ts3_sounddriver.exe

BCVcEOBPffb

qApjeN

The executable ts3_sounddriver.exe has been detected as malware by 24 anti-virus scanners. The file has been seen being downloaded from goo.gl.
Publisher:
qApjeN

Product:
BCVcEOBPffb

Description:
TlZ3Nsiwan

Version:
4.4.525.607

MD5:
6c3f4c04485e68ce61614b0426dcc6d8

SHA-1:
d9fe0abc00fe1e7fe2f6de1c3dba826a47390035

SHA-256:
30991759d0e907390a23ebc10e34ad630584a76e534d0b1db0641d83cee847ea

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/25/2024 8:16:27 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2559098
5836431

Avira AntiVirus
TR/Dropper.MSIL.105281
8.3.1.6

Arcabit
Trojan.Generic.D270C7A
1.0.0.425

avast!
Win32:Malware-gen
150717-0

AVG
Atros
2016.0.3036

Bitdefender
Trojan.GenericKD.2559098
1.0.20.1040

Emsisoft Anti-Malware
Trojan.GenericKD.2559098
10.0.0.5366

ESET NOD32
MSIL/Kryptik.CVB (variant)
9.12000

Fortinet FortiGate
W32/Inject.CDLX!tr
7/27/2015

F-Secure
Trojan.GenericKD.2559098
5.14.151

G Data
Trojan.GenericKD.2559098
15.7.25

K7 AntiVirus
Trojan
13.207.16685

Kaspersky
Trojan.MSIL.Inject
15.0.0.543

Microsoft Security Essentials
Threat.Undefined
1.203.493.0

MicroWorld eScan
Trojan.GenericKD.2559098
16.0.0.624

NANO AntiVirus
Trojan.Win32.Inject.dtszhk
0.30.24.2668

Norman
Trojan.GenericKD.2559098
07.07.2015 03:10:29

nProtect
Trojan.GenericKD.2559098
15.07.23.01

Panda Antivirus
Trj/CI.A
15.07.27.07

Qihoo 360 Security
Win32/Trojan.2b9
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R00JC0DGH15
10.465.27

VIPRE Antivirus
Threat.4150696
41608

File size:
1 MB (1,056,768 bytes)

Product version:
4.4.525.607

Copyright:
Copyright (C) 2006-2014 WPcIQPtOf7 O59MmB9jsDec

Original file name:
h6T8GVZ.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ts3_sounddriver.exe

File PE Metadata
Compilation timestamp:
7/10/2015 9:53:27 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:QsShX0oUn2ZVkInMuWbVZclG/ZAmhWJWYc34xvxjjjTjjj4Qgpcby1qfZyxYPrgG:pShXNTZVQuAVbAtS34e71CExergzCF

Entry address:
0xA670E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.3365

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
660 KB (675,840 bytes)

The file ts3_sounddriver.exe has been seen being distributed by the following URL.

Remove ts3_sounddriver.exe - Powered by Reason Core Security