Generatore M3U Playlist.exe

Generatore M3U Playlist

This is a setup program which is used to install the application. The file has been seen being downloaded from www.filedropper.com.
Product:
Generatore M3U Playlist

Version:
1.0.0.0

MD5:
c38fc7af2f39c75ca6dd26ce9c905945

SHA-1:
2b9f8b5b73d88d1e15e64c3f41c3957cbb109bf6

SHA-256:
99b524daa17f5e535f24d63193d680d6aa585f00088beed79a73f35845a8e813

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/7/2024 12:57:48 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/ATRAPS.Gen
7.11.206.68

IKARUS anti.virus
Trojan.ATRAPS
t3scan.1.8.6.0

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Trend Micro House Call
Suspicious_GEN.F47V0105
7.2.238

File size:
581.9 KB (595,832 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © SatNewbie 2015

Original file name:
Generatore M3U Playlist.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\generatore m3u playlist.exe

File PE Metadata
Compilation timestamp:
1/2/2015 2:56:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:0YVttvqW955SY5z0WbmuqcGc3Tl61g0qTohMUwDTab:0YVniqSMz7bPqCp0/qneb

Entry address:
0x3068E

Entry point:
FF, 25, 00, 20, 40, 00, BE, 05, 29, 0E, 31, 1B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
186 KB (190,464 bytes)

The file Generatore M3U Playlist.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ns265.altervista.org  (85.10.204.133:80)

Scan Generatore M3U Playlist.exe - Powered by Reason Core Security