~+jf6460298486553501376.tmp

{70166A21-2F6A-4CC0-822C-607696D8F4B7}

The file ~+jf6460298486553501376.tmp has been detected as malware by 22 anti-virus scanners.
Publisher:

MD5:
69d56d487d6805c91eee1dd168f7b0d2

SHA-1:
f14444d750a3490f0b5a6c6656a891b17b48d37a

SHA-256:
b3b6e2e806d48a6571f65b6672ac17a7bfe617b6a83d65ea1e6fdc59554bc908

Scanner detections:
22 / 68

Status:
Malware

Analysis date:
4/23/2024 7:42:48 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11246354
220

AhnLab V3 Security
Backdoor/Win32.Necurs
16.06.29

avast!
Win32:Rootkit-gen [Rtk]
2014.9-160629

AVG
Zbot
2017.0.2698

Baidu Antivirus
Trojan.MSIL.Injector
4.0.3.16629

Bitdefender
Trojan.Generic.11246354
1.0.20.905

Emsisoft Anti-Malware
Trojan.Generic.11246354
8.16.06.29.08

ESET NOD32
MSIL/Injector.DMR (variant)
10.9805

Fortinet FortiGate
W32/Inject.DMR!tr
6/29/2016

F-Secure
Trojan.Generic.11246354
11.2016-29-06_4

G Data
Trojan.Generic.11246354
16.6.24

IKARUS anti.virus
Trojan-Signed:Agent
t3scan.1.6.1.0

Kaspersky
Trojan.Win32.Inject
14.0.0.-17

Malwarebytes
Trojan.Inject
v2016.06.29.08

McAfee
PWSZbot-FXD!69D56D487D68
5600.6354

MicroWorld eScan
Trojan.Generic.11246354
17.0.0.543

nProtect
Trojan.Generic.11246354
14.05.15.01

Panda Antivirus
Generic Malware
16.06.29.08

Sophos
Troj/MSIL-RD
4.98

Trend Micro House Call
TROJ_GEN.R0CBC0PEF14
7.2.181

Trend Micro
TROJ_GEN.R0CBC0PEF14
10.465.29

VIPRE Antivirus
Trojan.Win32.Generic
29246

File size:
187.6 KB (192,064 bytes)

Common path:
C:\users\{user}\appdata\local\temp\~+jf6460298486553501376.tmp

Digital Signature
Authority:
{70166A21-2F6A-4CC0-822C-607696D8F4B7}

Valid from:
4/19/2014 5:47:18 AM

Valid to:
4/19/2015 11:47:18 AM

Subject:
CN={70166A21-2F6A-4CC0-822C-607696D8F4B7}

Issuer:
CN={70166A21-2F6A-4CC0-822C-607696D8F4B7}

Serial number:
3F0DF1EBD88FB1B94D119CFFAC6B01C9

File PE Metadata
Compilation timestamp:
4/28/2014 7:28:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:4IKyoToMBpgSoEkOFP9OOkT8Dc/w9monmFh8NLNL5hvTEhJ9jCDLjOaiu8HRAm2o:fKyoToMBp7oEkOfOOkT8I/4mon6WdhvG

Entry address:
0x2FA5E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
183 KB (187,392 bytes)

Remove ~+jf6460298486553501376.tmp - Powered by Reason Core Security