6070aff80.exe

The application 6070aff80.exe has been detected as a potentially unwanted program by 26 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.dfogol.info and multiple other hosts.
MD5:
69aecca2e3c2a43b3cf64710f29b5f65

SHA-1:
67f81b7b48a2eabec8d18b0bd6b4e4000598bf76

SHA-256:
649d9175e5f6d3caae743e8ee2ce3c28718d1d8af09eee0d651a2a6c969774ee

Scanner detections:
26 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 9:40:55 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2198800
690

Agnitum Outpost
PUA.ExtCrome
7.1.1

AhnLab V3 Security
Adware/Win32.Vonteera
2015.03.12

Avira AntiVirus
Adware/Vonteera.3808256
7.11.216.120

avast!
Win32:Dropper-gen [Drp]
2014.9-150316

AVG
Generic6
2016.0.3168

Baidu Antivirus
Adware.Win32.Vonteera
4.0.3.15316

Bitdefender
Trojan.GenericKD.2198800
1.0.20.375

Bkav FE
W32.HfsAutoB
1.3.0.6379

Comodo Security
ApplicUnwnt
21382

Emsisoft Anti-Malware
Trojan.GenericKD.2198800
8.15.03.16.12

ESET NOD32
Win32/AdWare.Vonteera (variant)
9.11309

Fortinet FortiGate
W32/Vonteera.K
3/16/2015

F-Secure
Trojan.GenericKD.2198800
11.2015-16-03_2

G Data
Trojan.GenericKD.2198800
15.3.25

K7 AntiVirus
Trojan
13.200.15240

Kaspersky
not-a-virus:AdWare.Win32.ExtCrome
14.0.0.2337

McAfee
Artemis!69AECCA2E3C2
5600.6824

MicroWorld eScan
Trojan.GenericKD.2198800
16.0.0.225

NANO AntiVirus
Riskware.Win32.ExtCrome.doswaf
0.30.0.296

nProtect
Trojan.GenericKD.2198800
15.03.12.01

Qihoo 360 Security
HEUR/QVM19.1.Malware.Gen
1.0.0.1015

Sophos
Mal/EncPk-DW
4.98

Trend Micro House Call
TROJ_GEN.R02KC0ECB15
7.2.75

VIPRE Antivirus
Trojan.Win32.Generic
38358

ViRobot
Adware.Vonteera.3808256[h]
2014.3.20.0

File size:
3.6 MB (3,808,256 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\i7kfnu1m\6070aff80.exe

File PE Metadata
Compilation timestamp:
3/4/2015 9:54:42 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:serbxmyW08yPUwXk1NZaeXxKaqYnTYxpT:ZrdmBryPUvhKwTYxl

Entry address:
0x1637000

Entry point:
56, 50, 53, E8, 01, 00, 00, 00, CC, 58, 89, C3, 40, 2D, 00, 60, 15, 00, 2D, E0, C5, A0, 05, 05, D7, C5, A0, 05, 80, 3B, CC, 75, 19, C6, 03, 00, BB, 00, 10, 00, 00, 68, 36, 49, 11, 17, 68, 74, 3E, E7, 31, 53, 50, E8, 0A, 00, 00, 00, 83, C0, 00, 89, 44, 24, 08, 5B, 58, C3, 55, 89, E5, 50, 53, 51, 56, 8B, 75, 08, 8B, 4D, 0C, C1, E9, 02, 8B, 45, 10, 8B, 5D, 14, 85, C9, 74, 0A, 31, 06, 01, 1E, 83, C6, 04, 49, EB, F2, 5E, 59, 5B, 58, C9, C2, 10, 00, 3F, 96, 61, 24, F4, 38, FD, 65, 00, EF, 68, 1B, 1C, D4, 61, D0...
 
[+]

Entropy:
7.9884  (probably packed)

Code size:
183.5 KB (187,904 bytes)

The file 6070aff80.exe has been seen being distributed by the following 8 URLs.

http://www.dfogol.info/.../03d62a.exe

http://www.dfogol.info/.../c1bbb90e.exe

http://www.dfogol.info/.../72db5e53.exe

http://www.dfogol.info/.../7a978e7e26.exe

Remove 6070aff80.exe - Powered by Reason Core Security