po tmoney2014.exe

Supersoft

The application po tmoney2014.exe by Supersoft has been detected as adware by 7 anti-malware scanners.
Publisher:
Supersoft  (signed and verified)

MD5:
69808091c98be0845ac15f82cf2aed72

SHA-1:
0f5215fb9e184570d5f57a5b364a3ff7a903ce51

SHA-256:
3d27a9bf6aad0be4192a1bf73f0978c0346b4dfa99f34e7501c469a0c866da79

Scanner detections:
7 / 68

Status:
Adware

Analysis date:
4/26/2024 12:16:17 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Spyware/Win32.Zbot
2014.07.08

Avira AntiVirus
TR/Dropper.MSIL.65070
7.11.158.200

Baidu Antivirus
Trojan.MSIL.LimitLogger
4.0.3.1477

ESET NOD32
MSIL/Spy.LimitLogger
8.10058

IKARUS anti.virus
Trojan.MSIL.Injector
t3scan.1.6.1.0

Reason Heuristics
PUP.Supersoft.N
14.7.27.14

Sophos
Troj/MSIL-VZ
4.98

File size:
780.2 KB (798,952 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
Supersoft

Valid from:
9/30/2012 10:26:38 AM

Valid to:
1/1/2040 12:59:59 AM

Subject:
CN=Supersoft

Issuer:
CN=Supersoft

Serial number:
6B50254A40C7CFB14A405056B8F04272

File PE Metadata
Compilation timestamp:
7/6/2014 10:20:42 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:+tSsWeL1S/jFjgVtvpc3Pto7y4anDgPdcogkxwelCxB:+4WCj5gXvpcloO4aEVoB

Entry address:
0xC2DBE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 48, 00, 00, 80, 10, 00, 00, 00, 60, 00, 00, 80, 18, 00, 00, 00, 78, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
771.5 KB (790,016 bytes)

Remove po tmoney2014.exe - Powered by Reason Core Security