SilentInstaller_dotnet4.exe

am0303

The executable SilentInstaller_dotnet4.exe has been detected as malware by 9 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from d3bt01lx9eiyhq.cloudfront.net.
Product:
am0303

Version:
3.0.0.3

MD5:
920b692a6ab9ac09bcaa2f64db30d889

SHA-1:
fdc381db371ca26869a284b7df98a0f60e958a19

SHA-256:
8883d369e4acc0133d7fcd78c5110f2c86f82f46b5632ab55f6ec0b945674283

Scanner detections:
9 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
5/7/2024 9:45:45 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Virtu-A
160215-2

AVG
Win32/Virut
2015.0.4530

Dr.Web
Win32.Virut.56
9.0.1.05190

ESET NOD32
Win32/Virut.NBP virus
7.0.302.0

F-Prot
W32/Virut.AL!Generic
4.6.5.141

F-Secure
Win32.Virtob.Gen.12
5.15.21

Kaspersky
Virus.Win32.Virut
15.0.0.562

McAfee
Virus.W32/Virut.n.gen
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.215.494.0

File size:
340.5 KB (348,672 bytes)

Product version:
3.0.0.3

Copyright:
Copyright © 2016

Original file name:
SilentInstaller_dotnet4.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\silentinstaller_dotnet4.exe

File PE Metadata
Compilation timestamp:
7/9/2005 8:09:30 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:0FZT8qbTR7SquD4L8vioH/X8i9DLnHWcefjVo8bS5VFs3xLlW3:MZwgVxGq86oH/MKvnolgFMN

Entry address:
0x588E4

Entry point:
83, 3C, 24, FE, 89, DB, 77, FE, 8D, 64, 24, CC, 60, 83, EC, DC, E8, 28, 04, 00, 00, 4B, 8A, EF, 66, 4B, 75, FC, F5, B2, 40, FC, FF, 73, 3C, FE, CA, 59, 81, E9, FD, FF, FF, 7F, 73, E7, FC, 8A, E2, 90, 81, D9, E6, 13, 00, 00, 71, DB, 04, F1, 42, 90, E9, 90, 01, 00, 00, 8B, 52, 0C, 8B, 5A, 1C, 8B, 5B, 08, 6A, 01, 68, 9C, 6A, D3, 03, 4A, E8, 0E, 04, 00, 00, 8B, D4, 90, 97, 6A, 04, 52, 6A, 15, 6A, FF, B8, 09, 12, AA, 3F, B5, 41, E8, F0, 03, 00, 00, 83, C4, 04, 81, C6, EF, 92, 57, 88, 87, FE, 5B, 5F, FF, D7, E8...
 
[+]

Code size:
309 KB (316,416 bytes)

The file SilentInstaller_dotnet4.exe has been seen being distributed by the following URL.

Remove SilentInstaller_dotnet4.exe - Powered by Reason Core Security