enquiry2015031500116387162-pdf.exe

WizLink Application

The executable enquiry2015031500116387162-pdf.exe has been detected as malware by 33 anti-virus scanners.
Product:
WizLink Application

Version:
1, 0, 0, 1

MD5:
393bcda3456106c32928d0beae80d9e2

SHA-1:
7b389bccfee55bc15e58515a41df0f9b234ccc75

SHA-256:
336ee4dd8905271c2f4d4f783e2adc785c6f85fecfa61a2baa6b01c231a25bf5

Scanner detections:
33 / 68

Status:
Malware

Analysis date:
4/27/2024 1:22:31 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2228096
623

Agnitum Outpost
Trojan.PWS.Fareit
7.1.1

AhnLab V3 Security
Trojan/Win32.Fareit
2015.05.04

avast!
Win32:Malware-gen
2014.9-150522

AVG
MSIL7
2016.0.3101

Baidu Antivirus
Trojan.Win32.InfoStealer
4.0.3.15522

Bitdefender
Trojan.GenericKD.2228096
1.0.20.710

Comodo Security
UnclassifiedMalware
21986

Dr.Web
Trojan.PWS.Siggen1.30451
9.0.1.0142

Emsisoft Anti-Malware
Trojan.GenericKD.2228096
8.15.05.22.02

ESET NOD32
Win32/PSW.Fareit
9.11568

Fortinet FortiGate
MSIL/Injector.IOJ!tr
5/22/2015

F-Prot
W32/Backdoor2.HXPS
v6.4.7.1.166

G Data
Trojan.GenericKD.2228096
15.5.25

IKARUS anti.virus
Trojan.MSIL.Injector
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.203.15786

Kaspersky
Trojan-PSW.Win32.Fareit
14.0.0.2002

McAfee
RDN/Generic PWS.y!bd3
5600.6757

Microsoft Security Essentials
PWS:Win32/Fareit
1.1.11602.0

MicroWorld eScan
Trojan.GenericKD.2228096
16.0.0.426

NANO AntiVirus
Trojan.Win32.Fareit.dpkexd
0.30.24.1357

Norman
Troj_Generic.ZKHAB
11.20150522

nProtect
Trojan-PWS/W32.Fareit.479232
15.04.30.01

Panda Antivirus
Trj/WLT.B
15.05.22.02

Qihoo 360 Security
Win32/Trojan.PSW.7cb
1.0.0.1015

Quick Heal
TrojanPWS.Fareit.rw3
5.15.14.00

Sophos
Mal/MSIL-ND
4.98

Total Defense
Win32/Fareit.ROPUfK
37.1.62.1

Trend Micro House Call
TROJ_GEN.R00UC0DCM15
7.2.142

Trend Micro
TROJ_GEN.R00UC0DCM15
10.465.22

Vba32 AntiVirus
TScope.Trojan.MSIL
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
39902

ViRobot
Trojan.Win32.A.PSW-Fareit.479232[h]
2014.3.20.0

File size:
468 KB (479,232 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2008

Original file name:
WizLink.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\enquiry2015031500116387162-pdf.exe

File PE Metadata
Compilation timestamp:
3/15/2015 9:04:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:pltoz9D30EWSB4fDz7MLV5EhEQa36C2PR0uybQG3Yg:pv+WS2Lz7MLV56EQw61R

Entry address:
0x474AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.9824

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
277.5 KB (284,160 bytes)

Remove enquiry2015031500116387162-pdf.exe - Powered by Reason Core Security