kotlt_al_waffa_il_2slamya.exe

kotlt al waffa il 2slamya

ليبعهحليبهخعلهخيبعلعيبعهخعهخ

The executable kotlt_al_waffa_il_2slamya.exe has been detected as malware by 23 anti-virus scanners. The file has been seen being downloaded from www.weebly.com.
Publisher:
ليبعهحليبهخعلهخيبعلعيبعهخعهخ

Product:
kotlt al waffa il 2slamya

Version:
1.03.05.07

MD5:
542528297c557fade9994d5c39ac894c

SHA-1:
f9c86a9843cbd350e6f86eb516fdee20c18ab684

SHA-256:
1e085f93af817c4acbdeac17c0a377bc26466b6df9d0c94d814c53a0ddaabfe7

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
4/25/2024 6:38:37 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.uq0@rL9us1laf
192

avast!
MSIL:GenMalicious-BJI [Trj]
2014.9-160727

AVG
Atros
2017.0.2670

Baidu Antivirus
Trojan.MSIL.Agent
4.0.3.16727

Bitdefender
Gen:Trojan.Heur.uq0@rL9us1laf
1.0.20.1045

Dr.Web
Trojan.DownLoader13.8791
9.0.1.0209

Emsisoft Anti-Malware
Gen:Trojan.Heur.uq0@rL9us1laf
8.16.07.27.10

ESET NOD32
MSIL/TrojanDropper.Agent.BDN (variant)
10.11641

Fortinet FortiGate
MSIL/Agent.BDN!tr
7/27/2016

F-Secure
Gen:Trojan.Heur.uq0@rL9us1laf
11.2016-27-07_4

G Data
Gen:Trojan.Heur.uq0@rL9us1laf
16.7.25

IKARUS anti.virus
Trojan-Dropper.MSIL.Agent
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.204.15935

Malwarebytes
Trojan.Passwords.FD
v2016.07.27.10

McAfee
Artemis!542528297C55
5600.6326

MicroWorld eScan
Gen:Trojan.Heur.uq0@rL9us1laf
17.0.0.627

NANO AntiVirus
Trojan.Win32.Agent.dkhgkn
0.30.24.1357

Norman
Obfuscated.W!genr
11.20160727

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.FakeDOC@CV!1.9C3B
23.00.65.16725

Trend Micro House Call
TROJ_GEN.R00UC0EE715
7.2.209

Trend Micro
TROJ_GEN.R00UC0EE715
10.465.27

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
40324

File size:
320.5 KB (328,192 bytes)

Product version:
1.03.05.07

Copyright:
Copyright ©يبهخعلهخيبهخعلهخيبه 2015

Trademarks:
صثهخحعهيبهخلعيبهخعلهخيبعهخلعهخيبعهخ

Original file name:
kotlt al waffa il 2slamya.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\kotlt_al_waffa_il_2slamya.exe

File PE Metadata
Compilation timestamp:
4/22/2015 9:31:01 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:92GhNjcIYC1jQprkUCWmPrTmOZVOCWQf1D:92iNjcIYnKbWsrbV2Qf1

Entry address:
0x42B6E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.2054

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
259 KB (265,216 bytes)

The file kotlt_al_waffa_il_2slamya.exe has been seen being distributed by the following URL.

Remove kotlt_al_waffa_il_2slamya.exe - Powered by Reason Core Security