maconfigx64_4_6_0_1.exe

The executable maconfigx64_4_6_0_1.exe has been detected as malware by 8 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from config.zebulon.fr.
MD5:
f12256c96b6585b26deb4a3802c624d0

SHA-1:
2b54f08e4a95beafd04a4eec4360752133e6eb74

SHA-256:
f44b57abb945a682989b1d451917975cba7d810e84b06daad679c585051dfbd2

Scanner detections:
8 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 6:53:37 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160518-2

AVG
Win32/Sality
2015.0.4604

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.225.268.0

Norman
Win32.Sality.3
19.05.2016 01:04:49

File size:
4.2 MB (4,438,912 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\maconfigx64_4_6_0_1.exe

File PE Metadata
Compilation timestamp:
6/6/2009 11:41:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:/X3d8MG/4dyQmcvit6L7V7v7O4m/9WdZOqeTgtqsz+B/yWsGs:ViQMQmcDL57z2FWcg41fJs

Entry address:
0x323C

Entry point:
60, F3, 78, 0C, 80, F9, 94, 69, C0, A0, B4, 57, 3A, F6, C3, 36, 29, C2, 0F, B7, ED, 34, 33, 81, FA, 28, 6A, 00, 00, 75, 08, 89, C7, C7, C1, B5, 9F, 99, BC, E8, 21, 00, 00, 00, EB, 08, 69, C1, 16, 5E, 97, 37, 84, C1, 71, 03, 14, F9, F3, FE, C9, 8A, E1, 87, F6, 03, D3, 71, 08, B8, 61, 53, 4C, 3E, FE, CD, F2, FE, CE, 73, 02, 89, FE, B1, C7, F7, C7, D5, A6, A1, 38, 3B, DA, 5A, 70, 02, 84, F0, 0F, BF, CF, 8D, 35, 73, 10, C0, 9C, FF, C1, FE, CC, F6, C0, 5A, 80, D0, 11, 86, F8, 2B, FF, 81, FA, F0, 19, 00, 00, 77...
 
[+]

Code size:
23 KB (23,552 bytes)

The file maconfigx64_4_6_0_1.exe has been seen being distributed by the following URL.

Remove maconfigx64_4_6_0_1.exe - Powered by Reason Core Security