UnLoad.exe

The executable UnLoad.exe has been detected as malware by 24 anti-virus scanners. While running, it connects to the Internet address 209-99-40-219.fwd.datafoundry.com on port 80 using the HTTP protocol.
Version:
0.0.0.0

MD5:
1c5ed9bfd1546edeb465af63f95064d9

SHA-1:
ad7d9a939a11664e9ee881be9765306da7ef2b78

SHA-256:
0cef5995192f21656f26f13a5f0c1b3a378d00281b330fdab505e8673d8e1c7f

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
5/3/2024 9:34:28 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.119483
433

Agnitum Outpost
Trojan.Agent
7.1.1

AhnLab V3 Security
Backdoor/Win32.Torwofun
2015.11.29

Avira AntiVirus
BDS/Backdoor.Gen
8.3.2.4

Arcabit
Trojan.Zusy.D1D2BB
1.0.0.624

avast!
Win32:Malware-gen
2014.9-151128

Baidu Antivirus
Trojan.MSIL.Agent
4.0.3.151128

Bitdefender
Gen:Variant.Zusy.119483
1.0.20.1660

Dr.Web
Trojan.DownLoader12.23010
9.0.1.0332

Emsisoft Anti-Malware
Gen:Variant.Zusy.119483
8.15.11.28.05

ESET NOD32
MSIL/Agent.QBC (variant)
9.12640

Fortinet FortiGate
MSIL/Agent.QBC!tr
11/28/2015

F-Prot
W32/A-770b6427
v6.4.7.1.166

F-Secure
Gen:Variant.Zusy.119483
11.2015-28-11_7

G Data
Gen:Variant.Zusy.119483
15.11.25

IKARUS anti.virus
Trojan-Ransom.Win32.Blocker
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.212.17997

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.1051

Malwarebytes
Ransom.FileCryptor
v2015.11.28.05

Microsoft Security Essentials
Trojan:MSIL/Toauta!rfn
1.1.12300.0

MicroWorld eScan
Gen:Variant.Zusy.119483
16.0.0.996

Panda Antivirus
Trj/CI.A
15.11.28.05

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1077

VIPRE Antivirus
Trojan.Win32.Generic
45482

File size:
74 KB (75,776 bytes)

Product version:
0.0.0.0

Original file name:
UnLoad.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\microsoft update\unload.exe

File PE Metadata
Compilation timestamp:
11/28/2015 12:10:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:96nnDBySpc9Fi9+id5ipOP1nZgnioSrRAznoLKXeEU3xHwsOSz2Q8FjP02K7PhQI:EBySUQ9+idEpsZVoSrRAznoLKXeEU3xV

Entry address:
0x13CDE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
71.5 KB (73,216 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to 209-99-40-219.fwd.datafoundry.com  (209.99.40.219:80)

TCP (HTTP):
Connects to ru.smart-ip.net  (193.178.146.17:80)

TCP (HTTP):
Connects to checkip.dyndns.com  (216.146.43.70:80)

Remove UnLoad.exe - Powered by Reason Core Security