8, 48, 00, 00, 00, 8D, 05, AA, 4E, D0, 9B, 88, C5, 8D, 35, C3, F4, 9D, 87, 47, 24, 66, 23, C7, 69, C1, 5D, 48, 61, 7B, 24, A5, F2, 8D, 55, 00, 86, CF, 81, EF, 86, C4, B3, EC, 85, FE, 8A, FA, 0F, BE, FB, 2B, ED, 85, F5, 71, 0D, F7, C1, 82, C1, 9F, 20, F2, F7, C1, 7C, DE, 81, E6, 33, EA, 85, D1, 74, 01, F2, 5E, 0F, AF, C6, 8D, 0D, CC, 75, 06, 0A, 0F, AF, FB, 53, 68, 47, D8, EE...
 
[+]

Entropy:
6.6415

Code size:
172 KB (176,128 bytes)

The file easy_resize_jpegs_by_folder.exe has been seen being distributed by the following URL.

Remove easy_resize_jpegs_by_folder.exe - Powered by Reason Core Security