gالسمكة.exe

The executable gالسمكة.exe has been detected as malware by 9 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
MD5:
88c4e8900f0e265559e9f29500bf8805

SHA-1:
a3fe611235cf0d49235b9170d44185e593d2829f

Scanner detections:
9 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 2:53:23 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160213-1

AVG
Win32/Sality
2015.0.4522

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Norman
Win32.Sality.3
08.02.2016 04:24:12

VIPRE Antivirus
Threat.4721115
47068

File size:
2.2 MB (2,260,992 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
4/19/2013 8:47:28 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:3PcDTzFY2Ot5fV4t2/M2KHW9qRwdRpl50P127j6wZr9C:ce204T2KH+qGd50P47eR

Entry address:
0x18F77

Entry point:
88, D5, 86, D5, 69, C9, B7, 26, ED, 1E, 68, 15, E1, F2, 00, 52, EB, 07, 38, EF, 8B, EF, 0F, AF, D1, C6, C5, E6, 3A, DB, 04, 44, 4D, EB, 05, BD, DA, 4F, 30, AA, 0F, AF, C0, 8B, FF, 3C, AF, 08, F1, C6, C5, 66, 0D, 09, 3A, E0, 34, 46, 2B, D7, 85, C8, 78, 08, BE, A0, FE, CB, 28, 0F, BF, DF, 8B, E8, 39, F5, 12, E9, C6, C7, 03, C6, C2, 66, 69, C7, 70, 68, DF, 60, 8A, C2, 85, DA, 3C, 7C, E8, 25, 00, 00, 00, 8D, 15, 18, 5D, 00, 10, FE, CA, 4F, 8D, 0D, A7, 44, CC, 69, 33, CB, 89, C9, FE, C7, B8, 3E, A4, 00, 00, C7...
 
[+]

Entropy:
7.8514  (probably packed)

Code size:
156 KB (159,744 bytes)

Remove gالسمكة.exe - Powered by Reason Core Security