legset.exe

Vendor

The application legset.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. The file has been seen being downloaded from d11sfnc01fj8ag.cloudfront.net. While running, it connects to the Internet address server-54-230-52-97.jfk6.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
Vendor

Product:
Vendor

Description:
Pack

Version:
1.33.0.0

MD5:
bc000d11986190a24d6a15e234f2079b

SHA-1:
7b2a0d40bcbd07a791413d4472239c345a59653d

SHA-256:
2599d2468f7512e8b01f382780d4cdca07edf237407d50e573bf5628d729266f

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
4/23/2024 6:23:13 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.15348549
399

Arcabit
Trojan.Generic.DEA3345
1.0.0.637

avast!
Win32:Adware-gen [Adw]
2014.9-160102

Bitdefender
Trojan.Generic.15348549
1.0.20.10

Comodo Security
Application.Win32.SBInstaller.DF
23651

Dr.Web
Adware.Searcher.3017
9.0.1.02

Emsisoft Anti-Malware
Trojan.Generic.15348549
8.16.01.02.08

F-Secure
Trojan.Generic.15348549
11.2016-02-01_7

G Data
Trojan.Generic.15348549
16.1.25

IKARUS anti.virus
Trojan-Dropper.Win32.Agent
t3scan.1.9.5.0

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.878

Malwarebytes
PUP.Optional.Goobzo
v2016.01.02.08

MicroWorld eScan
Trojan.Generic.15348549
17.0.0.6

nProtect
Trojan.Generic.15348549
15.12.24.01

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1077

VIPRE Antivirus
Trojan.Win32.Generic
46066

File size:
603.5 KB (617,984 bytes)

Product version:
1.33.0.0

Copyright:
Copyright (C) 2015

Original file name:
Vendor

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\legset.exe

File PE Metadata
Compilation timestamp:
11/24/2015 2:54:08 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:ianKwFAyEdOmqZpHGDAjB8U3cL3svdTf26hC75xrx9u:iC9tjmEjhvdTfc7rr

Entry address:
0x42F21

Entry point:
E8, 4B, C5, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 38, 7B, 48, 00, E8, B9, 52, 00, 00, E8, 8E, 2C, 00, 00, 0F, B7, F0, 6A, 02, E8, DE, C4, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 15, 73, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.4502

Code size:
421 KB (431,104 bytes)

The file legset.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to server-54-230-52-97.jfk6.r.cloudfront.net  (54.230.52.97:80)

Remove legset.exe - Powered by Reason Core Security