msqqyai.com

{70166A21-2F6A-4CC0-822C-607696D8F4B7}

The file msqqyai.com has been detected as malware by 34 anti-virus scanners.
Publisher:

MD5:
38daa4936221ae9d4bdcd23018d684f9

SHA-1:
04cb2929d00eef3dc859f004ecf47ab0e8f1e42a

SHA-256:
f019c57f6f279e1f5871868ecaa2aa4bb4bfdc82b4522a3a467178af8568089a

Scanner detections:
34 / 68

Status:
Malware

Analysis date:
4/19/2024 2:13:15 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1660125
810

Agnitum Outpost
Backdoor.Androm
7.1.1

AhnLab V3 Security
Backdoor/Win32.Necurs
14.11.16

Avira AntiVirus
TR/Injector.dmr.5
7.11.151.166

avast!
Win32:Malware-gen
2014.9-141116

AVG
MSIL3
2015.0.3288

Baidu Antivirus
Trojan.MSIL.Injector
4.0.3.141116

Bitdefender
Trojan.GenericKD.1660125
1.0.20.1600

Dr.Web
BackDoor.Andromeda.22
9.0.1.0320

Emsisoft Anti-Malware
Trojan.GenericKD.1660125
8.14.11.16.08

ESET NOD32
MSIL/Injector.DMR (variant)
8.9852

Fortinet FortiGate
W32/Androm.DMR!tr.bdr
11/16/2014

F-Secure
Trojan.GenericKD.1660125
11.2014-16-11_1

G Data
Trojan.GenericKD.1660125
14.11.24

IKARUS anti.virus
Trojan-Signed:Agent
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.178.12203

Kaspersky
Backdoor.Win32.Androm
14.0.0.2936

Malwarebytes
Trojan.Inject
v2014.11.16.08

McAfee
PWSZbot-FXD!38DAA4936221
5600.6944

Microsoft Security Essentials
Worm:Win32/Gamarue
1.10600

MicroWorld eScan
Trojan.GenericKD.1660125
15.0.0.960

NANO AntiVirus
Trojan.Win32.Androm.cxpxcg
0.28.0.59921

Norman
Troj_Generic.TTLGN
11.20141116

nProtect
Trojan.GenericKD.1660125
14.05.26.01

Panda Antivirus
Generic Malware
14.11.16.08

Qihoo 360 Security
Win32/Trojan.c17
1.0.0.1015

Quick Heal
Backdoor.Androm.r3
11.14.14.00

Sophos
Troj/MSIL-RD
4.98

Trend Micro House Call
TROJ_SPNV.03E214
7.2.320

Trend Micro
TROJ_SPNV.03E214
10.465.16

Vba32 AntiVirus
Backdoor.Androm
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
29646

ViRobot
Backdoor.Win32.A.Androm.155200
2011.4.7.4223

Zillya! Antivirus
Backdoor.Androm.Win32.8398
2.0.0.1801

File size:
151.6 KB (155,200 bytes)

Common path:
C:\users\a\local settings\temp\msqqyai.com

Digital Signature
Authority:
{70166A21-2F6A-4CC0-822C-607696D8F4B7}

Valid from:
4/19/2014 6:47:18 AM

Valid to:
4/19/2015 12:47:18 PM

Subject:
CN={70166A21-2F6A-4CC0-822C-607696D8F4B7}

Issuer:
CN={70166A21-2F6A-4CC0-822C-607696D8F4B7}

Serial number:
3F0DF1EBD88FB1B94D119CFFAC6B01C9

File PE Metadata
Compilation timestamp:
4/29/2014 5:07:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:DUCeazuCOvRUrK5MB5J322lMdqpLCFUAstVbY3hSF4Pd4d9ovI7:ACeiV5VrPavI7

Entry address:
0x26ACE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.2457

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
147 KB (150,528 bytes)

Remove msqqyai.com - Powered by Reason Core Security