╟┐╔·qq532419256.exe

The application ╟┐╔·qq532419256.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from doc-08-2s-docs.googleusercontent.com.
MD5:
f8d36cd2340d93f298b8047382fd453e

SHA-1:
ecd5c34491dc394a958f023bb8bdca0b9537aa86

SHA-256:
fac7d227cfcec686fa8b258192e4d194eb41ceab8103789ab85fd93fcac8943e

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 11:25:23 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.RvW@Jmsbmrai
240

Arcabit
Trojan.Heur.ECB2FE
1.0.0.669

avast!
Win32:Malware-gen
2014.9-160609

AVG
Win32/Heur
2017.0.2718

Bitdefender
Gen:Trojan.Heur.RvW@Jmsbmrai
1.0.20.805

Bkav FE
HW32.Packed
1.3.0.7744

Comodo Security
TrojWare.Win32.Amtar.KNB
24825

Emsisoft Anti-Malware
Gen:Trojan.Heur.RvW@Jmsbmrai
8.16.06.09.08

ESET NOD32
Win32/Packed.NoobyProtect.G suspicious (variant)
10.13349

Fortinet FortiGate
Malware_Generic.P0
6/9/2016

F-Secure
Gen:Trojan.Heur.RvW@Jmsbmrai
11.2016-09-06_5

G Data
Gen:Trojan.Heur.RvW@Jmsbmrai
16.6.25

IKARUS anti.virus
PUA.NoobyProtect
t3scan.2.0.9.0

MicroWorld eScan
Gen:Trojan.Heur.RvW@Jmsbmrai
17.0.0.483

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48 [F]
23.00.65.16607

VIPRE Antivirus
Trojan.Win32.Generic
48708

File size:
1.7 MB (1,753,088 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\╟┐╔·qq532419256.exe

File PE Metadata
Compilation timestamp:
3/31/2016 5:44:27 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
49152:k2xdWYUquw3Mn25FUsJWs2eVkpCZQ2pX3pm:RWYUqP3y25SsJx1VtV3pm

Entry address:
0x277ED4

Entry point:
E8, 1F, 00, 00, 00, 53, 61, 66, 65, 6E, 67, 69, 6E, 65, 20, 4E, 65, 74, 4C, 69, 63, 65, 6E, 73, 6F, 72, 20, 76, 32, 2E, 33, 2E, 38, 2E, 30, 00, 9C, F8, FD, E8, 45, 00, 00, 00, B0, 36, A4, C3, 3E, DC, A2, 2B, BB, DE, 2D, AC, CE, 59, B8, 9B, F2, ED, 81, 04, 24, AC, FA, FF, FF, E8, 5A, BE, EB, FF, E9, 2D, FF, FF, FF, F5, 66, 8F, 04, 24, 8D, 64, 24, 02, FC, E8, 3E, 00, 00, 00, FA, 7E, EC, 8B, 86, 01, CF, 53, C3, A6, 55, B5, 57, D4, 4A, 2D, DC, 32, C1, 89, 1C, 24, EB, D9, F9, 8D, 64, 24, 02, 55, 8D, A9, BE, A2...
 
[+]

Entropy:
7.8460  (probably packed)

The file ╟┐╔·qq532419256.exe has been seen being distributed by the following URL.

Remove ╟┐╔·qq532419256.exe - Powered by Reason Core Security