inquiry_201500303_0011637-pdf.exe

berea

The executable inquiry_201500303_0011637-pdf.exe, “ Performance Adapter” has been detected as malware by 34 anti-virus scanners.
Product:
berea

Description:
Performance Adapter

Version:
1.0.0.0

MD5:
d56dcf875fcb05b409a310fa66498153

SHA-1:
cd44465428c808aed729849e0ae072535096ac06

SHA-256:
590163dbb98e182f24510bf8a34dbb63a94b3a8c7705202d001c5d347861c71c

Scanner detections:
34 / 68

Status:
Malware

Analysis date:
4/23/2024 1:48:12 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2196589
623

Agnitum Outpost
Trojan.PWS.Fareit
7.1.1

AhnLab V3 Security
Trojan/Win32.MDA
2015.04.22

Avira AntiVirus
TR/Dropper.MSIL.128169
3.6.1.96

avast!
MSIL:GenMalicious-DYV [Trj]
2014.9-150522

AVG
MSIL7
2016.0.3101

Baidu Antivirus
Trojan.Win32.InfoStealer
4.0.3.15522

Bitdefender
Trojan.GenericKD.2196589
1.0.20.710

Comodo Security
UnclassifiedMalware
21853

Dr.Web
Trojan.PWS.Siggen1.29435
9.0.1.0142

Emsisoft Anti-Malware
Trojan.GenericKD.2196589
8.15.05.22.02

ESET NOD32
MSIL/Injector.IFN (variant)
9.11515

Fortinet FortiGate
MSIL/IFN!tr
5/22/2015

F-Prot
W32/MSIL_Injector.I.gen
v6.4.7.1.166

F-Secure
Trojan.GenericKD.2196589
11.2015-22-05_6

G Data
Trojan.GenericKD.2196589
15.5.25

IKARUS anti.virus
Trojan.MSIL.Injector
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.203.15674

Kaspersky
Trojan-PSW.Win32.Fareit
14.0.0.2002

Malwarebytes
Trojan.MSIL
v2015.05.22.02

McAfee
Trojan-FFWF!D56DCF875FCB
5600.6757

Microsoft Security Essentials
PWS:Win32/Fareit
1.1.11602.0

MicroWorld eScan
Trojan.GenericKD.2196589
16.0.0.426

NANO AntiVirus
Trojan.Win32.Fareit.doumae
0.30.20.1219

Norman
Troj_Generic.YYREU
11.20150522

nProtect
Trojan.GenericKD.2196589
15.04.22.01

Panda Antivirus
Trj/CI.A
15.05.22.02

Quick Heal
TrojanPWS.Fareit.r3
5.15.14.00

Sophos
Troj/MSIL-BYK
4.98

Trend Micro House Call
TROJ_MOSERAN.BME
7.2.142

Trend Micro
TROJ_MOSERAN.BME
10.465.22

Vba32 AntiVirus
TScope.Trojan.MSIL
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
39576

ViRobot
Trojan.Win32.A.PSW-Fareit.889344[h]
2014.3.20.0

File size:
868.5 KB (889,344 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
berea.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\inquiry_201500303_0011637-pdf.exe

File PE Metadata
Compilation timestamp:
3/3/2015 2:37:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:XKs+QktHAh5eUlVN8KMwA+4Y/VloXUdwTW/hdQb4E0Yj+50K1nTvpOiUW5:Xvh5nVN8WAZnChdQb4E0hFyt

Entry address:
0x1FADE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6239

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
119 KB (121,856 bytes)

Remove inquiry_201500303_0011637-pdf.exe - Powered by Reason Core Security