lineage.exe

lineage

The application lineage.exe has been detected as a potentially unwanted program by 27 anti-malware scanners.
Product:
lineage

Version:
1.00

MD5:
2e404110f517aef1f4f88a45c5fe1c0a

SHA-1:
9ccf3504ad7396d347aa5a81f6874e4680a30661

SHA-256:
b26fe54f9d136b600b16d091bfd3fd10998769425cb9097495d09d34cd62e38c

Scanner detections:
27 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 8:26:55 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2518079
551

Agnitum Outpost
Riskware.Themida
7.1.1

Avira AntiVirus
TR/Crypt.TPM.Gen
8.3.1.6

Arcabit
Trojan.Generic.D266C3F
1.0.0.425

avast!
Win32:Malware-gen
2014.9-150802

AVG
Generic13_c
2016.0.3029

Baidu Antivirus
Hacktool.Win32.Packed.Themida
4.0.3.1582

Bitdefender
Trojan.GenericKD.2518079
1.0.20.1070

Bkav FE
HW32.Packed
1.3.0.6979

Emsisoft Anti-Malware
Trojan.GenericKD.2518079
8.15.08.02.12

ESET NOD32
Win32/Packed.Themida suspicious application
6.3.12010.0

Fortinet FortiGate
PossibleThreat
8/2/2015

F-Secure
Trojan.GenericKD.2518079
11.2015-02-08_1

G Data
Trojan.GenericKD.2518079
15.8.25

K7 AntiVirus
Trojan
13.207.16756

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1642

McAfee
RDN/Generic.dx
5600.6685

MicroWorld eScan
Trojan.GenericKD.2518079
16.0.0.642

NANO AntiVirus
Trojan.Win32.TPM.dtjzfe
0.30.24.2668

nProtect
Trojan.GenericKD.2518079
15.07.31.01

Panda Antivirus
Generic Suspicious
15.08.02.12

Qihoo 360 Security
HEUR/QVM19.1.Malware.Gen
1.0.0.1015

Quick Heal
(Suspicious) - DNAScan
8.15.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.18D4FADB!416611035
23.00.65.15731

Sophos
Generic PUA JM
4.98

Trend Micro
TROJ_GEN.R00GC0EG815
10.465.02

VIPRE Antivirus
Trojan.Win32.Generic
42538

File size:
896 KB (917,504 bytes)

Product version:
1.00

Original file name:
lineage.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\lineage.exe

File PE Metadata
Compilation timestamp:
6/27/2015 7:13:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:1thX4jW0E+kdAwJ95xe3Ltba8alDBZWRUDYIP1lAFGorsVTKjtxDzGDFyBETYrpF:/qjZlkf5EatWeD/lcr+TKj/ptMBms8

Entry address:
0x206000

Entry point:
83, EC, 04, 50, 53, E8, 01, 00, 00, 00, CC, 58, 89, C3, 40, 2D, 00, 90, 0D, 00, 2D, AF, FB, 09, 06, 05, A4, FB, 09, 06, 80, 3B, CC, 75, 19, C6, 03, 00, BB, 00, 10, 00, 00, 68, 84, 42, 19, 7B, 68, 00, 46, CE, 7A, 53, 50, E8, 0A, 00, 00, 00, 83, C0, 00, 89, 44, 24, 08, 5B, 58, C3, 55, 89, E5, 50, 53, 51, 56, 8B, 75, 08, 8B, 4D, 0C, C1, E9, 02, 8B, 45, 10, 8B, 5D, 14, 85, C9, 74, 0A, 31, 06, 01, 1E, 83, C6, 04, 49, EB, F2, 5E, 59, 5B, 58, C9, C2, 10, 00, 5A, 1F, 7B, E9, D5, 3C, E9, F1, FF, 19, CA, 6B, 67, 1A...
 
[+]

Entropy:
7.8230  (probably packed)

Code size:
32 KB (32,768 bytes)

Remove lineage.exe - Powered by Reason Core Security