5acc.tmp

The file 5acc.tmp has been detected as malware by 8 anti-virus scanners. The file has been seen being downloaded from ln.syncusercontent.com.
MD5:
e269789983a9cdd45ddd14c504ae63b6

SHA-1:
3912c5d19b0589b468ea6d0af9dce4878ab3778a

SHA-256:
76e248c5b1867e2dd02b9063d2a298fdb2ee81410f92eba62edaada3f248f4e3

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
12/26/2024 2:09:18 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.Black.Gen2!c
2.1.4+

Avira AntiVirus
TR/Black.Gen2
8.3.3.4

AVG
Win32/Blacked
2017.0.2766

Bkav FE
HW32.Packed
1.3.0.7744

ESET NOD32
Win32/Packed.VMProtect.ABO (variant)
10.13372

Qihoo 360 Security
HEUR/QVM36.0.0000.Malware.Gen
1.0.0.1120

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16420

Sophos
Mal/VMProtBad-A
4.98

File size:
392.5 KB (401,920 bytes)

Common path:
C:\users\{user}\downloads\5acc.tmp

File PE Metadata
Compilation timestamp:
4/22/2016 6:30:42 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
6144:J+Cr+cFj/Yxo6kuNCfLxC2rUISYosvIG/9fdhlRyJs09WdAlDwf/irYRTkFKhxj:J+I+Aki6xNix+FYlgqfhRtdePekFU

Entry address:
0x1405B0

Entry point:
60, C7, 44, 24, 1C, F5, 51, AC, 9D, 66, C7, 04, 24, 22, 1B, C7, 44, 24, 18, BF, 07, 48, 91, 60, 8D, 64, 24, 38, E9, 63, 6F, 03, 00, F5, 0A, 99, BB, 9E, 80, F0, 5B, 89, 4A, 07, F1, A7, F0, 6F, 12, 3C, 9E, D6, 5E, D5, 30, EF, 09, 2D, BD, 30, FB, 62, 5C, DF, A2, F9, 9C, E6, 86, 10, E8, D0, 35, B0, E0, 72, 3B, 3F, 1E, 06, F4, 40, B2, 8B, D2, E0, 5B, 11, E4, 21, 55, 9C, 82, C6, 6C, E7, 22, 74, BD, EE, 10, 63, 35, FE, D9, AB, 3E, A5, 30, 43, A5, 3B, 2E, DE, 2F, A3, 1D, 15, F1, 51, 17, 31, AB, 37, AF, EE, 0C, 2B...
 
[+]

Entropy:
7.5655

Code size:
100.5 KB (102,912 bytes)

The file 5acc.tmp has been seen being distributed by the following URL.

Remove 5acc.tmp - Powered by Reason Core Security