videos_do_youtube_engraçados_005441.exe

safasfaf

kkkkk

The executable videos_do_youtube_engraçados_005441.exe has been detected as malware by 20 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from bit.ly.
Publisher:
kkkkk

Product:
safasfaf

Version:
1.00

MD5:
5b345f429517bb0b0e998f1b1aee0ea4

SHA-1:
2e8b37585c454233f85715f889a249fff0462b6f

SHA-256:
d15b484a45114cd21529004aea2d798244d64a62b8ef29b6d2dd4b541395a4fe

Scanner detections:
20 / 68

Status:
Malware

Analysis date:
4/23/2024 9:23:46 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.48288
389

AhnLab V3 Security
Trojan/Win32.VBKrypt
2013.12.03

Avira AntiVirus
TR/Kazy.48288.23
7.11.117.68

avast!
Win32:Dropper-gen [Drp]
2014.9-160111

AVG
Win32/DH
2017.0.2867

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.16111

Bitdefender
Gen:Variant.Kazy.48288
1.0.20.55

Emsisoft Anti-Malware
Gen:Variant.Kazy.48288
8.16.01.11.12

ESET NOD32
Win32/VB.QGW (variant)
10.9121

Fortinet FortiGate
W32/VB.APRV!tr
1/11/2016

F-Secure
Gen:Variant.Kazy.48288
11.2016-11-01_2

G Data
Gen:Variant.Kazy.48288
16.1.22

IKARUS anti.virus
Trojan.Win32.Cossta
t3scan.2.2.29

Kaspersky
Trojan.Win32.Agent
14.0.0.832

McAfee
Artemis!5B345F429517
5600.6523

MicroWorld eScan
Gen:Variant.Kazy.48288
17.0.0.33

Norman
Obfuscated.N2!genr
11.20160111

SUPERAntiSpyware
Trojan.Agent/Gen-FalComp
9392

Trend Micro House Call
TROJ_GEN.R021B01L113
7.2.11

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
23940

File size:
232 KB (237,568 bytes)

Product version:
1.00

Original file name:
videos_do_youtube_engraçados_005441.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\videos_do_youtube_engraçados_005441.exe

File PE Metadata
Compilation timestamp:
11/14/2013 11:37:33 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:/ohYkQr0jeLwJr95lJo6+tdfIyOiJNhYkQr0jeLwJr95Z:0YQqLwhHlW6+Lf+idYQqLwhH

Entry address:
0x1878

Entry point:
68, 5C, AB, 41, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, F2, 6C, DE, 25, E3, 85, 48, 45, 9E, 62, 2F, 2D, 44, 1A, C2, D2, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 50, 72, 6F, 6A, 65, 63, 74, 31, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 04, DE, 8E, EA, 6B, 74, 63, 97, 40, 83, 0E, 45, AB, D5, 91, 98, FC, 85, 99, 59, FE, 92, 03, F3, 45, AA, 8F, 0D, 6C, 9A, 23, 7E, 6B, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
132 KB (135,168 bytes)

The file videos_do_youtube_engraçados_005441.exe has been seen being distributed by the following URL.

Remove videos_do_youtube_engraçados_005441.exe - Powered by Reason Core Security