Application System.exe

Application System

The file Application System.exe has been detected as malware by 30 anti-virus scanners.
Product:
Application System

Version:
1.0.0.0

MD5:
e651e3777ee4a4033b600e689b9d6b39

SHA-1:
515621e19d6a88beb0d0e7d0d9e594ccc0561642

SHA-256:
aa2e11feb20b4cafa2484e04231cf4e31c93762025f9e79c581adef55f18bf25

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
5/9/2024 1:47:28 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12800989
655

Agnitum Outpost
Trojan.DR.FrauDrop
7.1.1

AhnLab V3 Security
Trojan/Win32.Gen
2015.04.06

avast!
Win32:Malware-gen
2014.9-150421

AVG
Bladabindi
2016.0.3133

Baidu Antivirus
Trojan.Win32.Dropper
4.0.3.15421

Bitdefender
Trojan.Generic.12800989
1.0.20.555

Comodo Security
UnclassifiedMalware
21667

Emsisoft Anti-Malware
Trojan.Generic.12800989
8.15.04.21.06

ESET NOD32
MSIL/Bladabindi.BC
9.11431

Fortinet FortiGate
W32/FrauDrop.AIMSE!tr
4/21/2015

F-Secure
Trojan.Generic.12800989
11.2015-21-04_3

G Data
Trojan.Generic.12800989
15.4.25

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.202.15494

Kaspersky
Trojan-Dropper.Win32.FrauDrop
14.0.0.2159

Malwarebytes
Backdoor.Bladabindi.MSIL
v2015.04.21.06

McAfee
RDN/Generic BackDoor!bb3
5600.6789

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi
1.1.11502.0

MicroWorld eScan
Trojan.Generic.12800989
16.0.0.333

NANO AntiVirus
Trojan.Win32.FrauDrop.dodtju
0.30.8.659

Norman
Suspicious_Gen4.HXOSJ
11.20150421

nProtect
Trojan.Generic.12800989
15.04.03.01

Panda Antivirus
Trj/CI.A
15.04.21.06

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Quick Heal
TrojanDropper.FrauDrop.r4
4.15.14.00

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.F0C2C00C415
7.2.111

Trend Micro
TROJ_GEN.F0C2C00C415
10.465.21

VIPRE Antivirus
Trojan.Win32.Generic
39108

File size:
119.5 KB (122,368 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
Application System.exe

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\microsoft\windows\start menu\programs\startup\trzf03c.tmp

File PE Metadata
Compilation timestamp:
2/10/2015 5:13:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:fnYSylfuHPcpzsFhM+3JyMPWmCaU/6/6IPuiT:wSylfgAzsFhM+lPFQ6

Entry address:
0x1EE5E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.2279

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
116 KB (118,784 bytes)

User Start Menu Item
Name:
trzF03C.tmp


Remove Application System.exe - Powered by Reason Core Security