uniextract161_noinst.rar

The file uniextract161_noinst.rar has been detected as a potentially unwanted program by 6 anti-malware scanners. The file has been seen being downloaded from blogattach.naver.net and multiple other hosts.
MD5:
949a20402c22a860d681b0b447244ec0

SHA-1:
e960091d203c84c6034c14a6146f8f4bb638b11a

SHA-256:
ce6e10bb0af83ed061b41860c0277ff42dc90d6982dd8c17c57cf81da1eef054

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 12:15:29 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
EICAR-AV-Test
2.1.4+

Bkav FE
HW32.Packed
1.3.0.6267

Qihoo 360 Security
qex.eicar.gen.gen
1.0.0.1015

Reason Heuristics
Unnamed.Threat.14
14.12.10.9

Sophos
PUA 'ForceLibrary' (of type Hacktool)
5.08

ViRobot
Trojan.Win32.A.Inject.5186991
2011.4.7.4223

File size:
4.9 MB (5,186,991 bytes)

Common path:
C:\users\{user}\downloads\uniextract161_noinst.rar

The file uniextract161_noinst.rar has been seen being distributed by the following 2 URLs.

http://blogattach.naver.net/aa3fb6061e212097bf5e3f0933d5aad67124d8f5/20160513_224_blogfile/.../???? ?????uniextract161.rar?type=attachment

Remove uniextract161_noinst.rar - Powered by Reason Core Security