wael.exe

The executable wael.exe has been detected as malware by 13 anti-virus scanners.
MD5:
a85833553407a36f4fd5f9b8867e3a97

SHA-1:
9ef6ebc48464ccd0dab0bb0f5f09fabea2a69f58

SHA-256:
20eaa2e9b6f76ee92b3cdaa1901956772d68f5717be2a1e116808387b71fae17

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
5/7/2024 6:17:20 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Patched2_c
2016.0.3001

Bkav FE
W32.HfsAutoB
1.3.0.4613

F-Prot
W32/Virtumonde!Generic
4.6.5.141

F-Secure
Suspicious:W32/Malware.9ef6ebc484!Online
5.14.151

herdProtect (fuzzy)
2015.10.27.0

IKARUS anti.virus
Trojan.Patched2
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.2017055

McAfee
Trojan.Artemis!A85833553407
18.0.204.0

NANO AntiVirus
Trojan.Win32.Virtumonde.dmpwsh
0.30.24.3283

Norman
Suspicious_Gen2.RYCIZ
11.20151027

Rising Antivirus
PE:Trojan.Crypt!6.A33
23.00.65.15828

VIPRE Antivirus
Trojan.Win32.Generic
24850

ViRobot
Trojan.Win32.A.NSAnti.3088896.A
2011.4.7.4223

File size:
2.9 MB (3,088,896 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
9/10/2012 6:15:03 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.50

CTPH (ssdeep):
24576:JtrSZlat4EQKhSFI1NvWM7axC7tpiCt90HhPuq1ihVCF2M1qrui6EbPjeW11Rdab:JSrMXypP5nsfbHrnYk3DL0LJkHDqFw

Entry address:
0x267BF0

Entry point:
55, 89, E5, 53, 83, EC, 48, 55, B8, FF, FF, FF, FF, 50, 50, 68, 40, 7E, 67, 00, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 83, EC, 20, 83, E4, E0, 68, 88, E6, 6D, 00, E8, EE, 00, 00, 00, 59, E8, 98, B5, 00, 00, E8, 23, 26, 00, 00, 85, C0, 74, 0F, 68, E0, A0, 66, 00, E8, B5, BC, FF, FF, 59, 85, C0, 74, 08, 6A, FF, E8, D9, BC, FF, FF, 59, E8, 43, 04, 01, 00, E8, 3E, 06, 01, 00, FF, 15, 68, 24, 6F, 00, 89, C3, EB, 18, 8D, 44, 20, 00, 3C, 22, 75, 0F, 43, 8A, 03, 84, C0, 74, 04, 3C, 22, 75, F5, 3C...
 
[+]

Entropy:
6.4966

Packer / compiler:
REALbasic

Code size:
2.5 MB (2,609,152 bytes)

Remove wael.exe - Powered by Reason Core Security