mixmaster under bot.exe

mixmaster under bot

The executable mixmaster under bot.exe has been detected as malware by 24 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dc756.4shared.com.
Publisher:
Microsoft*  (Invalid match)

Product:
mixmaster under bot

Version:
1.0.0.0

MD5:
94bbb88c220776b5d9be66eed0218eee

SHA-1:
28a1a9fb583e451320f777b163127e708a71d617

SHA-256:
a064999a4fae095cd55108f03dd4aa4b7883ad40286ec8038c650863276e1eb1

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
5/17/2024 5:43:52 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.696568
314

Avira AntiVirus
TR/Spy.A.16662
8.3.2.4

Arcabit
Trojan.Kazy.DAA0F8
1.0.0.624

avast!
Win32:Malware-gen
2014.9-160326

AVG
PSW.MSIL
2017.0.2792

Baidu Antivirus
Trojan.MSIL.Agent
4.0.3.16326

Bitdefender
Gen:Variant.Kazy.696568
1.0.20.430

Emsisoft Anti-Malware
Gen:Variant.Kazy.696568
8.16.03.26.12

ESET NOD32
MSIL/PSW.Agent.ONZ (variant)
10.12617

Fortinet FortiGate
MSIL/Agent.NRZ!tr.pws
3/26/2016

F-Secure
Gen:Variant.Kazy.696568
11.2016-26-03_7

G Data
Gen:Variant.Kazy.696568
16.3.25

IKARUS anti.virus
Trojan.MSIL.PSW
t3scan.1.9.5.0

K7 AntiVirus
Password-Stealer
13.212.17959

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.457

McAfee
RDN/Generic PWS.y
5600.6448

Microsoft Security Essentials
TrojanSpy:MSIL/Aconstel.A
1.1.12300.0

MicroWorld eScan
Gen:Variant.Kazy.696568
17.0.0.258

NANO AntiVirus
Trojan.Win32.Agent.dulphj
0.30.26.4751

Panda Antivirus
Trj/Sharik.B
16.03.26.12

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1077

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R01TC0VH615
10.465.26

VIPRE Antivirus
Trojan.Win32.Generic
45400

File size:
206 KB (210,944 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Microsoft 2015

Original file name:
mixmaster under bot.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\mixmaster under bot.exe

File PE Metadata
Compilation timestamp:
2/11/2015 8:12:15 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:82Akrn2FFa6lFKusYeDVVqcmhNfdczPN:T2FFiusYeDVR82P

Entry address:
0x30FCE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, BF, D3, DB, 54, 00, 00, 00, 00, 02, 00, 00, 00, 7C, 00, 00, 00, 1C, 20, 03, 00, 1C, F4, 02, 00, 52, 53, 44, 53, EE, 96, 98, 0C, 45, 5F, 04, 41, A5, 6D, DB, 6C, A4, 0B, 61, 2F, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 69, 73, 6D, 61, 65, 6C, 5C, 44, 6F, 77, 6E, 6C, 6F, 61, 64, 73, 5C...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
188 KB (192,512 bytes)

The file mixmaster under bot.exe has been seen being distributed by the following URL.

Remove mixmaster under bot.exe - Powered by Reason Core Security