hack pb.exe

The executable hack pb.exe has been detected as malware by 2 anti-virus scanners. This is a setup program which is used to install the application. This backdoor trojan may be used to conduct distributed denial of service attacks, or used to install additional trojans or other forms of malicious software as well as can steal your sensitive information. The file has been seen being downloaded from fs04n4.sendspace.com.
MD5:
8e82211134aee782a7eb58cf6593fe7f

SHA-1:
da953cab6668b4d481918c00b2c2f6f93a82c642

SHA-256:
44bc05b95fd01c43c89a5c4cafef6bafa54d35051cb58316fe9be867050855e7

Scanner detections:
2 / 68

Status:
Malware

Analysis date:
4/19/2024 10:45:23 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/Bladabindi.AS trojan
6.3

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi.AJ
1.225.3019.0

File size:
95.6 KB (97,883 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\hack pb.exe

File PE Metadata
Compilation timestamp:
7/31/2016 8:16:19 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:IYxgb7RuDt8zPb0vJA8E3r/Txr/xjMotnXnrl:3xgxBb0vebrdlPhXnJ

Entry address:
0x890E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
26.5 KB (27,136 bytes)

The file hack pb.exe has been seen being distributed by the following URL.

Remove hack pb.exe - Powered by Reason Core Security