moistv2.vmp.dll

The library moistv2.vmp.dll has been detected as malware by 14 anti-virus scanners. The file has been seen being downloaded from www.filedropper.com and multiple other hosts.
MD5:
8233f9db596cd1b1d6f1f70d7589495d

SHA-1:
98ad8cc4a784b09909ceb4adc00b38010fb8da64

SHA-256:
f8e2944674517e8b7ec1bc1dd4662f4d2a8073b38dc7880ee595cf7aa1e1842c

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
4/26/2024 4:30:30 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.778181
408

Avira AntiVirus
TR/Black.Gen2
8.3.2.4

Arcabit
Trojan.Kazy.DBDFC5
1.0.0.637

AVG
Win32/Blacked
2016.0.2886

Bitdefender
Gen:Variant.Kazy.778181
1.0.20.1785

Bkav FE
HW32.Packed
1.3.0.7400

Emsisoft Anti-Malware
Gen:Variant.Kazy.778181
8.15.12.23.06

ESET NOD32
Win32/Packed.VMProtect.ABO (variant)
9.12767

Fortinet FortiGate
W32/VMProtBad.A!tr
12/23/2015

F-Secure
Gen:Variant.Kazy.778181
11.2015-23-12_4

G Data
Gen:Variant.Kazy.778181
15.12.25

McAfee
Artemis!8233F9DB596C
5600.6542

MicroWorld eScan
Gen:Variant.Kazy.778181
16.0.0.1071

Sophos
Mal/VMProtBad-A
4.98

File size:
1.6 MB (1,670,656 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\moistv2.vmp.dll

File PE Metadata
Compilation timestamp:
12/22/2015 8:00:14 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
49152:U6T2tI01Qx+NSqciTAnTivZ1vKX1jvyEct+3tE32ptPpLKuZ5X:UjlKxdqFAnQYV

Entry address:
0x2A6926

Entry point:
9C, 68, FA, 5C, D1, 43, 60, 66, 89, 44, 24, 04, C7, 44, 24, 24, 0E, 9B, B0, F3, E9, 8D, 6D, EC, FF, 60, E8, ED, E7, FF, FF, C7, 04, 24, 02, 9B, B0, C3, 52, C7, 04, 24, 9B, 95, 0F, F0, 9C, 9C, 8D, 64, 24, 08, E9, AA, 68, 00, 00, AD, 35, C4, 15, D3, 84, AB, 0D, C5, 93, 0F, 87, EB, 93, DF, 7F, 57, A8, 18, 50, D4, 6C, 48, EA, 3C, 0A, 86, 06, 66, BE, BA, FB, 73, DB, 58, 90, 37, 8A, 0A, 8E, A1, DC, 0F, 4C, C7, 96, 0E, 4E, DF, FF, 90, F8, 87, CF, BC, 4A, CD, B6, 98, 28, 53, 8E, F6, 73, BB, 5A, A3, C8, 11, 48, 88...
 
[+]

Entropy:
7.8088  (probably packed)

Code size:
196.5 KB (201,216 bytes)

The file moistv2.vmp.dll has been seen being distributed by the following 3 URLs.

Remove moistv2.vmp.dll - Powered by Reason Core Security