871061b527e938902c185f2e53f20847.exe

The application 871061b527e938902c185f2e53f20847.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dl-6.one2up.com.
MD5:
4fafcdfaafc177abb8ba641eed15e114

SHA-1:
183bc5ff4cc975d29fe3063a568d155f96f561d8

SHA-256:
e29257d9162fe017dbb213b61c9c9aa85523c398a98b19b9602789433920ad5f

Scanner detections:
11 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 1:55:26 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.FU.3uW@ambX8Rd
5813571

Avira AntiVirus
W32/Slugin.A
7.11.30.172

Clam AntiVirus
Win.Trojan.Agent-822336
0.98/21229

Emsisoft Anti-Malware
Trojan.GenericKD.2957265
10.0.0.5366

ESET NOD32
Win32/HackTool.Patcher.AD potentially unsafe application
7.0.302.0

F-Prot
W32/Agent.KFY (exact, not disinfectable)
4.6.5.141

F-Secure
Trojan.GenericKD.2957265
5.05.7110

Microsoft Security Essentials
Threat.Undefined
1.213.1881.0

Norman
Trojan.GenericKD.2957265
05.01.2016 09:44:05

Sophos
PUA 'CrackTool' (of type Hacktool)
5.22

VIPRE Antivirus
Threat.4776241
46262

File size:
7.6 MB (7,945,531 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\programs\871061b527e938902c185f2e53f20847.exe

File PE Metadata
Compilation timestamp:
11/3/2014 3:36:30 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:CsRlyP6Fx0Xz3LoYgkRd6/X2AfgY+wQ1mFI:JGTbLoY5Rs/X2PYdQ1p

Entry address:
0x1D6AC

Entry point:
E8, 65, 64, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 79, FC, FF, FF, C7, 06, 20, B2, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, C7, 01, 20, B2, 42, 00, E9, 2E, FD, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, 20, B2, 42, 00, E8, 1B, FD, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 85, C9, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 8B, 47, 04, 85, C0, 74, 47, 8D, 50, 08, 80, 3A, 00, 74, 3F, 8B, 75, 0C, 8B, 4E, 04, 3B, C1, 74, 14, 83, C1, 08...
 
[+]

Entropy:
7.9954  (probably packed)

Code size:
162 KB (165,888 bytes)

The file 871061b527e938902c185f2e53f20847.exe has been seen being distributed by the following URL.

Remove 871061b527e938902c185f2e53f20847.exe - Powered by Reason Core Security