iphonelock.vn-v2.exe

iPhoneLock-V2:

iPhoneLock.VN: <Cung cap sim ghep>

The executable iphonelock.vn-v2.exe has been detected as malware by 10 anti-virus scanners. The file has been seen being downloaded from download005.fshare.vn.
Publisher:
iPhoneLock.VN:

Product:
iPhoneLock-V2: <???>

Description:
iPhoneLock-V2

Version:
1.0.0.1

MD5:
8277a03103936bda2fb8a8ec1dc248da

SHA-1:
b399a368db17fc25cc8ac62deb1327d7829d0ee7

SHA-256:
f3f07d758164e28c50880ac0840faf7881eb44061badaf4f1d1ac3cbfb3104ea

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
5/19/2024 12:36:53 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:RmnDrp
160327-1

Dr.Web
Win32.Rmnet
9.0.1.05190

Emsisoft Anti-Malware
Win32.Ramnit
11.5.0.6191

ESET NOD32
Win32/Ramnit.A virus
7.0.302.0

F-Prot
W32/Ramnit.B!Generic
4.6.5.141

F-Secure
Win32.Ramnit
5.15.96

Kaspersky
Virus.Win32.Nimnul
15.0.0.562

McAfee
Virus.W32/Ramnit.a
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.219.596.0

Norman
Win32.Ramnit
02.04.2016 17:35:19

File size:
2.6 MB (2,708,992 bytes)

Product version:
1.0.0.1

Copyright:
Hung 0915501357: (C) <???>????????

Original file name:
GPP.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\iphonelock.vn-v2.exe

File PE Metadata
Compilation timestamp:
5/24/2015 4:29:15 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:Mfdlv8axeDdVs6Ef+foP5v2lggB3HDX5QGWNhv9s54nLS312OVO:yv8UeDdVsrqoP5v2lggVDX5Ehv9ssOQ

Entry address:
0x292000

Entry point:
60, E8, 00, 00, 00, 00, 5D, 8B, C5, 81, ED, 32, 6F, 01, 20, 2B, 85, 50, 72, 01, 20, 89, 85, 4C, 72, 01, 20, B0, 00, 86, 85, 9E, 74, 01, 20, 3C, 01, 0F, 85, DE, 02, 00, 00, 8B, 85, 4C, 72, 01, 20, 2B, 85, 58, 72, 01, 20, 8B, 00, 89, 85, EA, 73, 01, 20, 8B, 85, 4C, 72, 01, 20, 2B, 85, 5C, 72, 01, 20, 8B, 00, 89, 85, F2, 73, 01, 20, 83, BD, F2, 73, 01, 20, 00, 0F, 84, A9, 02, 00, 00, 83, BD, EA, 73, 01, 20, 00, 0F, 84, 9C, 02, 00, 00, 8D, 85, 8D, 74, 01, 20, 50, FF, 95, EA, 73, 01, 20, 83, F8, 00, 0F, 84, 86...
 
[+]

Entropy:
6.1964

Packer / compiler:
ASPack v1.08.04

Code size:
1.4 MB (1,445,376 bytes)

The file iphonelock.vn-v2.exe has been seen being distributed by the following URL.

Remove iphonelock.vn-v2.exe - Powered by Reason Core Security