raidcall_tw_v8.1.8.exe

The executable raidcall_tw_v8.1.8.exe has been detected as malware by 10 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from update.raidtalk.com.tw.
MD5:
54f7cdc7bc6a193c6ae8f1759dd9f072

SHA-1:
96883341293ddf9b62305f9e9b58511b90f03b76

SHA-256:
ac2fbaad08f1a5cd821f34bdad8307c2b6e928bcb6ce77dfee4bfb8e4fe9b591

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/19/2024 8:01:43 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160414-2

AVG
Win32/Sality
2015.0.4568

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
16.06.21

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.96

Microsoft Security Essentials
Threat.Undefined
1.223.1669.0

Norman
Win32.Sality.3
19.05.2016 01:04:49

VIPRE Antivirus
Threat.4758034
50170

File size:
5 MB (5,280,344 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\raidcall_tw_v8.1.8.exe

File PE Metadata
Compilation timestamp:
3/22/2010 8:59:12 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:6o4WKW6bQRqh8ayE7woIBsby7pibA9uMzIAX2ni3tQSl2HspsgfsawRTw:sZXYE8aP7woIBsbTb8mq2c2MpsgfaRTw

Entry address:
0x114F

Entry point:
0F, CD, 50, 8D, 05, E5, EE, EA, 95, 13, CD, 33, F8, F7, C2, 10, EA, C3, 8E, 53, 68, D7, 8E, D3, 00, F6, C5, 8C, FF, C5, 51, C6, C1, 16, E8, 00, 00, 00, 00, FE, CD, 19, F8, 81, EB, 60, D0, 00, 00, 69, EA, 03, FD, 7B, 75, 81, C3, 61, 03, 00, 00, 58, 81, E3, 75, A6, CA, 7B, 0F, B7, D2, 03, C8, 80, C7, 94, 18, C3, 84, FC, 69, D0, EF, 78, 9B, 63, F6, C1, 61, 87, DE, BD, A4, 4C, 0C, 00, 81, C5, F8, 3D, 00, 00, 08, FF, 0F, CE, 33, D6, B7, 00, 8D, 5D, 00, 8D, 13, B7, 37, EB, 02, 00, DF, 8D, 32, 4B, 81, F9, 4C, A3...
 
[+]

Entropy:
7.9958  (probably packed)

Code size:
57.5 KB (58,880 bytes)

The file raidcall_tw_v8.1.8.exe has been seen being distributed by the following URL.

Remove raidcall_tw_v8.1.8.exe - Powered by Reason Core Security