!!!new_iphone7_leaked_photo.jpg.exe

The executable !!!new_iphone7_leaked_photo.jpg.exe has been detected as malware by 24 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from 4shared.com.
MD5:
4cfc4e8fa596cc56d6dfda7cae2bd5d9

SHA-1:
135d68df84854ef912027f15d4e68db59bf34587

SHA-256:
e1844bf334e7748f05d2c67ebcefb785457841c4af9b323549cc3de0b5a1751b

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/26/2024 4:50:59 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.120508
6350265

AhnLab V3 Security
Trojan/Win32.MDA
2015.01.16

avast!
Win32:Malware-gen
150101-1

AVG
Inject2
2016.0.3229

Bitdefender
Gen:Variant.Zusy.120508
1.0.20.75

Bkav FE
W32.Fitashi.Trojan
1.3.0.6267

Dr.Web
Trojan.KillFiles.19707
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Zusy.120508
9.0.0.4799

ESET NOD32
Win32/Agent.VZJ trojan
7.0.302.0

Fortinet FortiGate
W32/Injector.BRVT!tr
1/15/2015

F-Prot
W32/S-d9a04737
v6.4.7.1.166

F-Secure
Gen:Variant.Zusy.120508
5.13.68

G Data
Gen:Variant.Zusy.120508
15.1.24

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.2638

Malwarebytes
Trojan.Rupest
v2015.01.15.09

McAfee
Trojan.PWSZbot-FAHB!4CFC4E8FA596
16.8.708.2

Microsoft Security Essentials
TrojanDownloader:Win32/Joinkjot.gen!A
1.11302

MicroWorld eScan
Gen:Variant.Zusy.120508
16.0.0.45

NANO AntiVirus
Trojan.Win32.Dofoil.dlcaso
0.30.0.64448

Panda Antivirus
Trj/Genetic.gen
15.01.15.09

Sophos
Virus 'Mal/Wonton-AF'
5.09

Vba32 AntiVirus
Malware-Cryptor.Limpopo
3.12.26.3

VIPRE Antivirus
Threat.4657539
36504

Zillya! Antivirus
Backdoor.Androm.Win32.13681
2.0.0.2036

File size:
192.8 KB (197,400 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\!!!new_iphone7_leaked_photo.jpg.exe

File PE Metadata
Compilation timestamp:
12/23/2014 11:42:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:ky71WGMHey0bXYpZgR/MciBgVGyVv/Zu8c2/Ul0:j71okbL/jHw8J/Ua

Entry address:
0x2B66

Entry point:
E8, F1, 22, 00, 00, E9, 78, FE, FF, FF, 2D, A4, 03, 00, 00, 74, 22, 83, E8, 04, 74, 17, 83, E8, 0D, 74, 0C, 48, 74, 03, 33, C0, C3, B8, 04, 04, 00, 00, C3, B8, 12, 04, 00, 00, C3, B8, 04, 08, 00, 00, C3, B8, 11, 04, 00, 00, C3, 8B, FF, 56, 57, 8B, F0, 68, 01, 01, 00, 00, 33, FF, 8D, 46, 1C, 57, 50, E8, 4A, 23, 00, 00, 33, C0, 0F, B7, C8, 8B, C1, 89, 7E, 04, 89, 7E, 08, 89, 7E, 0C, C1, E1, 10, 0B, C1, 8D, 7E, 10, AB, AB, AB, B9, 60, 67, 41, 00, 83, C4, 0C, 8D, 46, 1C, 2B, CE, BF, 01, 01, 00, 00, 8A, 14, 01...
 
[+]

Code size:
35.5 KB (36,352 bytes)

The file !!!new_iphone7_leaked_photo.jpg.exe has been seen being distributed by the following URL.

Remove !!!new_iphone7_leaked_photo.jpg.exe - Powered by Reason Core Security