fax_390392029_072514.exe

The executable fax_390392029_072514.exe has been detected as malware by 33 anti-virus scanners. The file has been seen being downloaded from seife.hosting.paran.com.
MD5:
4ba43f0b82f86efed437c8523f7a4dee

SHA-1:
356b21b749c8bc5e2295a3db62ea03c47cb4c1cf

Scanner detections:
33 / 68

Status:
Malware

Analysis date:
5/4/2024 5:15:02 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1777873
895

Agnitum Outpost
Backdoor.Androm
7.1.1

AhnLab V3 Security
Backdoor/Win32.Qadars
2014.08.22

Avira AntiVirus
TR/Dyreza.A.1
7.11.168.180

avast!
Win32:Malware-gen
2014.9-140824

AVG
SHeur4
2015.0.3373

Baidu Antivirus
Backdoor.Win32.Androm
4.0.3.14824

Bitdefender
Trojan.GenericKD.1777873
1.0.20.1180

Dr.Web
Trojan.Dyre.1
9.0.1.0236

Emsisoft Anti-Malware
Backdoor.Win32.Androm
8.14.08.24.09

ESET NOD32
Win32/Battdil
8.10296

Fortinet FortiGate
W32/Androm.EPMJ!tr.bdr
8/24/2014

F-Secure
Trojan.GenericKD.1777873
11.2014-24-08_1

G Data
Trojan.GenericKD.1777873
14.8.24

IKARUS anti.virus
Backdoor.Win32.Androm
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.183.13125

Kaspersky
Backdoor.Win32.Androm
14.0.0.3358

Malwarebytes
Spyware.Dyre
v2014.08.24.09

McAfee
RDN/Generic BackDoor!zf
5600.7029

Microsoft Security Essentials
Trojan:Win32/Dynamer!ac
1.10904

MicroWorld eScan
Trojan.GenericKD.1777873
15.0.0.708

NANO AntiVirus
Trojan.Win32.Androm.ddieta
0.28.2.61721

nProtect
Trojan.GenericKD.1777873
14.08.22.01

Panda Antivirus
Trj/Genetic.gen
14.08.24.09

Qihoo 360 Security
Win32/Trojan.5b5
1.0.0.1015

Quick Heal
Backdoor.Androm.r4
8.14.14.00

Sophos
Troj/Agent-AIBT
4.98

Total Defense
Win32/Tnega.SFFPWL
37.0.11136

Trend Micro House Call
BKDR_ANDROM.TFD805
7.2.236

Trend Micro
BKDR_ANDROM.TFD805
10.465.24

Vba32 AntiVirus
Backdoor.Androm
3.12.26.3

VIPRE Antivirus
Win32.Malware!Drop
32440

Zillya! Antivirus
Backdoor.Androm.Win32.10172
2.0.0.1897

File size:
276.5 KB (283,136 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
7/25/2014 4:45:19 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:NYIPjoJyR6dNNdUvw9IbxQi2qJ+4DhYxrtaDi:NY/eP9j2LvxaDi

Entry address:
0x3ECA0

Entry point:
55, 8B, EC, 6A, FF, 68, E8, 28, 44, 00, 68, E0, EE, 43, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, C4, 98, 53, 56, 57, 89, 65, E8, C7, 45, FC, 00, 00, 00, 00, 6A, 02, FF, 15, A4, 02, 44, 00, 83, C4, 04, C7, 05, CC, 66, 44, 00, FF, FF, FF, FF, C7, 05, D0, 66, 44, 00, FF, FF, FF, FF, FF, 15, A8, 02, 44, 00, 8B, 0D, B8, 66, 44, 00, 89, 08, FF, 15, AC, 02, 44, 00, 8B, 15, B4, 66, 44, 00, 89, 10, A1, B0, 02, 44, 00, 8B, 08, 89, 0D, C8, 66, 44, 00, E8, 36, 05, FE, FF, A1, 70, 61, 44, 00, 85...
 
[+]

Entropy:
6.5268

Developed / compiled with:
Microsoft Visual C++

Code size:
249 KB (254,976 bytes)

The file fax_390392029_072514.exe has been seen being distributed by the following URL.

Remove fax_390392029_072514.exe - Powered by Reason Core Security