x642.wm4ztdw.fwv5.exe

The executable x642.wm4ztdw.fwv5.exe has been detected as malware by 30 anti-virus scanners.
MD5:
ddbb77cfd8fd159a79a857fe9682ef01

SHA-1:
b71f3d10e8b5e27e12548379f6c9c2d418be5c19

SHA-256:
0655e04b061db46d1307a678f2b0ecb85e97cfaec2431314d7405b0204414fe7

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
4/28/2024 3:06:38 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.226255
-40

AegisLab AV Signature
Troj.Ransom.W32.Zerber!c
2.1.4+

AhnLab V3 Security
Trojan/Win32.Cerber.R196417
3.8.3.16

Avira AntiVirus
TR/Crypt.ZPACK.cwxqr
8.3.3.4

Arcabit
Trojan.Zusy.D373CF
1.0.0.798

avast!
Win32:Trojan-gen
2014.9-170315

AVG
FileCryptor
2018.0.2438

Baidu Antivirus
Win32.Trojan.WisdomEyes.16070401.9500
4.0.3.17315

Bitdefender
Gen:Variant.Zusy.226255
1.0.20.370

Dr.Web
Trojan.Inject2.50423
9.0.1.074

Emsisoft Anti-Malware
Gen:Variant.Zusy.226255
8.17.03.15.11

ESET NOD32
Win32/Filecoder.Cerber
11.15083

Fortinet FortiGate
W32/Kryptik.FPKE!tr
3/15/2017

F-Secure
Gen:Variant.Zusy.226255
11.2017-15-03_4

G Data
Gen:Variant.Zusy.226255
17.3.A:25.11170B:25.9077

IKARUS anti.virus
Trojan.Win32.Filecoder
0.2.1.2

K7 AntiVirus
Trojan
13.10.5.22703

Kaspersky
Trojan-Ransom.Win32.Zerber
14.0.0.-1315

McAfee
Ransomware-FLBK!DDBB77CFD8FD
5600.6094

Microsoft Security Essentials
Ransom:Win32/Cerber
1.1.13504.0

MicroWorld eScan
Gen:Variant.Zusy.226255
18.0.0.222

NANO AntiVirus
Trojan.Win32.Zerber.emfzdz
1.0.70.15657

nProtect
Ransom/W32.Cerber.426410
17.03.14.01

Panda Antivirus
Trj/GdSda.A
17.03.15.11

Qihoo 360 Security
Win32/Trojan.663
1.0.0.1120

Rising Antivirus
Malware.Generic.5!tfe (cloud:w2u5oxKMhj)
23.00.65.17313

Sophos
Mal/Generic-S
4.98

Trend Micro
Mal_Cerber-21
10.465.15

VIPRE Antivirus
Trojan.Win32.Generic
56630

ViRobot
Trojan.Win32.Z.Zerber.426410.W[h]
2014.3.20.0

File size:
416.4 KB (426,410 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\x642.wm4ztdw.fwv5.exe

File PE Metadata
Compilation timestamp:
3/8/2017 12:39:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

Entry address:
0x9BB0

Entry point:
55, 8B, EC, 6A, FF, 68, 68, AC, 42, 00, 68, 9C, A2, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, C4, 90, 53, 56, 57, 89, 65, E8, B8, 94, 00, 00, 00, E8, 00, EF, 00, 00, 89, 65, 84, 89, 65, E8, 8B, 45, 84, 89, 45, 90, 8B, 4D, 90, C7, 01, 94, 00, 00, 00, 8B, 55, 90, 52, FF, 15, 10, A0, 42, 00, 8B, 45, 90, 8B, 48, 10, 89, 0D, AC, 09, 47, 00, 8B, 55, 90, 8B, 42, 04, A3, B8, 09, 47, 00, 8B, 4D, 90, 8B, 51, 08, 89, 15, BC, 09, 47, 00, 8B, 45, 90, 8B, 48, 0C, 81, E1, FF, 7F, 00, 00, 89, 0D...
 
[+]

Entropy:
7.1719

Developed / compiled with:
Microsoft Visual C++

Code size:
160 KB (163,840 bytes)

Remove x642.wm4ztdw.fwv5.exe - Powered by Reason Core Security