oDownload setup.exe

The executable oDownload setup.exe has been detected as malware by 35 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from pascalcbr.free.fr.
MD5:
e503d81ba361bf7d76e7b3a73af84dab

SHA-1:
265794d34b29ec4ec37050208e9ced7a8df27dcf

SHA-256:
d9a3f650d2078754463dfea633bc4d7e2c512021c90bfa042c731dd64cb3f71e

Scanner detections:
35 / 68

Status:
Malware

Analysis date:
4/26/2024 2:08:33 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Inject.SD
1150

Agnitum Outpost
Trojan.Buzus
7.1.1

AhnLab V3 Security
Trojan/Win32.Buzus
2013.12.28

Avira AntiVirus
SPR/Pwdsteal.C
7.11.122.120

avast!
Win32:Buzus-SV [Trj]
2014.9-130829

AVG
Generic11
2014.0.3543

Baidu Antivirus
Trojan.Win32.Buzus
4.0.3.131127

Bitdefender
Trojan.Inject.SD
1.0.20.1205

Bkav FE
W32.DownloadNodefB.Trojan
1.3.0.4613

Clam AntiVirus
Trojan.Buzus-3568
0.98/18155

Comodo Security
TrojWare.Win32.Trojan.Inject.SD0
17511

Dr.Web
Trojan.MulDrop1.15793
9.0.1.0241

Emsisoft Anti-Malware
Trojan.Inject.SD
8.13.08.29.12

ESET NOD32
Win32/PSW.Agent.NKR (variant)
7.9137

Fortinet FortiGate
W32/Buzus.AQY!tr
8/29/2013

F-Prot
W32/Trojan2.EPHP
v6.4.7.1.166

F-Secure
Trojan.Inject.SD
11.2013-27-11_4

G Data
Trojan.Inject.SD
13.8.22

IKARUS anti.virus
Trojan.Inject
t3scan.2.2.29

K7 AntiVirus
Trojan
13.174.10656

Kaspersky
Trojan.Win32.Buzus
14.0.0.3808

Malwarebytes
Trojan.Delf
v2013.08.29.12

McAfee
Artemis!E503D81BA361
5600.7181

Microsoft Security Essentials
VirTool:Win32/DelfInject.gen!BV
1.165.247.01

MicroWorld eScan
Trojan.Inject.SD
14.0.0.723

NANO AntiVirus
Trojan.Win32.Buzus.sbsl
0.28.0.57029

Norman
Suspicious_Gen2.IMIQ
11.20130829

nProtect
Trojan/W32.Inject.439296.C
13.12.27.01

Panda Antivirus
Trj/Buzus.AH
13.08.29.12

Reason Heuristics
Unnamed.Threat.66
14.3.1.0

Sophos
Mal/Generic-S
4.96

Vba32 AntiVirus
TrojanPSW.Agent
3.12.24.3

VIPRE Antivirus
BehavesLike.Win32.Malware.dss (mx-v)
24832

ViRobot
Trojan.Win32.Buzus.439296.C
2011.4.7.4223

XVirus List
Win.Detected
2.3.31

File size:
429 KB (439,296 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\odownload setup.exe

File PE Metadata
Compilation timestamp:
10/14/2008 12:56:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:jMyX3zAcSD3Dty9ZCOfVavfqfS5cNIdVQXc9PUgzdPOKg2mUHClWqtdyfg:jjzhSDTtyu2Ivz5cN8z5UgzdSpPtdyfg

Entry address:
0x6042

Entry point:
E8, 9F, 31, 00, 00, E9, 16, FE, FF, FF, 3B, 0D, 24, 2F, 41, 00, 75, 02, F3, C3, E9, 1F, 32, 00, 00, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 24, 2F, 41, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 24, 2F, 41, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00...
 
[+]

Entropy:
7.8248  (probably packed)

Code size:
48 KB (49,152 bytes)

The file oDownload setup.exe has been seen being distributed by the following URL.

Remove oDownload setup.exe - Powered by Reason Core Security