watch_video_stream_now.avi.exe

The executable watch_video_stream_now.avi.exe has been detected as malware by 23 anti-virus scanners. The file has been seen being downloaded from catalog.chaosium.com.
MD5:
7c031b694f638bee91019fc43632d2cb

SHA-1:
99560172707513be51c133a668e82883c5fee609

SHA-256:
bdb10e49f24c0aff324e5274f6d6cd402f7d3fe98ac8e9aaba55727cddb627ac

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
4/26/2024 9:11:54 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1635445
218

AhnLab V3 Security
Spyware/Win32.Zbot
16.06.30

Avira AntiVirus
TR/Crypt.Xpack.36838
7.11.142.28

avast!
Win32:Malware-gen
2014.9-160630

AVG
Inject2
2017.0.2696

Bitdefender
Trojan.GenericKD.1635445
1.0.20.910

Dr.Web
Trojan.PWS.Panda.5841
9.0.1.0182

Emsisoft Anti-Malware
Trojan.GenericKD.1635445
8.16.06.30.10

ESET NOD32
Win32/Injector.BBLH (variant)
10.9652

Fortinet FortiGate
W32/Mokes.BBIT!tr.bdr
6/30/2016

F-Secure
Trojan.GenericKD.1635445
11.2016-30-06_5

G Data
Trojan.GenericKD.1635445
16.6.24

K7 AntiVirus
Trojan
13.176.11696

Kaspersky
Backdoor.Win32.Mokes
14.0.0.-25

Malwarebytes
Spyware.Zbot
v2016.06.30.10

McAfee
Artemis!7C031B694F63
5600.6352

Microsoft Security Essentials
TrojanDownloader:Win32/Dofoil.R
1.10401

MicroWorld eScan
Trojan.GenericKD.1635445
17.0.0.546

nProtect
Trojan.GenericKD.1635445
14.04.08.01

Panda Antivirus
Trj/Zbot.M
16.06.30.10

Qihoo 360 Security
Win32/Backdoor.574
1.0.0.1015

Sophos
Mal/Zbot-QJ
4.98

Trend Micro House Call
TROJ_GEN.F47V0407
7.2.182

File size:
69.9 KB (71,528 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\watch_video_stream_now.avi.exe

File PE Metadata
Compilation timestamp:
3/27/2014 10:57:58 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
768:GXAYv8rgh9S8ycRGi0zm3ZSeyNQXdKHo/MFYNHfvfCniITmxygqV/BfxJB4:GKAycESpj8ON/vjOmx7W1xc

Entry address:
0x2CD0

Entry point:
55, 8B, EC, 6A, FF, 68, 70, 47, 40, 00, 68, 56, 2E, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, E9, B2, 05, 00, 00, CC, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 34, 42, 40, 00, 59, 83, 0D, 30, 62, 40, 00, FF, 83, 0D, 34, 62, 40, 00, FF, FF, 15, 30, 42, 40, 00, 8B, 0D, 24, 62, 40, 00, 89, 08, FF, 15, 2C, 42, 40, 00, 8B, 0D, 20, 62, 40, 00, 89, 08, A1, 28, 42, 40, 00, 8B, 00, A3, 2C, 62, 40, 00, E8, 16, 01, 00, 00, 39, 1D, 40, 60, 40, 00, 75, 0C, E9, 48, 04, 00, 00, FF, 15, 24, 42...
 
[+]

Entropy:
6.4030

Developed / compiled with:
Microsoft Visual C++

Code size:
12 KB (12,288 bytes)

The file watch_video_stream_now.avi.exe has been seen being distributed by the following URL.

Remove watch_video_stream_now.avi.exe - Powered by Reason Core Security