sx2a8687.exe

The executable sx2a8687.exe has been detected as malware by 35 anti-virus scanners. According to AVG, this software downloads additional adware offers during setup.
MD5:
b7b73d83babddfe9223af9975ba4ba27

SHA-1:
befbeabf8ba3ac4d3d13db01cd7ee7c926f40f7a

SHA-256:
a3418d75525305e22572bea08626b942e7801f8396ffd6498f202017c319e1e8

Scanner detections:
35 / 68

Status:
Malware

Analysis date:
4/28/2024 6:51:09 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Ransom.BIV
-40

AegisLab AV Signature
Troj.W32.Generic!c
2.1.4+

AhnLab V3 Security
Trojan/Win32.Cerber.R194440
3.8.3.16

Avira AntiVirus
TR/Crypt.ZPACK.sfenc
8.3.3.4

Arcabit
Trojan.Ransom.BIV
1.0.0.795

avast!
Win32:Trojan-gen
2014.9-170316

AVG
Downloader.Generic14
2018.0.2438

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.17316

Bitdefender
Trojan.Ransom.BIV
1.0.20.375

Dr.Web
Trojan.Encoder.7458
9.0.1.075

Emsisoft Anti-Malware
Trojan.Ransom.BIV
8.17.03.16.03

ESET NOD32
Win32/Kryptik.FNMW (variant)
11.14926

Fortinet FortiGate
W32/Generic.AP.583CC!tr
3/16/2017

F-Prot
W32/S-9ba02768
v6.4.7.1.166

F-Secure
Trojan.Ransom.BIV
11.2017-16-03_5

G Data
Trojan.Ransom.BIV
17.3.25

IKARUS anti.virus
Trojan.Win32.Crypt
0.1.3.4

K7 AntiVirus
Trojan
13.250.22376

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-1316

Malwarebytes
Ransom.Cerber
v2017.03.16.03

McAfee
GenericR-JEQ!B7B73D83BABD
5600.6094

Microsoft Security Essentials
Trojan:Win32/Dynamer!ac
1.1.13407.0

MicroWorld eScan
Trojan.Ransom.BIV
18.0.0.225

NANO AntiVirus
Trojan.Win32.Kryptik.eljfzx
1.0.70.15039

Panda Antivirus
Trj/Genetic.gen
17.03.16.03

Qihoo 360 Security
HEUR/QVM20.1.CF08.Malware.Gen
1.0.0.1120

Quick Heal
Ransom.Exxroute.A3
3.17.14.00

Rising Antivirus
Trojan.Generic!8.C3-Q2gL49W69rB (cloud)
23.00.65.17314

Sophos
Mal/Elenoocka-E
4.98

SUPERAntiSpyware
Ransom.Cerber/Variant
8533

Trend Micro House Call
Ransom_CERBER.F117BA
7.2.75

Trend Micro
Ransom_CERBER.F117BA
10.465.16

VIPRE Antivirus
Trojan.Win32.Generic
55932

ViRobot
Trojan.Win32.Cerber.248181[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Kryptik.Win32.1040140
2.0.0.3204

File size:
242.4 KB (248,181 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\sx2a8687.exe

File PE Metadata
Compilation timestamp:
10/5/2014 11:03:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.1

Entry address:
0x73D5

Entry point:
6A, 00, 01, 2C, 24, 89, E5, B9, 3B, 00, 00, 00, BA, 1D, 00, 00, 00, B8, 31, 00, 00, 00, 8D, 65, C8, 66, 81, FD, 00, FE, 0F, 87, FF, D7, FF, FF, 68, B8, 9B, 40, 00, B8, 00, 00, 00, 00, 50, B8, 00, 00, 10, 00, 50, E8, B4, FB, FF, FF, 85, C0, 0F, 85, 18, C5, FF, FF, 68, B8, 9B, 40, 00, B8, 00, 00, 00, 00, 50, B8, 00, 00, 10, 00, 50, E8, 96, FB, FF, FF, 85, C0, 0F, 85, FA, C4, FF, FF, B8, 08, 00, 00, 00, 50, 68, 97, 9B, 40, 00, 68, 8C, 9B, 40, 00, E8, 29, D5, FF, FF, 85, C0, 0F, 85, DD, C4, FF, FF, 8D, 1D, C7...
 
[+]

Entropy:
7.7868  (probably packed)

Code size:
29.5 KB (30,208 bytes)

Remove sx2a8687.exe - Powered by Reason Core Security