sys32.exe

The executable sys32.exe has been detected as malware by 6 anti-virus scanners.
MD5:
2b5ae4460133004c3ea16bb5c3ed9326

SHA-1:
c716809072bdfd6887e8663800a5ac38ad4fab8e

SHA-256:
27f31379a12bd094fcaa51953da041a82f44a415fac10827bc6f93154d04b5e5

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
5/10/2024 12:27:55 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
MSIL:GenMalicious-AV [Trj]
140813-1

AVG
Trojan horse PSW.ILUSpy
2014.0.3986

Dr.Web
BackDoor.Bladabindi.1194
9.0.1.05190

ESET NOD32
MSIL/Bladabindi.BH trojan
7.0.302.0

Microsoft Security Essentials
Threat.Undefined
1.183.359.0

VIPRE Antivirus
Threat.4799966
32210

File size:
24 KB (24,576 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
7/12/2014 11:35:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:AcKDEq5xnXwwyKqvSNYhx5vcCADXrLkFYht/JiNsf/EU/45EucY2j8kM9lUGszzh:Awq6vS4rEFXlTBiNsf/z/C/k8kFVjt

Entry address:
0x77EE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 00, 00, 00, 00, 01, 00, 18, 00, 00, 00, 18, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 30, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 48, 00, 00, 00, 58, 80, 00, 00, E7, 01, 00, 00, E4, 04, 00, 00, 00, 00, 00, 00, 3C, 3F, 78, 6D, 6C, 20, 76, 65, 72, 73, 69, 6F, 6E, 3D, 22, 31, 2E, 30, 22, 20, 65, 6E...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
22 KB (22,528 bytes)

Remove sys32.exe - Powered by Reason Core Security