Droop.exe

Dapples Fireballs

Zhejiang University

The file Droop.exe has been detected as malware by 31 anti-virus scanners.
Publisher:
Zhejiang University

Product:
Dapples Fireballs

Description:
Geldings

Version:
182, 179, 65, 84

MD5:
fb81a902450be169d597b6ec18d03c68

SHA-1:
f406ef322a086538197a2c1da3d49032d5f938b2

SHA-256:
57eed2c8b604057172423ff3196ff6a6c6879ec071972861b93e7c56148ad56b

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
4/24/2024 4:32:10 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2456659
577

Agnitum Outpost
Trojan.Filecoder
7.1.1

AhnLab V3 Security
Trojan/Win32.Agent
2015.06.16

Avira AntiVirus
TR/Crowti.A.349
8.3.1.6

Arcabit
Trojan.Generic.D257C53
1.0.0.425

avast!
Win32:Malware-gen
2014.9-150707

AVG
Inject2
2016.0.3055

Baidu Antivirus
Trojan.Win32.Filecoder
4.0.3.1577

Bitdefender
Trojan.GenericKD.2456659
1.0.20.940

Dr.Web
Trojan.Encoder.514
9.0.1.0188

Emsisoft Anti-Malware
Trojan.GenericKD.2456659
8.15.07.07.03

ESET NOD32
Win32/Filecoder.CO
9.11790

Fortinet FortiGate
W32/Filecoder.CO!tr
7/7/2015

F-Secure
Trojan.GenericKD.2456659
11.2015-07-07_3

G Data
Trojan.GenericKD.2456659
15.7.25

IKARUS anti.virus
Trojan.Win32.Filecoder
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.205.16251

Malwarebytes
Trojan.Agent.FKRVED
v2015.07.07.03

McAfee
RDN/Generic.cf!a
5600.6711

Microsoft Security Essentials
Ransom:Win32/Crowti
1.1.11701.0

MicroWorld eScan
Trojan.GenericKD.2456659
16.0.0.564

NANO AntiVirus
Trojan.Win32.Encoder.dsnmje
0.30.24.2086

nProtect
Trojan.GenericKD.2456659
15.06.15.01

Panda Antivirus
Trj/Chgt.O
15.07.07.03

Qihoo 360 Security
Win32/Trojan.fbb
1.0.0.1015

Quick Heal
Ransom.Crowti.r4
7.15.14.00

Sophos
Mal/Generic-L
4.98

Trend Micro House Call
TROJ_GEN.R06AC0DF815
7.2.188

Trend Micro
TROJ_GEN.R06AC0DF815
10.465.07

VIPRE Antivirus
Trojan.Win32.Generic
41164

ViRobot
Trojan.Win32.S.Agent.192512.ADW[h]
2014.3.20.0

File size:
188 KB (192,512 bytes)

Product version:
60, 165, 146, 236

Copyright:
Copyright © Impertinent

Original file name:
Droop.exe

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\appdata\local\temp\f780.tmp

File PE Metadata
Compilation timestamp:
6/3/2005 7:05:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:GAIiXiDRoBPJPYf2o95DVESfD7+nCDSGteRb7TiKoLbaDftZRB:tIiXilihQ2o1Es7+se6KoLcHRB

Entry address:
0x14D8A

Entry point:
55, 8B, EC, 6A, FF, 68, B0, 54, 41, 00, 68, 10, 4F, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 44, 52, 41, 00, 59, 83, 0D, E4, 7C, 45, 00, FF, 83, 0D, E8, 7C, 45, 00, FF, FF, 15, 48, 52, 41, 00, 8B, 0D, E0, 7C, 45, 00, 89, 08, FF, 15, 4C, 52, 41, 00, 8B, 0D, DC, 7C, 45, 00, 89, 08, A1, 50, 52, 41, 00, 8B, 00, A3, EC, 7C, 45, 00, E8, 10, 01, 00, 00, 39, 1D, C0, 7C, 41, 00, 75, 0C, 68, 06, 4F, 41, 00, FF, 15, 54, 52...
 
[+]

Entropy:
7.2344

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
80 KB (81,920 bytes)

Remove Droop.exe - Powered by Reason Core Security