e3c20fd24695d7bff96776967230b7c0.pe

The file e3c20fd24695d7bff96776967230b7c0.pe has been detected as malware by 42 anti-virus scanners.
MD5:
e3c20fd24695d7bff96776967230b7c0

SHA-1:
c5e874e326ced5f3b0993cbacd4b4fdea5a17c6c

SHA-256:
6ea2150026ca1c3315dc7f54b1d5605a01d02e722aff048815b4e4519e6ce4e9

Scanner detections:
42 / 68

Status:
Malware

Analysis date:
4/19/2024 2:06:05 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Generic.Malware.SYBdg.76C7DE29
658

Agnitum Outpost
Worm.AutoRun
7.1.1

AhnLab V3 Security
Trojan/Win32.Swisyn
2015.03.23

Avira AntiVirus
TR/Patched.Ren.Gen
7.11.219.26

avast!
Win32:Malware-gen
2014.9-150418

AVG
Worm/Generic
2016.0.3136

Baidu Antivirus
Trojan.Win32.Swisyn
4.0.3.15418

Bitdefender
Dropped:Generic.Malware.SYBdg.76C7DE29
1.0.20.540

Bkav FE
W32.LRExplorerMWHSL.Trojan
1.3.0.4562

Clam AntiVirus
Trojan.Agent-173696
0.98/21511

Comodo Security
UnclassifiedMalware
21494

Dr.Web
Trojan.Siggen3.34436
9.0.1.0108

Emsisoft Anti-Malware
Dropped:Generic.Malware.SYBdg.76C7DE29
8.15.04.18.08

ESET NOD32
Win32/AutoRun.IRCBot.FL (variant)
9.11358

Fortinet FortiGate
W32/IRCBot.C!worm
4/18/2015

F-Prot
W32/Downloader-Web-based!Maximu
v6.4.7.1.166

F-Secure
Dropped:Generic.Malware.SYBdg.76C7DE29
11.2015-18-04_7

G Data
Dropped:Generic.Malware.SYBdg.76C7DE29
15.4.25

herdProtect (fuzzy)
2015.7.19.21

IKARUS anti.virus
Gen.Win32.IRC-Backdoor
t3scan.1.8.6.0

K7 AntiVirus
Virus
13.174.10396

Kaspersky
Trojan.Win32.Swisyn
14.0.0.2173

McAfee
W32/IRCbot.worm.gen.az
5600.6792

Microsoft Security Essentials
Worm:Win32/Pushbot.gen!F
1.1.11400.0

MicroWorld eScan
Gen:Win32.IRC-Backdoor.kmZ@aaaQSJo
16.0.0.324

NANO AntiVirus
Trojan.Win32.Siggen3.btxcfz
0.28.0.56582

Norman
Malware
11.20150418

nProtect
Trojan/W32.Swisyn.171525.B
13.12.03.01

Panda Antivirus
Trj/Sinowal.WEA
15.04.18.08

Qihoo 360 Security
HEUR/QVM18.1.Malware.Gen
1.0.0.1015

Quick Heal
Win32.Packed.Katusha.n.3
4.15.12.00

Reason Heuristics
Threat.Win.Reputation.IMP
15.4.20.1

Rising Antivirus
PE:Backdoor.Win32.Fednu.rk!1075352618
23.00.65.15416

Sophos
Mal/Generic-S
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Pushbot
9928

Total Defense
Win32/Pushbot.HJQZIDC
37.0.11507

Trend Micro House Call
TSPY_SDBOT_DD300534.UVPA
7.2.108

Trend Micro
TSPY_SDBOT_DD300534.UVPA
10.465.18

Vba32 AntiVirus
BScope.Trojan.Jorik.IRCbot
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
38656

ViRobot
Trojan.Win32.A.Swisyn.89088[h]
2014.3.20.0

Zillya! Antivirus
Worm.AutoRun.Win32.79844
2.0.0.2110

File size:
475.5 KB (486,912 bytes)

Common path:
C:\users\{user}\downloads\e3c20fd24695d7bff96776967230b7c0.pe

File PE Metadata
Compilation timestamp:
7/18/1995 6:03:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:i/atXTAPMMX3wQqr2CahcopYDpEoueyc4MktJolG:ttjjiqr2VhhYDpzwcZkqG

Entry address:
0x89A9

Entry point:
55, 8B, EC, 6A, FF, 68, 40, 14, 41, 00, 68, 20, D5, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 44, 11, 41, 00, 33, D2, 8A, D4, 89, 15, 48, DB, 41, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 44, DB, 41, 00, C1, E1, 08, 03, CA, 89, 0D, 40, DB, 41, 00, C1, E8, 10, A3, 3C, DB, 41, 00, 33, F6, 56, E8, 40, 28, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, 52, 41, 00, 00, FF, 15, 40, 11, 41, 00, A3, 64, F1, 41, 00, E8...
 
[+]

Entropy:
2.6297

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
62 KB (63,488 bytes)

Remove e3c20fd24695d7bff96776967230b7c0.pe - Powered by Reason Core Security