leis.exe

The executable leis.exe has been detected as malware by 12 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www74.zippyshare.com and multiple other hosts.
MD5:
cbfb285ac765af6726b76fb1caa6039a

SHA-1:
4d6a2ef6d3264fd350364c176710f73993744c9c

SHA-256:
e2c463e210c09de9d99019c77c940fd7f49820380532f60908c1b18324b2e94a

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
5/17/2024 12:33:52 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:WrongInf-A [Susp]
2014.9-141016

AVG
Skodna.GameHack
2015.0.3386

Bkav FE
W32.Clod05f.Trojan
1.3.0.4959

ESET NOD32
Win32/GameHack.BB (variant)
8.10206

Fortinet FortiGate
W32/Injector.IGS!tr
8/11/2014

F-Prot
W32/Heuristic-KPP
v6.4.7.1.166

K7 AntiVirus
Trojan
13.182.12959

McAfee
Artemis!CBFB285AC765
5600.7042

Trend Micro House Call
PAK_Generic.001
7.2.289

Trend Micro
PAK_Generic.001
10.465.16

VIPRE Antivirus
Trojan.Win32.Generic
31942

ViRobot
JS.A.Iframe.57344.AB
2011.4.7.4223

File size:
56 KB (57,344 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
1/7/2009 9:40:19 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
768:77qA3vH0uj1ZLANRr4PvPgynk50uEs3P3XEt/P:72UfTLAb8PXnk9Mt/P

Entry address:
0x1BAC

Entry point:
E8, 55, 18, 00, 00, E9, 40, FE, FF, FF, 56, 6A, 01, 68, 08, C0, 40, 00, 8B, F1, E8, D5, 18, 00, 00, C7, 06, 7C, 91, 40, 00, 8B, C6, 5E, C3, C7, 01, 7C, 91, 40, 00, E9, 30, 19, 00, 00, 56, 8B, F1, C7, 06, 7C, 91, 40, 00, E8, 22, 19, 00, 00, F6, 44, 24, 08, 01, 74, 07, 56, E8, 88, FD, FF, FF, 59, 8B, C6, 5E, C2, 04, 00, 56, FF, 74, 24, 08, 8B, F1, E8, AA, 18, 00, 00, C7, 06, 7C, 91, 40, 00, 8B, C6, 5E, C2, 04, 00, 55, 8B, EC, 83, EC, 0C, EB, 0D, FF, 75, 08, E8, A1, 1B, 00, 00, 85, C0, 59, 74, 0F, FF, 75, 08...
 
[+]

Code size:
32 KB (32,768 bytes)

The file leis.exe has been seen being distributed by the following 6 URLs.

http://www74.zippyshare.com/d/ZbHNNiO2/.../Leis.exe

http://s6913.chomikuj.pl/File.aspx?e=OSgtPPcrEY8x__6VH4-w-GqwfTlmRXU2sV3m32mDWbFvbohk39r6tqJJ2M6MXzY_kZ3RbZ8JBntXbHQHtOe8ZUKu4v-uEW-cGjt_K3V6-g_H9qoW1AHev81qQB5Dai6M&pv=2

Remove leis.exe - Powered by Reason Core Security