pespin(1.32).exe

PESpin

cyberbob

The executable pespin(1.32).exe, “Freeware PE-File Compressor/Protector” has been detected as malware by 14 anti-virus scanners.
Publisher:
cyberbob

Product:
PESpin

Description:
Freeware PE-File Compressor/Protector

Version:
x.xx

MD5:
28f56117866fde28701897397d61d498

SHA-1:
89064cab0e4e03e7d081218cd764e8cd89651088

SHA-256:
cec4905b4e44a58c9dd31dd4bdfef1523ff5e068fd3c106b70f9dc5909362b50

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
4/27/2024 3:45:08 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PCK/PESpin
7.11.114.154

ESET NOD32
Win32/Packed.PESpin (variant)
8.9070

Fortinet FortiGate
W32/Cryp_PESpin
4/24/2014

IKARUS anti.virus
Packer.PESpin
t3scan.2.2.29

K7 AntiVirus
Trojan
13.173.10249

McAfee
Generic.dx!28F56117866F
5600.7151

nProtect
Trojan/W32.Agent.68096.T
13.11.19.01

Panda Antivirus
Generic Malware
14.04.24.09

Quick Heal
(Suspicious) - DNAScan
4.14.12.00

Rising Antivirus
Trojan.Win32.Generic.12784C04
23.00.65.14422

Sophos
Mal/EncPk-C
4.94

Trend Micro House Call
Cryp_PESpin
7.2.114

Trend Micro
Cryp_PESpin
10.465.24

VIPRE Antivirus
Trojan.Win32.Packer.PESpinv1.32
23530

File size:
66.5 KB (68,096 bytes)

Product version:
0, 0, 0, 0

Copyright:
Copyright © cyberbob

File type:
Executable application (Win32 EXE)

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

CTPH (ssdeep):
1536:qA+AWLjQCnNs2OpsN201Nyt8WNZymj7VtsyO3X62E9D6U:qwWLjTNxN20Xyt3zJvVtsXXieU

Entry address:
0x150D4

Entry point:
EB, 01, 68, 60, E8, 00, 00, 00, 00, 8B, 1C, 24, 83, C3, 12, 81, 2B, E8, B1, 06, 00, FE, 4B, FD, 82, 2C, 24, 17, E6, 46, 00, 0B, E4, 74, 9E, 75, 01, C7, 81, 73, 04, D7, 7A, F7, 2F, 81, 73, 19, 77, 00, 43, B7, F6, C3, 6B, B7, 00, 00, F9, FF, E3, C9, C2, 08, 00, A3, 68, 72, 01, FF, 5D, 33, C9, 41, E2, 17, EB, 07, EA, EB, 01, EB, EB, 0D, FF, E8, 01, 00, 00, 00, EA, 5A, 83, EA, 0B, FF, E2, EB, 04, 9A, EB, 04, 00, EB, FB, FF, E8, 02, 00, 00, 00, A0, 00, 5A, 81, EA, 45, 51, 01, 00, 83, EA, FE, 89, 95, A9, 57, 40...
 
[+]

Entropy:
7.7667

Packer / compiler:
PE Spin v0.4x

Code size:
54 KB (55,296 bytes)

Remove pespin(1.32).exe - Powered by Reason Core Security