Multi-Email Bomber.exe

Multi Email Bomber

Ghoster

This is a setup program which is used to install the application. The file has been seen being downloaded from download1159.mediafire.com.
Publisher:
Ghoster

Product:
Multi Email Bomber

Version:
1.0.0.0

MD5:
edc14bf66aaf477d8e3979269184ee78

SHA-1:
4179422c4e8d3a8a4b1542789da0ee34a1d429df

SHA-256:
cbd265371e6a5c3be8a61985ec7f60ec3df5348d9e047399ba24338a5c62e5eb

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/24/2024 6:18:26 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/ATRAPS.Gen2
8.3.1.6

IKARUS anti.virus
Trojan.ATRAPS
t3scan.1.9.5.0

McAfee
Artemis!EDC14BF66AAF
5600.6358

SUPERAntiSpyware
Trojan.Hoster
9061

File size:
196 KB (200,704 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2012

Original file name:
Multi-Email Bomber.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\multi-email bomber.exe

File PE Metadata
Compilation timestamp:
7/17/2012 11:40:56 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:XgXGdmpSxA+LTScOCOEKPIAc7dmpSxA+LT:0GBA+vS2j3BA+v

Entry address:
0x21A6E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
127 KB (130,048 bytes)

The file Multi-Email Bomber.exe has been seen being distributed by the following URL.

Scan Multi-Email Bomber.exe - Powered by Reason Core Security