echoofsoul_us_downloader.exe

Downloader

Aeria Games & Entertainment

The executable echoofsoul_us_downloader.exe has been detected as malware by 14 anti-virus scanners. This is a setup program which is used to install the application. Infected by the Parite virus, a polymorphic file infecting virus that infects all portable EXE and SCR files found on local and shared network drives. The file has been seen being downloaded from download.aeriagames.com.
Publisher:
Aeria Games & Entertainment

Product:
Downloader

Version:
2,1,0,0

MD5:
a2211e8a2295d20dee7dc0c181f6caf7

SHA-1:
1e226231a36abe9730a7d81241e4537cc0cc8792

SHA-256:
4dff73c2a69aff30c300e2f8492803b4780e06e6a3d8232fa9c1d4005b0d7bc6

Scanner detections:
14 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/19/2024 9:34:11 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Parite.B
5813571

avast!
Win32:Parite
160119-0

AVG
Win32/Parite
2015.0.4489

Clam AntiVirus
Heuristics.W32.Parite.B
0.98/21286

Dr.Web
Win32.Parite.2
9.0.1.05190

Emsisoft Anti-Malware
Win32.Parite
10.0.0.5366

ESET NOD32
Win32/Parite.B virus
7.0.302.0

F-Prot
W32/Parite.B
4.6.5.141

Kaspersky
Virus.Win32.Parite
15.0.0.562

McAfee
Virus.W32/Pate.b
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.3521.0

Norman
Win32.Parite.B
11.01.2016 17:30:26

Sophos
Virus 'W32/Parite-B'
5.22

VIPRE Antivirus
Threat.46249
46426

File size:
668 KB (683,988 bytes)

Product version:
2,1,4992,0

Copyright:
© 2012 Aeria Games & Entertainment, Inc.

Original file name:
Downloader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\echoofsoul_us_downloader.exe

File PE Metadata
Compilation timestamp:
4/29/2015 2:49:25 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:cJE6RsyxSysH6FQaBL7kw5aTw2EKSxmH8dkIan04m9/uwt8bkgaLEJ7:g8yo56eq7kwoTw2YmhR04NLbsLEJ7

Entry address:
0x80000

Entry point:
90, 90, BB, E8, B5, 2D, 06, BE, 1A, 00, 48, 00, 90, 68, 98, 05, 00, 00, 5A, 31, 1C, 32, 90, 4A, 83, EA, 03, 75, F6, 90, 00, C8, 2C, 06, E8, B5, 2D, 06, E8, B5, 6D, 06, 59, AF, 2F, 06, F0, 0D, 2A, 06, 3C, 0A, 2A, 06, E8, 05, 2F, 06, E9, B5, 2D, 06, 58, 85, 6E, 06, 72, 4B, 6E, 06, 5A, 4B, 6E, 06, 9C, 51, 2E, 06, 70, 4B, 2E, 06, 58, 4B, 2E, 06, 58, AB, 2E, 06, 70, 4B, 2E, 06, 58, 4B, 2E, 06, E8, B5, 2D, 06, E8, B5, 2D, 06, E8, B5, 2D, 06, E8, B5, 2D, 06, E8, B5, 2D, 06, E8, B5, 2D, 06, E8, B5, 2D, 06, E8, B5...
 
[+]

Code size:
198.5 KB (203,264 bytes)

The file echoofsoul_us_downloader.exe has been seen being distributed by the following URL.

Remove echoofsoul_us_downloader.exe - Powered by Reason Core Security