phone-locator.exe

The application phone-locator.exe has been detected as a potentially unwanted program by 22 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.phone-locator.pl.
MD5:
010f59e2ad4712853d3ca0d26a52574b

SHA-1:
3abfb332e3cf77829315622bb7ee0c9a7398177d

SHA-256:
260181d72410b90f4a744fe5191b4788b9bafc092bc060ca68c6d622dc8e5d4f

Scanner detections:
22 / 68

Status:
Potentially unwanted

Analysis date:
8/5/2025 1:03:12 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.72303
477

Agnitum Outpost
Riskware.Hoax
7.1.1

Avira AntiVirus
TR/Graftor.137367.6
7.11.214.168

AVG
Skodna.ArchSMS
2016.0.2955

Baidu Antivirus
Trojan.Win32.BadJoke
4.0.3.151015

Bitdefender
Gen:Variant.Strictor.72303
1.0.20.1440

Comodo Security
UnclassifiedMalware
21334

Emsisoft Anti-Malware
Gen:Variant.Strictor.72303
8.15.10.15.06

ESET NOD32
Win32/Hoax.ArchSMS.AGG (variant)
9.11285

F-Prot
W32/A-b6aac9c2
v6.4.7.1.166

F-Secure
Gen:Variant.Strictor.72303
11.2015-15-10_5

G Data
Gen:Variant.Strictor.72303
15.10.25

IKARUS anti.virus
Trojan-Banker.Win32.Banker
t3scan.1.8.6.0

K7 AntiVirus
JokeProgram
13.200.15196

Kaspersky
Hoax.Win32.FakeSMSLocate
14.0.0.1271

McAfee
GenericR-AVZ!010F59E2AD47
5600.6611

MicroWorld eScan
Gen:Variant.Strictor.72303
16.0.0.864

NANO AntiVirus
Trojan.Win32.Graftor.cyxrkw
0.30.0.296

Panda Antivirus
Trj/Chgt.A
15.10.15.06

Qihoo 360 Security
Win32/Trojan.885
1.0.0.1015

Sophos
Generic PUA DK
4.98

VIPRE Antivirus
Hoax.Win32.FakeSMSLocate (not malicious)
38228

File size:
3.1 MB (3,245,056 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\phone-locator.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:W4SHtNxcNvaj6RSQo5TuTZCIOv5scUL2j1y+hP:WFH9b6gQzCIOv5scUL2j1yY

Entry address:
0x137DA4

Entry point:
55, 8B, EC, 83, C4, F0, B8, B4, 78, 53, 00, E8, 18, E9, EC, FF, A1, 28, 05, 54, 00, 8B, 00, E8, 68, B9, F2, FF, A1, 28, 05, 54, 00, 8B, 00, BA, 1C, 7E, 53, 00, E8, 4F, B5, F2, FF, 8B, 0D, 90, 03, 54, 00, A1, 28, 05, 54, 00, 8B, 00, 8B, 15, A4, 56, 53, 00, E8, 57, B9, F2, FF, 8B, 0D, E0, 01, 54, 00, A1, 28, 05, 54, 00, 8B, 00, 8B, 15, EC, 76, 53, 00, E8, 3F, B9, F2, FF, A1, 28, 05, 54, 00, 8B, 00, E8, B3, B9, F2, FF, E8, 32, C4, EC, FF, 00, 00, FF, FF, FF, FF, 0B, 00, 00, 00, 4C, 6F, 6B, 61, 6C, 69, 7A, 61...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.2 MB (1,273,856 bytes)

The file phone-locator.exe has been seen being distributed by the following URL.

Remove phone-locator.exe - Powered by Reason Core Security