trz31e7.tmp

The file trz31e7.tmp has been detected as malware by 34 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download.
MD5:
5cbe83bab9e8290d76018f0fe55890fe

SHA-1:
3332ae480dfc20e644ba5b2922a55cda486a12a6

SHA-256:
91e681050a0631febb56ddc35e4b1c4dc1d3a3ccb3c3c83ffa290794af2a65ee

Scanner detections:
34 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/19/2024 3:58:29 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
5828757

Agnitum Outpost
Win32.Sality.BL
7.1.1

AhnLab V3 Security
Win32/Kashu.E
2014.11.24

Avira AntiVirus
W32/Sality.AT
7.11.30.172

avast!
Win32:SaliCode
141119-1

AVG
Win32/Sality
2014.0.4189

Baidu Antivirus
Virus.Win32.Sality.$Emu
4.0.3.141123

Bitdefender
Win32.Sality.3
1.0.20.1635

Bkav FE
W32.Sality.PE
1.3.0.4959

Comodo Security
Virus.Win32.Sality.Gen
20172

Dr.Web
Win32.Sector.22
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
9.0.0.4570

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
11.2014-23-11_1

G Data
Win32.Sality
14.11.24

K7 AntiVirus
Virus
13.185.14098

Kaspersky
Virus.Win32.Sality
15.0.0.543

McAfee
W32/Sality.gen.z
5600.6938

Microsoft Security Essentials
Threat.Undefined
1.189.509.0

MicroWorld eScan
Win32.Sality.3
15.0.0.981

NANO AntiVirus
Virus.Win32.Sality.beygb
0.28.6.63474

Norman
Sality.ZHB
11.20141123

nProtect
Virus/W32.Sality.D
14.11.21.01

Panda Antivirus
W32/Sality.AA
14.11.23.08

Quick Heal
W32.Sality.U
11.14.14.00

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.141121

Sophos
Mal/Sality-D
4.98

Total Defense
Win32/Sality.AA
37.0.11294

Trend Micro House Call
PE_SALITY.RL
7.2.327

Trend Micro
PE_SALITY.RL
10.465.23

Vba32 AntiVirus
Virus.Win32.Sality.bakc
3.12.26.3

VIPRE Antivirus
Threat.4721115
35010

ViRobot
Win32.Sality.N
2011.4.7.4223

File size:
395 KB (404,480 bytes)

File PE Metadata
Compilation timestamp:
10/9/2010 11:59:30 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
6144:Z/bP2yYf7dGr0s+V/5CWnwbJQH1nP55hTprqnKaapdtxre82Ensmzlf+K:FdYA4s+TCMwbOfhqKamdtxbNsmoK

Entry address:
0xB8690

Entry point:
F7, C3, 53, 2A, 4D, BE, 88, C4, 69, FB, BE, F1, E0, A9, 77, 01, 4B, 8B, C9, 01, D9, F2, F6, C4, 03, 14, 2C, 69, FF, 80, 53, BD, A5, 81, D3, 97, 92, CF, 07, C6, C3, 12, C6, C7, 24, 8D, 4D, 00, 86, E7, FF, C3, 8B, DB, 09, C0, 51, BA, ED, 7F, A1, FF, F7, C5, 25, 17, DB, AF, 5D, 86, DE, 8A, F7, F3, 42, 85, EB, 0F, AF, D7, F2, B8, 00, 00, 00, 00, 8D, 1D, 3E, EF, BC, A2, 4D, 4E, 81, CB, B6, 64, 03, 02, F3, 05, 01, 00, 00, 00, 89, DE, 8B, F8, 8B, FB, 69, F0, E9, DB, B4, 0A, F7, C2, 71, 28, FC, 9D, 70, 02, 2A, C8...
 
[+]

Entropy:
7.8278  (probably packed)

Code size:
316 KB (323,584 bytes)

Remove trz31e7.tmp - Powered by Reason Core Security