pengaktif baru v14.exe

The executable pengaktif baru v14.exe has been detected as malware by 22 anti-virus scanners. The program is a setup application that uses the Self-extracting archive installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from c19.pcloud.com.
MD5:
dfb5f60af096b206f29072567f575098

SHA-1:
64d0f1bf6eb0640bf324c49124093a184e486515

SHA-256:
049d25d69e6b2e41ddecbb65e7273c4013197b1f5134d67f5bdd3aa959d2df81

Scanner detections:
22 / 68

Status:
Malware

Analysis date:
4/26/2024 6:28:08 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.23524
1092

Agnitum Outpost
Trojan.Agent
7.1.1

Avira AntiVirus
TR/Symmi.21243.1
7.11.125.80

Bitdefender
Gen:Variant.Symmi.23524
1.0.20.195

Bkav FE
W32.Clodba7.Trojan
1.3.0.4613

Comodo Security
UnclassifiedMalware
17614

Emsisoft Anti-Malware
Gen:Variant.Symmi.23524
8.14.02.08.10

Fortinet FortiGate
W32/SPNR.08LM13!tr
2/8/2014

F-Secure
Gen:Variant.Symmi.23524
11.2014-08-02_7

G Data
Gen:Variant.Symmi.23524
14.2.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.2.29

K7 AntiVirus
Riskware
13.175.10852

McAfee
Artemis!DFB5F60AF096
5600.7226

MicroWorld eScan
Gen:Variant.Symmi.23524
15.0.0.117

Norman
Troj_Generic.RQUDB
11.20140208

Panda Antivirus
Suspicious file
14.02.08.10

Quick Heal
(Suspicious) - DNAScan
2.14.12.00

Rising Antivirus
PE:Trojan.VB!1.690D
23.00.65.14206

Sophos
Mal/Behav-105
4.96

Trend Micro House Call
TROJ_SPNR.08LM13
7.2.39

Trend Micro
TROJ_SPNR.08LM13
10.465.08

VIPRE Antivirus
Trojan.Win32.Generic
25450

File size:
2.9 MB (3,030,540 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Self-extracting archive

Common path:
C:\users\{user}\downloads\pengaktif baru v14.exe

File PE Metadata
Compilation timestamp:
7/26/2013 3:53:37 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:OBKb26tgFnKSBQf3UO8Sj7abbNyVW+soeZh0BCUJ9Mo5wdlUMmZ0Xl:8KDGFK6Qf30WWpynXc0B7/MoCDkZe

Entry address:
0x1D338

Entry point:
E8, F0, 57, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 05, FD, FF, FF, C7, 06, F4, 81, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, C7, 01, F4, 81, 42, 00, E9, BA, FD, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, F4, 81, 42, 00, E8, A7, FD, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, C9, C9, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 8B, 47, 04, 85, C0, 74, 47, 8D, 50, 08, 80, 3A, 00, 74, 3F, 8B, 75, 0C, 8B, 4E, 04, 3B, C1, 74, 14, 83, C1, 08...
 
[+]

Entropy:
7.9747  (probably packed)

Code size:
148.5 KB (152,064 bytes)

The file pengaktif baru v14.exe has been seen being distributed by the following URL.

Remove pengaktif baru v14.exe - Powered by Reason Core Security