youtube_downloader-_mp3__hd_video_download.exe

Microsoft Windows

The executable youtube_downloader-_mp3__hd_video_download.exe has been detected as malware by 28 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dc488.4shared.com.
Publisher:
Microsoft Windows

Version:
9.65.8.2

MD5:
a69286b98f9b2d785009c9893e6f81f5

SHA-1:
632ed4de2eb1a74e40a0d946af51949c71eb1cc8

SHA-256:
6d1b53872fcc387102d7286a2ef9b7f6bc6e94966dc58912bfd1cce0012b2696

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/24/2024 8:07:44 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.13860
550

Agnitum Outpost
Trojan.PWS.Qhost
7.1.1

Avira AntiVirus
TR/Strictor.13860.33
7.11.213.138

avast!
Win32:Downloader-UGZ [Trj]
2014.9-150804

Baidu Antivirus
Trojan.Win32.Banker
4.0.3.1584

Bitdefender
Gen:Variant.Strictor.13860
1.0.20.1080

Clam AntiVirus
Win.Trojan.Strictor-44
0.98/21511

Comodo Security
UnclassifiedMalware
21297

Dr.Web
Trojan.Siggen6.31393
9.0.1.0216

Emsisoft Anti-Malware
Gen:Variant.Strictor.13860
8.15.08.04.01

Fortinet FortiGate
W32/Qhost.ZO!tr
8/4/2015

F-Secure
Gen:Variant.Strictor.13860
11.2015-04-08_3

G Data
Gen:Variant.Strictor.13860
15.8.25

IKARUS anti.virus
Trojan.Win32.Spy
t3scan.1.8.6.0

Kaspersky
Trojan-Banker.Win32.Qhost
14.0.0.1635

Malwarebytes
Spyware.Password
v2015.08.04.01

McAfee
Artemis!A69286B98F9B
5600.6684

MicroWorld eScan
Gen:Variant.Strictor.13860
16.0.0.648

NANO AntiVirus
Trojan.Win32.Qhost.daalyi
0.30.0.296

Norman
Troj_Generic.PPLDO
11.20150804

nProtect
Trojan/W32.Agent.1183598
15.03.04.01

Panda Antivirus
Trj/CI.A
15.08.04.01

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Rising Antivirus
PE:Trojan.Win32.Generic.15205BE1!354442209
23.00.65.15802

Sophos
Mal/Generic-S
4.98

Vba32 AntiVirus
TrojanBanker.Qhost
3.12.26.3

VIPRE Antivirus
Worm.Win32.Palevo.kav
38134

Zillya! Antivirus
Trojan.Qhost.Win32.10632
2.0.0.2088

File size:
1.1 MB (1,183,598 bytes)

Copyright:
Copyright ©2009-2012

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\youtube_downloader-_mp3__hd_video_download.exe

File PE Metadata
Compilation timestamp:
1/25/2011 9:42:57 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:nxS2bOH3ZbnJPA/uioRMtb5LbV8c2ggtD701s:nguC8OcFgtc1s

Entry address:
0x4CF44

Entry point:
55, 8B, EC, 6A, FF, 68, 50, E5, 44, 00, 68, CA, D0, 44, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 50, E2, 44, 00, 59, 83, 0D, 44, 4C, 45, 00, FF, 83, 0D, 48, 4C, 45, 00, FF, FF, 15, 4C, E2, 44, 00, 8B, 0D, 3C, 4C, 45, 00, 89, 08, FF, 15, 48, E2, 44, 00, 8B, 0D, 38, 4C, 45, 00, 89, 08, A1, 44, E2, 44, 00, 8B, 00, A3, 40, 4C, 45, 00, E8, 16, 01, 00, 00, 39, 1D, D0, 43, 45, 00, 75, 0C, 68, C6, D0, 44, 00, FF, 15, 3C, E2...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
308 KB (315,392 bytes)

The file youtube_downloader-_mp3__hd_video_download.exe has been seen being distributed by the following URL.