labo110.exe

The executable labo110.exe has been detected as malware by 11 anti-virus scanners.
MD5:
96bfc08580defd76233d15a132e83ed2

SHA-1:
acde94c2716db764c8f831748cac84d6cac24b5d

SHA-256:
2e096431c6c6b7f172f83f7bd69e69d1ad1fd31df570a4a492b8f888b23ed1bb

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
4/25/2024 9:16:05 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Agent.41445879
7.11.173.10

AVG
Trojan horse BackDoor.Generic17.DQR
2014.0.4015

Dr.Web
BackDoor.Poison.15880
9.0.1.0264

F-Prot
W32/Agent.QW.gen
4.6.5.141

IKARUS anti.virus
Backdoor.Win32.Poison
t3scan.1.7.8.0

NANO AntiVirus
Trojan.Win32.Poison.bgkspz
0.28.2.62151

nProtect
Backdoor/W32.Poison.41472.CZ
14.09.17.01

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.21.11

Rising Antivirus
PE:Backdoor.Poison!6.487
23.00.65.14915

Vba32 AntiVirus
BackDoor.Poison
3.12.26.3

File size:
40.5 KB (41,472 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
9/25/2013 10:16:11 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.50

CTPH (ssdeep):
768:fTT3M03DrSkERvrHWLl9aaRR+H7j4IxubkNB4tPT25//+IHWm5zk:fTzvaZvrHWLl91R+H7j6bCmM5/Cm

Entry address:
0x1190

Entry point:
55, 89, E5, 6A, FF, 68, 5C, 90, 40, 00, 68, 68, 1A, 40, 00, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 83, EC, 0C, 53, 56, 57, 89, 65, E8, 68, 00, 00, 00, 02, E8, 90, 25, 00, 00, 59, A3, 18, B5, 40, 00, E8, B5, 0A, 00, 00, 85, C0, 75, 0D, 6A, 01, E8, EA, 0C, 00, 00, 59, E9, 9B, 00, 00, 00, C7, 45, FC, 00, 00, 00, 00, E8, E8, 0C, 00, 00, E8, A3, 0D, 00, 00, E8, EE, 0D, 00, 00, E8, F9, 11, 00, 00, E8, 94, 12, 00, 00, BB, 80, A1, 40, 00, 81, FB, 80, A1, 40, 00, 73, 0D, FF, 13, 83, C3, 04, 81, FB...
 
[+]

Code size:
32 KB (32,768 bytes)

Remove labo110.exe - Powered by Reason Core Security