ntr2013.exe

The executable ntr2013.exe has been detected as malware by 20 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download1694.mediafire.com and multiple other hosts.
Version:
1.1.5.0

MD5:
2a6d6d4f363779c01cfa61017cd98493

SHA-1:
740dc8f7020dc6327e14ec4a924ea2dce44ede4f

SHA-256:
442cdd57f0910f7458fb96fcf88d65af39643dac19bc3653aee7fb9da8657b38

Scanner detections:
20 / 68

Status:
Malware

Analysis date:
4/23/2024 6:13:40 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.8816189
1103

Avira AntiVirus
SPR/AutoIt.Gen
7.11.127.82

avast!
Win32:Malware-gen
2014.9-140127

AVG
Dropper.Generic8
2015.0.3581

Bitdefender
Trojan.Generic.8816189
1.0.20.135

Bkav FE
HW32.CDB
1.3.0.4923

Comodo Security
UnclassifiedMalware
17683

Emsisoft Anti-Malware
Trojan.Generic.8816189
8.14.01.27.05

F-Secure
Trojan.Generic.8816189
11.2014-27-01_2

G Data
Trojan.Generic.8816189
14.1.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.2.2.29

K7 AntiVirus
Riskware
13.175.10972

McAfee
Artemis!2A6D6D4F3637
5600.7237

MicroWorld eScan
Trojan.Generic.8816189
15.0.0.81

Norman
Suspicious_Gen4.CFFED
11.20140127

nProtect
Trojan.Generic.8816189
14.01.27.01

Reason Heuristics
Unnamed.Threat.14
14.3.6.7

Rising Antivirus
PE:Trojan.Win32.Generic.14AF1991!347019665
23.00.65.14125

Trend Micro House Call
TROJ_GEN.R0CBH07K313
7.2.27

VIPRE Antivirus
Trojan.Win32.Packer.EnigmaProtector1.1X-1.3X
25858

File size:
1.5 MB (1,540,200 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\norton 2013 license\ntr2013.exe

File PE Metadata
Compilation timestamp:
1/30/2012 12:32:28 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:wCfSUNPudgWtzMsHpmcYwI/tEU8xB5rJJQW2RzAu9jWhISo6QSUze:wqSUkgWJMsJmpwI/tEU8lJJZ2Rzl9jWL

Entry address:
0x18D1

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, 10, 40, 00, E8, 01, 00, 00, 00, 9A, 83, C4, 10, 8B, E5, 5D, E9, 27, D6, 57, 00, FF, AC, 39, 2E, 48, 54, 0E, B4, 2F, 0D, 23, 50, 4F, 1D, C5, 07, DC, 6D, 4B, 2A, 65, 7B, 9F, E8, AE, 81, CB, 02, 5D, 40, 7E, 77, 6F, 42, 40, 0D, 79, 3D, 02, A0, 7E, 95, 12, 57, E0, B7, 89, CC, 64, F6, D9, 85, BE, 60, 68, AC, 34, FD, 3E, 27, 63, 11, 66, C3, 6E, 32, A2, 5E, 43, CF, 77, 31, 02, B3, 27, 5A, BB, 7B, E9, C1, 66, EE, D4, C6, 86, 6C, AB, 46, 98, BB, 97, 74, 79, 0A, 59, BB, 86, 95, B3, 01...
 
[+]

Entropy:
7.6595

Developed / compiled with:
Microsoft Visual C++

Code size:
514 KB (526,336 bytes)

The file ntr2013.exe has been seen being distributed by the following 5 URLs.

Remove ntr2013.exe - Powered by Reason Core Security