rcsetup152.exe

FroggerExtreme

bobby

The executable rcsetup152.exe has been detected as malware by 8 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from filehippo.com.
Publisher:
bobby

Product:
FroggerExtreme

Version:
1.00

MD5:
f7a34a44138f744d0db4c8166527f240

SHA-1:
a131be59b154065e52f1cc7bf78dc1ef60d29360

SHA-256:
8e4c31cb0383e256048da12b7e36340f252941bfa871f189a67bb22d88cf0fc9

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
4/19/2024 5:01:30 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1982291
5813571

avast!
Win32:Malware-gen
160112-0

Dr.Web
Trojan.Siggen6.21548
9.0.1.05190

Emsisoft Anti-Malware
Trojan.GenericKD.1982291
10.0.0.5366

ESET NOD32
Win32/Injector.BJZL trojan
7.0.302.0

Kaspersky
Trojan-Dropper.Win32.VB
15.0.0.562

McAfee
Trojan.GenericR-ASC!F7A34A44138F
18.0.204.0

Norman
Trojan.GenericKD.1982291
11.01.2016 17:30:26

File size:
5 MB (5,265,814 bytes)

Product version:
1.00

Original file name:
FroggerExtreme.exe

File type:
Executable application (Win32 EXE)

Language:
Spanish

Common path:
C:\users\{user}\downloads\rcsetup152.exe

File PE Metadata
Compilation timestamp:
5/6/2014 1:09:09 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
46.0

CTPH (ssdeep):
98304:1qiVrwS5/codOojppgYazg0zvAtG8fqGwbFlc23BTFw6Vkf31+P5:EiCjU2YakSWGZGwbfhlFwOkfF+h

Entry address:
0x2FC0

Entry point:
68, F4, 8B, 41, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 1A, F0, 45, A9, 34, 0A, 14, 45, B1, D9, 54, F9, 96, BD, 64, 07, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 46, 72, 6F, 67, 67, 65, 72, 45, 78, 74, 72, 65, 6D, 65, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 05, 44, 9C, CF, 83, FF, BB, 81, 43, BD, DB, 64, 0A, E1, A8, 31, 53, 07, 59, 80, 10, 3D, DF, 8A, 45, A5, E1, 82, 0C, 20, 34, 1D, 3B, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
560 KB (573,440 bytes)

The file rcsetup152.exe has been seen being distributed by the following URL.

Remove rcsetup152.exe - Powered by Reason Core Security