performance.exe

The executable performance.exe has been detected as malware by 24 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from down1.optimizedisk.com and multiple other hosts.
MD5:
259b612b11d4a9f9150393e5670b2c09

SHA-1:
32c9bfd69fce98f55cbc05b89faa4cb5103422cb

SHA-256:
607dba4d381521b28a3daf9d3c9e140f19d7c2096cd587759d304328b77aa7b9

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/29/2024 2:45:23 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.537936
707

Avira AntiVirus
TR/Kazy.2782720
7.11.212.228

avast!
Win32:Dropper-gen [Drp]
2014.9-150228

Baidu Antivirus
Trojan.Win32.Sasfis
4.0.3.15316

Bitdefender
Gen:Variant.Kazy.537936
1.0.20.295

Bkav FE
HW32.Packed
1.3.0.6379

Comodo Security
UnclassifiedMalware
21412

Dr.Web
Trojan.KillFiles.25290
9.0.1.075

Emsisoft Anti-Malware
Gen:Variant.Kazy.537936
8.15.02.28.08

Fortinet FortiGate
W32/Sasfis.EIOR!tr
3/16/2015

F-Prot
W32/Threat-HLLIE-based
v6.4.7.1.166

F-Secure
Gen:Variant.Kazy.537936
11.2015-28-02_7

G Data
Gen:Variant.Kazy.537936
15.2.25

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.6.0

K7 AntiVirus
Riskware
13.200.15262

Kaspersky
Trojan.Win32.Sasfis
14.0.0.2335

McAfee
Artemis!259B612B11D4
5600.6841

MicroWorld eScan
Gen:Variant.Kazy.537936
16.0.0.177

Panda Antivirus
Trj/Genetic.gen
15.03.16.11

Qihoo 360 Security
HEUR/QVM18.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.16.23

Trend Micro House Call
TROJ_GEN.R047H09BO15
7.2.59

VIPRE Antivirus
Trojan.Win32.Generic
37980

ViRobot
Trojan.Win32.A.Sasfis.2766336.C[h]
2014.3.20.0

File size:
2.7 MB (2,782,720 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\performance.exe

File PE Metadata
Compilation timestamp:
2/4/1972 3:01:20 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:/8lzq8VOZwyNXeuXioaYuOB0V0bDUgsD7NMyeD3kbbOGfMcBD6sQ9gp4zlSB0nPN:0l2RnQeTPUga7Ne3G8sizlSBYPJ

Entry address:
0x5C821

Entry point:
E8, 61, 00, 00, 00, E9, 79, FE, FF, FF, 68, 60, BB, 44, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, CC, 6E, 46, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, CC, CC, 83, C4, 04, E9, F1, 68, A2, 00, 09, 55, A3, 4F, 05, CA, 42, 90, 38, 0A, CE, F3, 2A, 05, 7A, 53, A8, 41...
 
[+]

Code size:
1.7 MB (1,757,184 bytes)

The file performance.exe has been seen being distributed by the following 2 URLs.

Remove performance.exe - Powered by Reason Core Security