minime.exe

Tune therl to sofidr

Dur Declined

The executable minime.exe, “Lithiari be thehe thedis thar post” has been detected as malware by 26 anti-virus scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from space.cachefly.net.
Publisher:
Dur Declined

Product:
Tune therl to sofidr

Description:
Lithiari be thehe thedis thar post

Version:
1, 3, 6, 5

MD5:
ffeb28361e03c85c1c9a3d95005ce58a

SHA-1:
1ef11164f5ad8982c1065f1cd97dd1e4e4473bcf

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
5/5/2024 10:14:38 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Swizzor.D.2
7.10.6.115

Emsisoft A-Squared
Virus.Trojan.Win32.Obfuscated!IK
4.5.0.50

avast!
Win32:Malware-gen
2014.9-160518

AVG
Downloader.Swizzor
2017.0.2740

Bitdefender
Trojan.Generic.3057387
1.0.20.695

Clam AntiVirus
Trojan.Agent-143981
0.98/170.3

Comodo Security
TrojWare.Win32.TrojanDownloader.Swizzor.Gen
4628

Dr.Web
Trojan.Swizzor.based
9.0.1.0139

ESET NOD32
Win32/Agent (variant)
10.5036

Fortinet FortiGate
W32/Swizzor.D!tr
5/18/2016

F-Prot
W32/Swizzor.E!Generic
v6.4.5.1.85

F-Secure
Trojan.Generic.3057387
11.2016-18-05_4

G Data
Trojan.Generic.3057387
16.5.19

IKARUS anti.virus
Virus.Trojan.Win32.Obfuscated
t3scan.1.1.80.0

Kaspersky
Trojan.Win32.Swizzor
14.0.0.194

McAfee
Swizzor.gen.g
5600.6396

Microsoft Security Essentials
Trojan:Win32/Remhead
1.163.1557.0

Norman
W32/Swizzor.JFRB
11.20160518

nProtect
Trojan/W32.Swizzor.323584.ABB
10.04.17.01

Panda Antivirus
Generic Malware
16.05.18.06

Prevx
High Risk Cloaked Malware
3.0

Quick Heal
Win32.Trojan.Swizzor.c.4
5.16.10.00

Rising Antivirus
Trojan.Win32.Generic.51FA5689
23.00.65.16516

Sophos
Mal/Generic-A
4.52

Vba32 AntiVirus
Trojan.Win32.Swizzor.d
3.12.12.4

ViRobot
Trojan.Win32.Swizzor.323584.CX
2010.4.17.2282

File size:
316 KB (323,584 bytes)

Product version:
1, 4, 3, 5

Copyright:
(C) 2006 Dur Declined

Original file name:
dash.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\minime.exe

File PE Metadata
Compilation timestamp:
9/25/2007 7:43:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:WnThZgcBvyOpfHZgVsDGtbgBFj+4ZuX1uaVg4BjmVaLyM:OTDgcH5v6gBFj+4OuEjmAL1

Entry address:
0x5139

Entry point:
E8, 59, AA, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 8B, 46, 0C, A8, 83, 74, 1E, A8, 08, 74, 1A, FF, 76, 08, E8, A9, BE, FF, FF, 81, 66, 0C, F7, FB, FF, FF, 33, C0, 59, 89, 06, 89, 46, 08, 89, 46, 04, 5E, 5D, C3, 3B, 85, 60, 04, 00, 00, 0F, 8C, 3D, FD, FF, FF, 89, 56, F4, 8B, 56, 24, 89, 54, 24, 50, 8B, D1, 8B, CF, 8B, 7C, 24, 0C, 8B, 76, D8, 83, C4, 40, E9, 50, 02, 00, 00, 8B, B5, 64, FE, FF, FF, 83, C6, 02, 8B, CB, 8B, DE, 8B, 74, 24, 0C, 8B, 44, 24, 04, 89, 44, 24, 0C, A1, 94, E3...
 
[+]

Code size:
108 KB (110,592 bytes)

The file minime.exe has been seen being distributed by the following URL.

Remove minime.exe - Powered by Reason Core Security