ets2-alexandereliot.exe

The executable ets2-alexandereliot.exe has been detected as malware by 13 anti-virus scanners.
MD5:
5d88191d86f057c089401eb7d3ba9078

SHA-1:
3c7493fa2a361f2c12e4cdb5e21d345c5f4b4cdb

SHA-256:
43fe4a012c4d376b089174ed6cec79a8f5ab2e1cc21eba95f24e56b04f722d75

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
4/24/2024 10:16:14 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Malware-gen
2014.9-140822

Bkav FE
HW32.CDB
1.3.0.4959

Clam AntiVirus
Trojan.DNSchanger-163
0.98/19168

Dr.Web
infected with Trojan.DownLoader10.63222
9.0.1.0234

ESET NOD32
Win32/HackTool.CheatEngine.AL potentially unsafe application
7.0.302.0

F-Prot
W32/GenTroj.BA3.gen
4.6.5.141

K7 AntiVirus
Riskware
13.176.11510

NANO AntiVirus
Trojan.Win32.DownLoader10.cxrpww
0.28.0.59911

Norman
CheatEngine.AB
11.20140822

Qihoo 360 Security
Malware.QVM05.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.8.22.21

Sophos
Mal/Generic-S
4.98

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

File size:
753.1 KB (771,125 bytes)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
9/7/2013 9:57:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.50

CTPH (ssdeep):
12288:XMBepk4+a2aWYw6Qge0BdkkZIUA2Jalm+h4dMkkAkDJBV1Ls2LMpB8aUH0C:XpMa2aWYw6jp2UqD4ibDJBV1Ls2wBPUD

Entry address:
0x1000

Entry point:
68, 8C, 00, 00, 00, 68, 00, 00, 00, 00, 68, 70, BE, 4A, 00, E8, 2C, 10, 00, 00, 83, C4, 0C, 68, 00, 00, 00, 00, E8, 25, 10, 00, 00, A3, 74, BE, 4A, 00, 68, 00, 00, 00, 00, 68, 00, 10, 00, 00, 68, 00, 00, 00, 00, E8, 12, 10, 00, 00, A3, 70, BE, 4A, 00, E8, DC, 3D, 00, 00, E8, 7B, 3D, 00, 00, E8, 12, 34, 00, 00, E8, 72, 32, 00, 00, E8, 68, 31, 00, 00, E8, 1F, 2C, 00, 00, E8, DE, 2A, 00, 00, E8, 2A, 21, 00, 00, E8, B0, 11, 00, 00, A1, 08, BF, 4A, 00, 50, 50, E8, 20, 2C, 00, 00, 8D, 0D, 7C, BE, 4A, 00, 5A, E8...
 
[+]

Entropy:
6.9681

Packer / compiler:
PKLITE32, 0x1.1

Code size:
17 KB (17,408 bytes)

Remove ets2-alexandereliot.exe - Powered by Reason Core Security