private_video_23424.mp4.exe

The executable private_video_23424.mp4.exe has been detected as malware by 27 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from doc-04-5o-docs.googleusercontent.com.
MD5:
dfe733ba086c961458b74747b5707694

SHA-1:
a6757ee1e377003428741cdd7ee3d849ca6f4089

SHA-256:
2cfc898c791076360a9c4b65be4c920348ce942876879d180d2029fb390a0ade

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
4/20/2024 3:23:45 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.RSfb.A
272

AhnLab V3 Security
Trojan/Win32.Downloader
2014.12.05

Avira AntiVirus
TR/Dropper.Gen
7.11.192.154

avast!
VBS:Malware-gen
2014.9-160507

AVG
Ransomer
2017.0.2750

Baidu Antivirus
Trojan.Win32.Delf
4.0.3.1657

Bitdefender
Trojan.RSfb.A
1.0.20.640

Clam AntiVirus
Win.Trojan.Rsfb
0.98/21511

Comodo Security
UnclassifiedMalware
20282

ESET NOD32
Win32/TrojanDropper.Delf.OGG
10.10826

Fortinet FortiGate
W32/Delf.OGG!tr
5/7/2016

F-Secure
Trojan.RSfb.A
11.2016-07-05_7

G Data
Trojan.RSfb
16.5.24

IKARUS anti.virus
Trojan-Dropper.Win32.Delf
t3scan.1.8.5.0

K7 AntiVirus
Trojan
13.186.14239

Malwarebytes
Trojan.Dropper.AD
v2016.05.07.05

McAfee
RDN/Generic Dropper!uz
5600.6406

MicroWorld eScan
Trojan.RSfb.A
17.0.0.384

NANO AntiVirus
Trojan.Win32.Delf.dcxean
0.28.6.63850

Norman
Delf.QTZE
11.20160507

nProtect
Trojan.RSfb.A
14.12.03.01

Panda Antivirus
Trj/CI.A
16.05.07.05

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Sophos
Mal/RarMal-E
4.98

Trend Micro House Call
TROJ_SPNR.09H014
7.2.128

Trend Micro
TROJ_SPNR.09H014
10.465.07

VIPRE Antivirus
Trojan.Win32.Generic
35416

File size:
837.5 KB (857,595 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\private_video_23424.mp4.exe

File PE Metadata
Compilation timestamp:
6/6/2014 8:29:14 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:ImOMSPEKigS2+MeBiNOkSgfaVZTAfejiDvln:mPmg9DugfuAtD9n

Entry address:
0x1D41B

Entry point:
E8, 5D, 64, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 7A, FC, FF, FF, C7, 06, F0, B1, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, C7, 01, F0, B1, 42, 00, E9, 2F, FD, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, F0, B1, 42, 00, E8, 1C, FD, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 86, C9, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 8B, 47, 04, 85, C0, 74, 47, 8D, 50, 08, 80, 3A, 00, 74, 3F, 8B, 75, 0C, 8B, 4E, 04, 3B, C1, 74, 14, 83, C1, 08...
 
[+]

Code size:
161.5 KB (165,376 bytes)

The file private_video_23424.mp4.exe has been seen being distributed by the following URL.

Remove private_video_23424.mp4.exe - Powered by Reason Core Security