uplauncher-valor.exe

Ankama Games

The executable uplauncher-valor.exe has been detected as malware by 6 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler named Update triggered to execute each time a user logs in.
Publisher:
Ankama Games  (signed and verified)

Version:
0.0.0.0

MD5:
a1c3235221fa680163ceac3df23984af

SHA-1:
4b573fbbf45139c2e8f8bff68fc93fadba7b944c

SHA-256:
b4d4bcd0d0ba16e730ffb2156c78ef5d23c4315dc5057696554df08ea225354b

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
4/26/2024 10:02:42 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Llac
2016.01.20

Avira AntiVirus
TR/Krypt.1470512
8.3.2.4

ESET NOD32
MSIL/Kryptik.EVS (variant)
10.12896

Kaspersky
Trojan-Dropper.Win32.FrauDrop
14.0.0.776

Malwarebytes
Trojan.Agent.MSIL
v2016.01.22.09

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1077

File size:
1.4 MB (1,470,512 bytes)

Product version:
0.0.0.0

Original file name:
ss.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\uplauncher-valor.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/5/2013 2:00:00 AM

Valid to:
8/6/2015 1:59:59 AM

Subject:
CN=Ankama Games, OU=Editeur, O=Ankama Games, L=Roubaix, S=Nord, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1DAF2407E53BA7C004C253209A2EB841

File PE Metadata
Compilation timestamp:
1/19/2016 11:41:08 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:omBb5pGA410rjgfUgjz5/aqo/EdHTGBP7mTtkp1D2bFrJ5W9vEmrzS7og2Pyj3:omBzGA410AfUkzs/+GKM1ybFl5W9MjxR

Entry address:
0x141EAE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.3 MB (1,310,720 bytes)

Scheduled Task
Task name:
Update

Path:
\Update\Update

Trigger:
Logon (Runs on logon)


Remove uplauncher-valor.exe - Powered by Reason Core Security