money-hack.exe

The executable money-hack.exe has been detected as malware by 19 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from freecache28-free.uloz.to.
Version:
1.7.0.0

MD5:
62fb624de9bd1082066c3fe863d0092d

SHA-1:
25f2ab09b21bc7fb2419f92d7952aa7dfbf9198f

Scanner detections:
19 / 68

Status:
Malware

Analysis date:
9/19/2018 12:47:33 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.Agent.Gen!c
2.1.4+

AhnLab V3 Security
Malware/Win32.Generic
2016.06.10

Baidu Antivirus
Hacktool.Win32.CheatEngine
4.0.3.1671

ESET NOD32
Win32/HackTool.CheatEngine.AB potentially unsafe (variant)
10.13624

Fortinet FortiGate
Riskware/CheatEngine
7/1/2016

F-Prot
W32/A-2c468524
v6.4.7.1.166

G Data
Win32.Riskware.Hacktool
16.7.25

IKARUS anti.virus
Virus.Win32.Trojan
t3scan.2.0.9.0

K7 AntiVirus
Trojan
13.227.19875

K7 Gateway Antivirus
Hacktool
13.227.19875

Malwarebytes
HackTool.GamesCheat.Gen
v2016.07.01.01

McAfee
Artemis!62FB624DE9BD
5600.6351

McAfee Web Gateway
BehavesLike.Win32.Dropper.dc
7.6351

Qihoo 360 Security
Win32/Trojan.cfa
1.0.0.1120

Rising Antivirus
Trojan.Generic-PfkriTQZHSP (Cloud)
23.00.65.16629

Sophos
CheatEngine (PUA)
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Delf
9048

VIPRE Antivirus
Trojan.Win32.Delf.abt
50010

Yandex
HackTool.Delf!XOoMuHWlj84
5.5.1.3

File size:
207.5 KB (212,456 bytes)

Product version:
1.2

File type:
Executable application (Win32 EXE)

Language:
Holandcina (Holandsko)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\money-hack.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:fRorGrobc/tZ3bHtrDJYR+WNc9xStgs7IzNagOMA7pGntMmiHLLHxwEj9n:5LrobWjDmRAs7pM3t6nHB

Entry address:
0x96CA0

Entry point:
60, BE, 00, 50, 46, 00, 8D, BE, 00, C0, F9, FF, C7, 87, A8, 50, 07, 00, 95, 01, A9, 0C, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8738

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
200 KB (204,800 bytes)

The file money-hack.exe has been seen being distributed by the following URL.

Remove money-hack.exe - Powered by Reason Core Security