stealer.exe

The executable stealer.exe has been detected as malware by 19 anti-virus scanners.
Publisher:
Microsoft*  (Invalid match)

Product:
Microsoft

Version:
1.0.0.0

MD5:
05e5de068bbcd433e8e800cf2f2de603

SHA-1:
412666a97fd19e160f257d82cfca04a5d11bf230

SHA-256:
ba9cb32791d10c13b7bc84e65ee1e375095a219ec24cca0b6decfce8e41c6856

Scanner detections:
19 / 68

Status:
Malware

Analysis date:
4/20/2024 1:45:48 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Heur.MSIL.Krypt.2
1022

Agnitum Outpost
Worm.Bladabindi
7.1.1

Avira AntiVirus
TR/Dropper.Gen
7.11.145.90

avast!
MSIL:Injector-FH [Trj]
2014.9-140419

AVG
ILCrypt
2015.0.3500

Bitdefender
Gen:Heur.MSIL.Krypt.2
1.0.20.545

Dr.Web
Tool.PassView.849
9.0.1.0109

Emsisoft Anti-Malware
Gen:Heur.MSIL.Krypt
8.14.04.19.05

ESET NOD32
MSIL/Bladabindi (variant)
8.9727

F-Secure
Gen:Heur.MSIL.Krypt.2
11.2014-19-04_7

G Data
Gen:Heur.MSIL.Krypt
14.4.24

IKARUS anti.virus
HackTool.Win32.MSNPass
t3scan.1.6.1.0

Kaspersky
not-a-virus:HEUR:PSWTool.Win32.NetPass
14.0.0.3994

Malwarebytes
Trojan.Dropper
v2014.04.19.05

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi.G
1.10502

MicroWorld eScan
Gen:Heur.MSIL.Krypt.2
15.0.0.327

Sophos
Mal/MSIL-BA
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-GameJack
10657

VIPRE Antivirus
Trojan.Win32.Generic
28606

File size:
370 KB (378,880 bytes)

Product version:
1.0.0.0

Copyright:
Microsoft

Trademarks:
Microsoft

Original file name:
svchost.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\stealer.exe

File PE Metadata
Compilation timestamp:
4/17/2014 10:59:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:eCbS/QTjhUqBfxrwEnuNcSsm7IoYGW0VvBXCAt6kihB:PQtqB5urTIoYWBQk

Entry address:
0x5D75E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
366 KB (374,784 bytes)

Remove stealer.exe - Powered by Reason Core Security