portraitprofessionalstudio.exe

Portrait Professional

Anthropics Technology Ltd.

The executable portraitprofessionalstudio.exe has been detected as malware by 20 anti-virus scanners.
Publisher:
Anthropics Technology Ltd.

Product:
Portrait Professional

Version:
10, 9, 3, 0

MD5:
a4503f74903c97ab1ff4968c1d0e4435

SHA-1:
8e03b6fa573e64f8ef1299f5b86a278235e43708

SHA-256:
276556a2c50d6395b3eed5687081c7e0f0e19c169eef70a0ec58428c64a22e61

Scanner detections:
20 / 68

Status:
Malware

Analysis date:
4/26/2024 4:12:09 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.W32.Gen
2.1.4+

Agnitum Outpost
Trojan.Packed
7.1.1

Avira AntiVirus
TR/Agent.VMProtect.aba.3
7.11.154.60

AVG
Generic6_c
2015.0.3446

Baidu Antivirus
Trojan.Win32.VMProtect
4.0.3.14612

Bkav FE
HW32.TsCabk
1.3.0.4959

Comodo Security
UnclassifiedMalware
18503

ESET NOD32
Win32/Packed.VMProtect.ABA (variant)
8.9924

Fortinet FortiGate
W32/Generic
6/12/2014

IKARUS anti.virus
Trojan.Agent
t3scan.1.6.1.0

K7 AntiVirus
Riskware
13.1712358

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3723

McAfee
Artemis!A4503F74903C
5600.7102

Norman
Suspicious_Gen4.BFGIE
11.20140612

Panda Antivirus
Trj/Thed.W
14.06.12.09

Qihoo 360 Security
Win32/Trojan.e6d
1.0.0.1015

Sophos
Mal/VMProtBad-A
4.98

Trend Micro House Call
TROJ_GEN.R0CBC0RBA14
7.2.163

Trend Micro
TROJ_GEN.R0CBC0RBA14
10.465.12

VIPRE Antivirus
Trojan.Win32.Generic
30164

File size:
6 MB (6,324,736 bytes)

Product version:
10, 9, 3, 0

Copyright:
Copyright 2012 Anthropics Technology Ltd.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\portrait professional studio 10\portraitprofessionalstudio.exe

File PE Metadata
Compilation timestamp:
4/5/2012 10:10:28 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:f+0K8GFvjEwLBp+SMgVvWbNiXuFTDDbmS8OUmpCd8UYnCWsY9/Medmo5A+WWoF6r:FpGFQAB5irDbmlOU+CGRH3moX0oxzSo

Entry address:
0xC3F84C

Entry point:
E9, 1A, DF, 18, 00, 5A, FC, AE, 92, 07, 57, 37, 96, A9, C8, 61, D3, 32, 92, AD, 0F, 79, 6E, 32, D2, FA, 6E, 0C, 46, 01, 62, 9D, D1, A3, 54, B1, 24, 4A, 6D, D2, FD, 6B, E5, 6D, 03, 30, A8, A2, C7, 62, D7, 61, 20, 9A, 25, 67, D2, 6D, 2F, D0, 0F, 82, 6F, 6F, 4B, 40, 23, 66, 99, EF, EB, 9D, 1D, F5, E1, 51, F8, 51, CF, 2C, 4D, 4A, 3B, 1D, 3A, 9E, 08, F5, 55, 97, 65, 69, 24, E9, 59, FC, 34, C6, 98, F9, D7, CA, 7F, 42, FA, 81, B6, 10, ED, 00, E1, 3D, 73, 54, D0, 85, E5, B2, E3, 20, 56, F1, 84, 49, B4, D4, F7, 4C...
 
[+]

Entropy:
7.9102

Packer / compiler:
Xtreme-Protector v1.05

Code size:
2.6 MB (2,725,888 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-23-23-162-63.compute-1.amazonaws.com  (23.23.162.63:80)

Remove portraitprofessionalstudio.exe - Powered by Reason Core Security