unlocker1-9-2.exe

The executable unlocker1-9-2.exe has been detected as malware by 7 anti-virus scanners. The program is a setup application that uses the Nullsoft Scriptable Install System installer, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from unlocker.en.softonic.com.
MD5:
c585828383b14357d6051423bc92c560

SHA-1:
b3e099b5637d68b6bafc1eb9f3794690c205270e

SHA-256:
42a93d92beec941fb55a2327d1b07d4d0da1dce1bf19891ef72fef19f3ef10c7

Scanner detections:
7 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 2:52:39 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160708-3

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.225.1261.0

Norman
Win32.Sality.3
19.05.2016 01:04:49

VIPRE Antivirus
Threat.4758034
50516

File size:
1.1 MB (1,148,223 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\unlocker1-9-2.exe

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:5a3LNEAMeYSiGTpTLDxxwqQcqOj5eyHox6ZGmAuXE7ZBlbT:spEMPbVvwqQpoLHontDrlbT

Entry address:
0x30CB

Entry point:
01, C8, C7, C7, D6, 0D, 47, CA, 2A, C5, 2C, FB, 81, F6, 04, 80, 00, 00, 89, F5, C7, C3, EA, 7B, F3, 25, 3D, 2C, 8D, 00, 00, 76, 0D, 8B, ED, 0F, B6, CD, FF, C6, 8D, 35, C6, 48, A6, 58, 69, EB, 2F, 14, EB, A6, 01, DB, E8, 14, 00, 00, 00, 8A, E7, F6, D4, 81, FD, 91, 0D, 00, 00, 71, 02, 0F, C8, 81, FB, 1B, E9, 00, 00, 77, 05, 38, F3, 0F, AF, D5, 0F, B7, F1, 8D, 3D, 18, 0D, 00, 00, F7, C1, 46, C4, 90, 8E, 81, EF, 18, 0D, 00, 00, 8D, 05, BA, 0C, 3A, 99, 88, D4, 8A, C4, 81, C7, 01, 00, 00, 00, 80, E7, 95, 69, CD...
 
[+]

Code size:
22.5 KB (23,040 bytes)

The file unlocker1-9-2.exe has been seen being distributed by the following URL.

Remove unlocker1-9-2.exe - Powered by Reason Core Security