tmp3bf9.exe

Tiramisu

The executable tmp3bf9.exe has been detected as malware by 30 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Oqzqics’.
Publisher:
Tiramisu

Product:
Tiramisu

Version:
8.00.0007

MD5:
34ec22bb42de2c0a45aa65b23b30d84b

SHA-1:
0d142d68e7a2a428d6437fc243a831546b483227

SHA-256:
97ddda41af5e1a2d6f82b97f2a75bfdcefe17dea4eb7efca3890a14282453961

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
4/27/2024 2:43:26 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2531293
558

Agnitum Outpost
Trojan.DR.VB
7.1.1

AhnLab V3 Security
Win-Trojan/MDA.B52502
2015.07.02

Avira AntiVirus
TR/Dropper.VB.929
8.3.1.6

Arcabit
Trojan.Generic.D269FDD
1.0.0.425

avast!
Win32:Malware-gen
2014.9-150726

AVG
Crypt_vb
2016.0.3036

Baidu Antivirus
Trojan.Win32.Dropper
4.0.3.15726

Bitdefender
Trojan.GenericKD.2531293
1.0.20.1035

Dr.Web
Trojan.Siggen6.23087
9.0.1.0207

Emsisoft Anti-Malware
Trojan.GenericKD.2531293
8.15.07.26.05

ESET NOD32
Win32/Injector.CECS (variant)
9.11910

Fortinet FortiGate
W32/VB.DBRA!tr
7/26/2015

F-Secure
Trojan.GenericKD.2531293
11.2015-26-07_1

G Data
Trojan.GenericKD.2531293
15.7.25

IKARUS anti.virus
Trojan.Win32.Injector
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.205.16502

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1800

Malwarebytes
Trojan.VBCrypt
v2015.07.01.11

McAfee
RDN/Generic.dx!d2r
5600.6692

MicroWorld eScan
Trojan.GenericKD.2531293
16.0.0.621

NANO AntiVirus
Trojan.Win32.VB.dtnxus
0.30.24.2487

nProtect
Trojan.GenericKD.2531293
15.07.08.01

Panda Antivirus
Trj/CI.A
15.07.26.05

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R000C0EG815
10.465.26

Vba32 AntiVirus
TScope.Trojan.VB
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
41836

ViRobot
Trojan.Win32.S.Agent.159744.ADA[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Injector.Win32.274610
2.0.0.2276

File size:
156 KB (159,744 bytes)

Product version:
8.00.0007

Copyright:
Tiramisu

Trademarks:
Tiramisu

Original file name:
Tiramisu.exe

File type:
Executable application (Win32 EXE)

Language:
Welsh (Verenigd Koninkrijk)

Common path:
C:\ProgramData\application data\microsoft\performance\monitor\temp\tmp3bf9.exe

File PE Metadata
Compilation timestamp:
4/27/2015 12:10:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:+LUCItjrkEfDqLZTxgpOxwhVn9EOxIBPyAa9ZA18L3xQxJteWPRSYOexf8L:VtjjWZTx0RrxVywsjeWpS7eJ

Entry address:
0x12D4

Entry point:
68, AC, 55, 41, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 50, 00, 00, 00, 00, 00, 00, 00, CB, 11, D6, DD, 5D, A6, 17, 46, 9F, 9C, 3B, C4, D7, 5B, 81, D7, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 2D, 32, 34, 34, 37, 38, 41, 75, DF, 65, 6E, 68, 61, 6E, 64, 65, 6C, 73, 65, 6E, 74, 77, 69, 63, 6B, 6C, 75, 6E, 67, 37, 00, 20, 3D, 20, 31, 33, 35, 31, 00, 00, 00, 00, FF, CC, 31, 00, 03, BA, 4B, 86, 02, 81, 0A, 91, 40, A9, 56, 25, 34, 76, 90, 78, 9B, 2B, 4E, 69, 9F, C7, C4, DC, 4C, A5, 0A, 56...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
128 KB (131,072 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Oqzqics

Command:
C:\users\{user}\appdata\local\oqzqics\tmp3bf9.exe


Remove tmp3bf9.exe - Powered by Reason Core Security