talaash_2012_hindi_movie_dvdscr_xvid-briq.exe

The executable talaash_2012_hindi_movie_dvdscr_xvid-briq.exe has been detected as malware by 10 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.torrntv.com.
MD5:
8bb722e2e2d0291bba388a879c042f5e

SHA-1:
522f62acf93dd483f6de51620d4b95ba4410a6f2

SHA-256:
9ed19313248bf19fa3ee9b4c2de366e9de4cecf0d061df1fc99cbabcc5460619

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
4/24/2024 7:56:40 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160503-1

AVG
Win32/Sality
2015.0.4604

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.225.793.0

Norman
Win32.Sality.3
19.05.2016 05:17:13

VIPRE Antivirus
Threat.4721115
50516

File size:
323.5 KB (331,264 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\talaash_2012_hindi_movie_dvdscr_xvid-briq.exe

File PE Metadata
Compilation timestamp:
12/6/2009 4:20:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:oEtc0Vn9Z6iFw8rb/EkRfL95SL8eIa84f0qPVI5AynE9T:dVn9ZW8//F9Ar8spPV7y0T

Entry address:
0x323C

Entry point:
60, 86, D5, 25, D8, AD, 82, 6A, EB, 06, FE, C7, B1, B0, 0A, FE, 73, 08, C7, C0, C4, 08, AD, 2C, 89, D8, 74, 01, F2, 80, F6, 35, 69, F6, 3C, D9, FE, D9, C6, C2, 83, EB, 06, C7, C7, 64, 41, 6C, A7, 0F, BE, D0, 08, F6, 8B, F0, 0F, BE, FD, 33, FB, B6, C2, FF, C7, 8D, 0E, 4F, 8A, D7, 69, FE, 22, AD, 7D, 56, F7, C5, 23, 98, EE, 93, FF, CF, 81, D2, 4A, 2E, 5E, 0A, 8B, C1, 8A, F7, 0F, B7, D0, 69, D0, 92, FE, D2, 68, 81, FE, AB, CF, 00, 00, 71, 08, 69, CF, 77, ED, 01, A5, 88, E6, 6B, DB, 00, 3B, C5, 76, 03, 0F, BE...
 
[+]

Entropy:
7.7904  (probably packed)

Code size:
23 KB (23,552 bytes)

The file talaash_2012_hindi_movie_dvdscr_xvid-briq.exe has been seen being distributed by the following URL.