lawl.exe

The executable lawl.exe has been detected as malware by 14 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www33.speedyshare.com and multiple other hosts.
Version:
1.1.10.01

MD5:
4767f469e82c717313065cee83a4755c

SHA-1:
3e24403c9b3fe0cba9a9b8456df4146dccd7c650

SHA-256:
1b54f1182076b40475c65540ecef247104130bb75b6a4510ac6f7d70a609324b

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
4/23/2024 2:09:08 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11737224
852

avast!
Win32:Dropper-gen [Drp]
2014.9-141006

Bitdefender
Trojan.Generic.11737224
1.0.20.1395

Dr.Web
Trojan.BPlug.61
9.0.1.0279

Emsisoft Anti-Malware
Trojan.Generic.11737224
8.14.10.06.09

F-Secure
Trojan.Generic.11737224
11.2014-06-10_2

G Data
Trojan.Generic.11737224
14.10.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.7.8.0

McAfee
Artemis!B7935B71BAB5
5600.6986

MicroWorld eScan
Trojan.Generic.11737224
15.0.0.837

Norman
Suspicious_Gen4.HAETL
11.20141006

nProtect
Trojan.Generic.11737224
14.09.23.01

Reason Heuristics
Threat.Win.Reputation.IMP
14.10.6.9

Zillya! Antivirus
Backdoor.SdBot.Win32.14005
2.0.0.1835

File size:
725.5 KB (742,912 bytes)

Product version:
1.1.10.01

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\lawl.exe

File PE Metadata
Compilation timestamp:
5/17/2013 11:24:02 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:wsFkEcnQjJ1Q2WKfNz/pnyZE8hdGM+8XP6mqNCLl1FTi41hrFH3Fkb0rm5wdTbkd:wJEcQF1Q2WWLm/B1FTighrd3Ri5Cbn7k

Entry address:
0x833CA

Entry point:
E8, B2, 5E, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 83, 65, FC, 00, 53, 8B, 5D, 10, 85, DB, 75, 07, 33, C0, E9, 9A, 00, 00, 00, 56, 83, FB, 04, 72, 75, 8D, 73, FC, 85, F6, 74, 6E, 8B, 4D, 0C, 8B, 45, 08, 8A, 10, 83, C0, 04, 83, C1, 04, 84, D2, 74, 52, 3A, 51, FC, 75, 4D, 8A, 50, FD, 84, D2, 74, 3C, 3A, 51, FD, 75, 37, 8A, 50, FE, 84, D2, 74, 26, 3A, 51, FE, 75, 21, 8A, 50, FF, 84, D2, 74, 10, 3A, 51, FF, 75, 0B, 83, 45, FC, 04, 39, 75, FC, 72, C2, EB, 2E, 0F, B6, 40, FF, 0F, B6, 49, FF, EB, 46...
 
[+]

Code size:
575 KB (588,800 bytes)

The file lawl.exe has been seen being distributed by the following 2 URLs.

Remove lawl.exe - Powered by Reason Core Security