lanspy_setup.exe

LanTricks.com

The executable lanspy_setup.exe, “LanSpy Setup ” has been detected as malware by 9 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from lantricks.com.
Publisher:
LanTricks.com

Description:
LanSpy Setup

MD5:
64b2cffa6700c416c1f9d53abbbb505f

SHA-1:
7f8c5917620d5876d6d34c048be017813595c2f9

SHA-256:
45b98459924f27d4df6bf64a56d3b202efe4b9a994900b5bdcf8dd83c12f41a2

Scanner detections:
9 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
6/21/2025 10:04:53 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160216-0

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.215.1919.0

Norman
Win32.Sality.3
29.02.2016 03:11:57

File size:
1.2 MB (1,213,356 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\lanspy_setup.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:PJ/2ILT730VhgI03HHl1HkTV5waCo8RBhCfajItclwg3QjfCu8u6LaF/X3YCnoLH:YIL/Ei1Hcja9cmCggZ6+vxoLa6

Entry address:
0x9408

Entry point:
84, CF, F3, 0F, BF, F1, F6, C1, 6F, FE, C8, F7, C5, 20, EC, EF, CD, 20, E4, F2, 34, 2D, 84, C9, 35, 94, 59, 47, A1, 8A, DC, E8, 0E, 00, 00, 00, 0F, BF, EB, 0F, AF, CA, 80, F5, 32, 0F, AF, D8, 3B, C1, 2D, 91, 8F, 4C, 01, 41, FF, C9, C7, C7, E2, 7A, A4, 3F, 0F, BF, C7, F7, C6, 2C, 5E, AA, F6, 81, EE, 40, 85, 00, 00, 8D, 15, D0, D5, 2D, 01, 69, D6, 75, EE, 25, 9A, 81, EE, DC, 0B, 00, 00, 59, 39, D2, BA, 12, 75, D5, 96, F2, 1C, 97, C7, C2, E7, 75, 3F, 1E, 0F, BE, C3, 77, 06, 69, C6, 1B, 68, 1E, 9D, 81, C1, EE...
 
[+]

Code size:
35 KB (35,840 bytes)

The file lanspy_setup.exe has been seen being distributed by the following URL.

Remove lanspy_setup.exe - Powered by Reason Core Security