pbhaack.exe

PBHAACK

www.easyosteam.com

The executable pbhaack.exe has been detected as malware by 25 anti-virus scanners. The file has been seen being downloaded from download1661.mediafire.com.
Publisher:
www.easyosteam.com

Product:
PBHAACK

Version:
1.0.0.0

MD5:
db4ac07780103675da62da808dfc045d

SHA-1:
1c0272378500a64831de874c353cd0043f0e67ec

SHA-256:
8564988d5f4e10a9508ef911fe4e4803fe997aca239f574cc20e82e87476df31

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
4/18/2024 11:41:40 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2749924
484

Agnitum Outpost
Trojan.PWS.OnLineGames
7.1.1

Avira AntiVirus
TR/Spy.OnlGame.26624.12
8.3.2.2

Arcabit
Trojan.Generic.D29F5E4
1.0.0.568

avast!
Win32:Malware-gen
2014.9-151009

AVG
PSW.MSIL
2016.0.2962

Bitdefender
Trojan.GenericKD.2749924
1.0.20.1410

Comodo Security
UnclassifiedMalware
23333

Emsisoft Anti-Malware
Trojan.GenericKD.2749924
8.15.10.09.11

ESET NOD32
MSIL/PSW.OnLineGames.LN (variant)
9.12338

Fortinet FortiGate
MSIL/Agent.OFU!tr
10/9/2015

F-Secure
Trojan.GenericKD.2749924
11.2015-09-10_6

G Data
Trojan.GenericKD.2749924
15.10.25

IKARUS anti.virus
Trojan.MSIL.PSW
t3scan.1.9.5.0

K7 AntiVirus
Password-Stealer
13.210.17388

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1303

McAfee
Artemis!DB4AC0778010
5600.6618

MicroWorld eScan
Trojan.GenericKD.2749924
16.0.0.846

NANO AntiVirus
Trojan.Win32.OnlGame.dxivex
0.30.26.3725

nProtect
Trojan.GenericKD.2749924
15.10.01.01

Panda Antivirus
Trj/Sharik.B
15.10.09.11

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R02KC0VIS15
10.465.09

VIPRE Antivirus
Trojan.Win32.Generic
44194

File size:
26 KB (26,624 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © www.easyosteam.com 2015

Original file name:
PBHAACK.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\pbhaack.exe

File PE Metadata
Compilation timestamp:
9/21/2015 4:43:16 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:41O3j1Urb/Vez2rtzi8BcPwC2gcjLDYPrJGFKsl0:4c3RUkz2PBY8VjLDYPrJwK00

Entry address:
0x721E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.2794

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
21 KB (21,504 bytes)

The file pbhaack.exe has been seen being distributed by the following URL.

Remove pbhaack.exe - Powered by Reason Core Security