tmpa84c.exe

Weigh

Blind tax waste - www.Weigh.com

The executable tmpa84c.exe, “Betsy spider tightly” has been detected as malware by 26 anti-virus scanners.
Publisher:
Blind tax waste - www.Weigh.com

Product:
Weigh

Description:
Betsy spider tightly

Version:
6.0.0.1

MD5:
e48bfca047410a8f89419461cd7693d4

SHA-1:
a9aff704817491bc874652406021431591b2f1af

SHA-256:
f7db81e7341d3ed49e190ce6868ab563b09f5d4e13370755d562f1c84472deed

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
4/19/2024 8:30:57 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.474643
827

AegisLab AV Signature
Troj.W32.Gen
2.1.4+

AhnLab V3 Security
Dropper/Win32.Necurs
2014.10.31

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

avast!
Win32:Kryptik-OGB [Trj]
141025-0

AVG
Win32/Cryptor
2014.0.4040

Bitdefender
Gen:Variant.Kazy.474643
1.0.20.1515

Comodo Security
TrojWare.Win32.Yakes.DNG
19945

Emsisoft Anti-Malware
Gen:Variant.Kazy.474643
8.14.10.30.07

ESET NOD32
Win32/Injector.BLNN (variant)
8.10646

Fortinet FortiGate
W32/Kryptik.BPPO!tr
10/30/2014

F-Prot
W32/Powessere.A.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Kazy.474643
11.2014-30-10_5

G Data
Gen:Variant.Kazy.474643
14.10.24

IKARUS anti.virus
Trojan.Inject2
t3scan.1.8.3.0

K7 AntiVirus
Trojan
13.185.13853

Malwarebytes
Trojan.Ransom.ED
v2014.10.30.07

McAfee
GenericATG-FAJO!E48BFCA04741
5600.6961

Microsoft Security Essentials
Threat.Undefined
1.187.750.0

MicroWorld eScan
Gen:Variant.Kazy.474643
15.0.0.909

NANO AntiVirus
Trojan.Win32.BLNN.dgrdri
0.28.6.62995

Norman
Injector.HHJL
11.20141030

Quick Heal
TrojanRansom.Crowti.A6
10.14.14.00

Sophos
Mal/Wonton-J
4.98

Vba32 AntiVirus
Heur.Malware-Cryptor.Ngrbot
3.12.26.3

VIPRE Antivirus
Threat.5064238
34232

File size:
411.4 KB (421,290 bytes)

Product version:
2.0

Copyright:
Copyright (C) Weigh 2001-2013

File type:
Executable application (Win32 EXE)

Language:
Arabic (Saudi Arabia)

Common path:
C:\users\{user}\appdata\local\temp\tmpa84c.exe

File PE Metadata
Compilation timestamp:
9/8/2014 8:18:33 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:MuFzxO27Lz0hnIsNgFmggP9zLCxAdb+pRX:MuFzxO2zAtSayxAdbS

Entry address:
0xF573

Entry point:
E8, D3, 50, 00, 00, E9, 1E, FE, FF, FF, CC, CC, CC, 53, 56, 8B, 44, 24, 18, 0B, C0, 75, 18, 8B, 4C, 24, 14, 8B, 44, 24, 10, 33, D2, F7, F1, 8B, D8, 8B, 44, 24, 0C, F7, F1, 8B, D3, EB, 41, 8B, C8, 8B, 5C, 24, 14, 8B, 54, 24, 10, 8B, 44, 24, 0C, D1, E9, D1, DB, D1, EA, D1, D8, 0B, C9, 75, F4, F7, F3, 8B, F0, F7, 64, 24, 18, 8B, C8, 8B, 44, 24, 14, F7, E6, 03, D1, 72, 0E, 3B, 54, 24, 10, 77, 08, 72, 07, 3B, 44, 24, 0C, 76, 01, 4E, 33, D2, 8B, C6, 5E, 5B, C2, 10, 00, 8B, FF, 55, 8B, EC, 56, FF, 35, D0, 79, 42...
 
[+]

Entropy:
7.3548

Code size:
112.5 KB (115,200 bytes)

Remove tmpa84c.exe - Powered by Reason Core Security