{blocked}.exe

The executable {blocked}.exe has been detected as malware by 35 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from chelmonline.pl.
MD5:
5ace9017105a67699c04f34812b6c055

SHA-1:
9f99291048b2e823dee5553d01e2634b39208c22

SHA-256:
14e428afbba3a3b677c31d266e968d42def16bd55e645575e8948112ce3c476d

Scanner detections:
35 / 68

Status:
Malware

Analysis date:
5/5/2024 12:53:00 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Inject.AQQ
885

Agnitum Outpost
Trojan.Inject
7.1.1

AhnLab V3 Security
Trojan/Win32.Ransomlock
2014.08.14

Avira AntiVirus
TR/Crypt.ZPACK.67692
7.11.146.148

avast!
Win32:Injector-BRZ [Trj]
2014.9-140902

AVG
Cryptic
2015.0.3483

Baidu Antivirus
Trojan.Win32.Injector
4.0.3.1492

Bitdefender
Trojan.Inject.AQQ
1.0.20.1225

Comodo Security
UnclassifiedMalware
19186

Emsisoft Anti-Malware
Trojan.Inject.AQQ
8.14.09.02.05

ESET NOD32
Win32/Injector.BCXR (variant)
8.9745

Fortinet FortiGate
W32/Injector.BCKP!tr
9/2/2014

F-Secure
Trojan.Inject.AQQ
11.2014-02-09_3

G Data
Trojan.Inject.AQQ
14.9.24

IKARUS anti.virus
Trojan-Spy.Zbot
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.183.13043

Kaspersky
Trojan.Win32.Inject
14.0.0.3912

Malwarebytes
Spyware.ZeuS
v2014.05.05.04

McAfee
RDN/Spybot.bfr!l
5600.7019

Microsoft Security Essentials
VirTool:Win32/Injector.gen!ET
1.10802

MicroWorld eScan
Trojan.Inject.AQQ
15.0.0.735

NANO AntiVirus
Trojan.Win32.Inject.cxbldm
0.28.2.61519

Norman
Agent.BCFRL
11.20140902

nProtect
Trojan.Inject.AQQ
14.08.13.01

Panda Antivirus
Trj/Genetic.gen
14.09.02.05

Qihoo 360 Security
HEUR/Malware.QVM19.Gen
1.0.0.1015

Quick Heal
Trojan.Inject.r4
9.14.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.2.17

Sophos
Mal/Zbot-QT
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Refroso
10384

Trend Micro House Call
TROJ_GEN.F47V0501
7.2.125

Trend Micro
TROJ_SPNR.11EM14
10.465.02

Vba32 AntiVirus
TrojanSpy.Zbot
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
32204

ViRobot
Trojan.Win32.U.Downloader.483840
2011.4.7.4223

File size:
180 KB (184,320 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\hot_image_collection_001.jpg.exe

File PE Metadata
Compilation timestamp:
5/1/2014 9:34:28 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
3.0

CTPH (ssdeep):
3072:MWNoc9k4M19D/uVyVziax9RzCfU8CM9PYJoT/pNQcAH036jlMFoKD:h9kN9Tu0hi8zCFCMCODvQcACo+

Entry address:
0x3671

Entry point:
55, 8B, EC, E8, 57, DC, FF, FF, 8B, 4C, 24, 08, 8D, 86, 00, 02, 00, 00, E8, DD, FB, FF, FF, 8B, 4C, 24, 0C, 8D, 86, 00, 01, 00, 00, E8, CE, FB, FF, FF, 6A, 10, 8D, 86, 84, 01, 00, 00, 8D, 8E, 7C, 01, 00, 00, 5A, 8B, 71, FC, 89, 70, FC, 8B, 31, 89, 30, 8B, B1, FC, 00, 00, 00, 89, B0, FC, FE, FF, FF, 8B, B1, 00, 01, 00, 00, 89, B0, 00, FF, FF, FF, 8B, B1, FC, FE, FF, FF, 89, B0, FC, 00, 00, 00, 8B, B1, 00, FF, FF, FF, 89, B0, 00, 01, 00, 00, 83, C0, 08, 83, E9, 08, 4A, 75, BD, 33, C0, 5E, 6A, 0A, 58, 50, 56...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
12 KB (12,288 bytes)

The file {blocked}.exe has been seen being distributed by the following URL.

Remove {blocked}.exe - Powered by Reason Core Security