stolen_bytes_pespin.exe

The executable stolen_bytes_pespin.exe has been detected as malware by 18 anti-virus scanners.
MD5:
eb360d7bc1be52cf93320f0a96014c08

SHA-1:
7b949a745d44329bbbcd2dc5aeac6cb51a316355

SHA-256:
ef7c4a10074d88f02f2ad1383f470ee43eb69ccdd0f6a1f21e1d1b53bbf867cc

Scanner detections:
18 / 68

Status:
Malware

Analysis date:
4/26/2024 7:06:15 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PeSpin
7.1.1

Avira AntiVirus
HEUR/Crypted
7.11.48.126

Bitdefender
Gen:Packer.PESpin.A.cqWaaC7mzui
1.0.20.565

Comodo Security
TrojWare.Win32.Banbra.sl
14045

Emsisoft Anti-Malware
Gen:Packer.PESpin.A.cqWaaC7mzui
8.14.04.23.07

F-Prot
W32/Patched.R.gen
v6.4.6.5.141

F-Secure
Gen:Packer.PESpin.A.cqWaaC7mzui
11.2014-23-04_4

G Data
Gen:Packer.PESpin.A.cqWaaC7mzui
14.4.22

IKARUS anti.virus
Packer.PESpin
t3scan.1.1.122.0

K7 AntiVirus
Riskware
13.153.7800

MicroWorld eScan
Gen:Packer.PESpin.A.cqWaaC7mzui
15.0.0.339

Norman
W32/Packed_PeSpin.B
11.20140423

Panda Antivirus
Trj/Genetic.gen
14.04.23.07

Quick Heal
(Suspicious) - DNAScan
4.14.12.00

Sophos
Mal/Packer
4.82

Trend Micro House Call
Cryp_PESpin
7.2.113

Trend Micro
Cryp_PESpin
10.465.23

VIPRE Antivirus
Trojan.Win32.Packer.PESpinv1.32
13762

File size:
35.5 KB (36,352 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

CTPH (ssdeep):
768:bVbspikLI6pKOvtvPzR6Ae4aWDTCWTkgwPqapHbEGm2xE/ZToy:bVA0k1pPvt3VobEkgwPqaR1ixs

Entry address:
0xB0D4

Entry point:
EB, 01, 68, 60, E8, 00, 00, 00, 00, 8B, 1C, 24, 83, C3, 12, 81, 2B, E8, B1, 06, 00, FE, 4B, FD, 82, 2C, 24, 17, E6, 46, 00, 0B, E4, 74, 9E, 75, 01, C7, 81, 73, 04, D7, 7A, F7, 2F, 81, 73, 19, 77, 00, 43, B7, F6, C3, 6B, B7, 00, 00, F9, FF, E3, C9, C2, 08, 00, A3, 68, 72, 01, FF, 5D, 33, C9, 41, E2, 17, EB, 07, EA, EB, 01, EB, EB, 0D, FF, E8, 01, 00, 00, 00, EA, 5A, 83, EA, 0B, FF, E2, EB, 04, 9A, EB, 04, 00, EB, FB, FF, E8, 02, 00, 00, 00, A0, 00, 5A, 81, EA, 45, B1, 00, 00, 83, EA, FE, 89, 95, A9, 57, 40...
 
[+]

Entropy:
7.8734

Packer / compiler:
PE Spin v0.4x

Code size:
20 KB (20,480 bytes)

Remove stolen_bytes_pespin.exe - Powered by Reason Core Security