dacab39366927b2ed951e09ff529abe0.pe

The file dacab39366927b2ed951e09ff529abe0.pe has been detected as malware by 21 anti-virus scanners.
MD5:
dacab39366927b2ed951e09ff529abe0

SHA-1:
6ccdd180d8a7cb779d9a642af64f44c099f91d22

SHA-256:
bbdf4efaecd510c003d1baf70c9e84cda705592bc8c1bdc8af32099568ef120a

Scanner detections:
21 / 68

Status:
Malware

Analysis date:
4/24/2024 3:23:45 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.127081
658

Agnitum Outpost
Backdoor.Agent
7.1.1

AhnLab V3 Security
Backdoor/Win32.Zegost
2015.03.15

Avira AntiVirus
TR/Crypt.ZPACK.Gen
7.11.217.78

avast!
Win32:Malware-gen
2014.9-150418

AVG
Win32/DH{gRKBE0FYZxIgJw87gRA2}
2016.0.3136

Bitdefender
Gen:Variant.Zusy.127081
1.0.20.540

Bkav FE
HW32.Packed
1.3.0.6379

Dr.Web
Trojan.DownLoader12.47296
9.0.1.0200

Emsisoft Anti-Malware
Gen:Variant.Zusy.127081
8.15.04.18.08

ESET NOD32
Win32/Farfli.DZ trojan
9.7.0.302.0

F-Secure
Gen:Variant.Zusy.127081
11.2015-18-04_7

G Data
Gen:Variant.Zusy.127081
15.4.25

Kaspersky
Backdoor.Win32.Agent
14.0.0.2173

Malwarebytes
Trojan.Email.FakeDoc
v2015.04.18.08

McAfee
Trojan.RDN/Generic BackDoor!bcn
5600.6699

Microsoft Security Essentials
Threat.Undefined
1.195.3480.0

MicroWorld eScan
Gen:Variant.Zusy.127081
16.0.0.324

Rising Antivirus
PE:Malware.FakeDOC@CV!1.9C3C
23.00.65.15416

VIPRE Antivirus
Threat.4150696
38882

File size:
158.5 KB (162,304 bytes)

Common path:
C:\users\{user}\downloads\dacab39366927b2ed951e09ff529abe0.pe

File PE Metadata
Compilation timestamp:
3/6/2015 12:50:23 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:zWKpkx1M4j1HCYEh+zHjJpzXd5TC6gEuwkVEDSzmyrBJj0Oh9O1r:zWK2nPj1iYXD7pcHn8jGn9Ot

Entry address:
0x1B00

Entry point:
55, 8B, EC, 6A, FF, 68, 20, 24, 40, 00, 68, 86, 1C, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, C0, 21, 40, 00, 59, 83, 0D, 64, A7, 44, 00, FF, 83, 0D, 68, A7, 44, 00, FF, FF, 15, C4, 21, 40, 00, 8B, 0D, 58, A7, 44, 00, 89, 08, FF, 15, C8, 21, 40, 00, 8B, 0D, 54, A7, 44, 00, 89, 08, A1, CC, 21, 40, 00, 8B, 00, A3, 60, A7, 44, 00, E8, 16, 01, 00, 00, 39, 1D, 70, 6E, 42, 00, 75, 0C, 68, 82, 1C, 40, 00, FF, 15, D0, 21...
 
[+]

Entropy:
7.6398

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
3.5 KB (3,584 bytes)

Remove dacab39366927b2ed951e09ff529abe0.pe - Powered by Reason Core Security