New Dos.exe

DDoS Booter

XTremeHacker

The executable New Dos.exe, “XTremeHacker DDoS” has been detected as malware by 13 anti-virus scanners. The file has been seen being downloaded from download1912.mediafire.com.
Publisher:
XTremeHacker

Product:
DDoS Booter

Description:
XTremeHacker DDoS

Version:
1.0.0.0

MD5:
9003fe82c95673638bddc08ce17887ed

SHA-1:
b388b555cf5fa37db19fffd7d8f74713ed647a84

SHA-256:
34db735806954103e1ddaf5d2e3fe209e8cc8014cb7141dbc9ea5f39e9d006bb

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
4/26/2024 6:26:13 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1651815
947

Bitdefender
Trojan.GenericKD.1651815
1.0.20.915

Bkav FE
HW32.CDB
1.3.0.4959

Emsisoft Anti-Malware
Trojan.GenericKD.1651815
8.14.07.02.09

F-Secure
Trojan.GenericKD.1651815
11.2014-02-07_4

G Data
Trojan.GenericKD.1651815
14.7.24

Kaspersky
Trojan.Win32.Badur
14.0.0.3620

McAfee
Artemis!9003FE82C956
5600.7081

MicroWorld eScan
Trojan.GenericKD.1651815
15.0.0.549

nProtect
Trojan.GenericKD.1651815
14.04.24.02

Qihoo 360 Security
Win32/Trojan.24e
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R00UH07DM14
7.2.183

Vba32 AntiVirus
Trojan.Badur
3.12.26.0

File size:
4.1 MB (4,327,936 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
New Dos.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\new dos.exe

File PE Metadata
Compilation timestamp:
4/11/2014 3:01:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:/zeR6olUePCtY4KXcJ13AOTN7YEAREGujouhouwLh3t+KAW95cTabE8dKUMy2QDK:/zvo0v4S5vTuuDPMr/K/+UO7V3+I+S/u

Entry address:
0x411696

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, DC, 64, 48, 53, 00, 00, 00, 00, 02, 00, 00, 00, 79, 00, 00, 00, D8, 16, 41, 00, D8, F8, 40, 00, 52, 53, 44, 53, A0, 9E, FA, 4A, 5D, B1, 06, 48, 83, 15, 88, B8, C1, 58, C3, 3E, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 54, 72, 6F, 6C, 6C, 5C, 64, 6F, 63, 75, 6D, 65, 6E, 74, 73, 5C, 76, 69, 73, 75, 61, 6C, 20, 73, 74, 75, 64, 69, 6F...
 
[+]

Entropy:
6.7844

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
4.1 MB (4,257,792 bytes)

The file New Dos.exe has been seen being distributed by the following URL.

Remove New Dos.exe - Powered by Reason Core Security