whatsapp plus 1.1.vmp.exe

Asdq

Sony

The application whatsapp plus 1.1.vmp.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from docs.google.com.
Publisher:
Sony

Product:
Asdq

Version:
1.00

MD5:
03c97991ae3407e491611a1f5d110f34

SHA-1:
e9c9e510b20fb4c76c150cba63a4f2b47a85f1ab

SHA-256:
9d68cf565203582fc2f844cbbc5d95d36987d81271353e632938da1719d77ee3

Scanner detections:
9 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 7:42:38 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Black.Gen2
8.3.2.2

AVG
Win32/Blacked
2017.0.2850

Baidu Antivirus
PUA.Win32.VMProtect
4.0.3.16129

ESET NOD32
Win32/Packed.VMProtect.ABD (variant)
10.12241

Microsoft Security Essentials
TrojanDownloader:Win32/Banload.BAX
1.1.12002.0

Qihoo 360 Security
HEUR/QVM16.0.Malware.Gen
1.0.0.1015

Quick Heal
(Suspicious) - DNAScan
1.16.14.00

Sophos
Mal/VMProtBad-A
4.98

Vba32 AntiVirus
TScope.Trojan.VB
3.12.26.4

File size:
1020 KB (1,044,480 bytes)

Product version:
1.00

Original file name:
Project1.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\whatsapp plus 1.1.vmp.exe

File PE Metadata
Compilation timestamp:
8/5/2015 2:32:05 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:69P3iUH7Skvzn4ulVWtmEqd1ZCoCE4Tav+U6r0:gxvzn42Vchqd1wE4ae0

Entry address:
0x1022E4

Entry point:
68, CA, 0F, 2F, 72, E9, 7E, 2A, 00, 00, 8B, 6C, 24, 04, C7, 44, 24, 04, 42, FF, 47, 82, 60, FF, 74, 24, 28, C2, 30, 00, 87, 34, 24, 66, 89, FE, 66, D3, CE, 89, FE, 0F, A3, FC, F5, 52, 29, C6, 9C, 66, C7, 04, 24, 8B, F8, 60, E8, CC, FA, FF, FF, 84, E4, 68, 1E, B1, C8, EE, 8D, 64, 24, 30, 0F, 85, 81, 04, 00, 00, E8, B5, 08, 00, 00, 4C, EA, A6, 40, 28, CA, CE, E3, F3, 5B, 2F, 01, 56, B2, 92, 34, 5D, 42, 1E, 80, E1, BE, AE, 10, 71, 8E, 9B, B8, 80, DC, 39, 6A, 57, 3B, 2A, 6C, 5C, 0E, C8, 25, A8, 22, C6, 8A, 6C...
 
[+]

Code size:
72 KB (73,728 bytes)

The file whatsapp plus 1.1.vmp.exe has been seen being distributed by the following URL.

Remove whatsapp plus 1.1.vmp.exe - Powered by Reason Core Security