adele - set fire to the rain - lancamento - 2012.mp3.exe

mp3

The executable adele - set fire to the rain - lancamento - 2012.mp3.exe has been detected as malware by 33 anti-virus scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from dc584.4shared.com.
Publisher:
mp3

Version:
1.0.0.0

MD5:
de28e062c25d341447f97035f535505a

SHA-1:
b69b7a3f9d6a5cfcea3f3a0f4f90acc7a6c6e05e

SHA-256:
10ce28fed606e2096749796756f1a3ac6f880d2f16f58ae3911dff501012a063

Scanner detections:
33 / 68

Status:
Malware

Analysis date:
12/26/2024 2:21:02 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/NTkrnl
7.1.1

AhnLab V3 Security
Downloader/Win32.Agent
2013.04.23

Avira AntiVirus
TR/Crypt.XPACK.Gen
7.11.73.248

avast!
Win32:Packed-E [Heur]
2014.9-160714

AVG
Downloader.Agent2
2017.0.2683

Bitdefender
Gen:Variant.Zusy.16121
1.0.20.980

Comodo Security
TrojWare.Win32.PSW.Ldpinch.~NNT
16030

Dr.Web
Trojan.Click.20169
9.0.1.0196

Emsisoft Anti-Malware
Gen:Variant.Zusy.16121
8.16.07.14.12

ESET NOD32
Win32/Spy.Banker.SMU (variant)
10.8256

Fortinet FortiGate
W32/FakeAV.FE!tr
7/14/2016

F-Prot
W32/SuspPack.G.gen
v6.4.7.1.166

F-Secure
Trojan-Spy:W32/Banker.JGT
11.2016-14-07_5

G Data
Gen:Variant.Zusy.16121
16.7.22

IKARUS anti.virus
Trojan-Downloader.Win32.Genome
t3scan.2.0.0.0

K7 AntiVirus
Trojan-Downloader
13.166.8564

Kaspersky
Trojan-Downloader.Win32.Agent
14.0.0.-90

Malwarebytes
Spyware.Banker
v2016.07.14.12

McAfee
PWS-Banker!hgh
5600.6339

Microsoft Security Essentials
VirTool:Win32/Obfuscator.LC
1.163.1557.0

MicroWorld eScan
Gen:Variant.Zusy.16121
17.0.0.588

NANO AntiVirus
Trojan.Win32.Agent2.xcupr
0.24.0.52049

Norman
Packed_NTKrnl.B
11.20160714

Panda Antivirus
Generic Trojan
16.07.14.12

Quick Heal
TrojanDownloader.Agent.wjrg
7.16.12.00

Sophos
Mal/Banker-Z
4.88

SUPERAntiSpyware
Trojan.Agent/Gen-Pakret
9023

Total Defense
Win32/SillyDl.PVN!packed
37.0.10389

Trend Micro House Call
TROJ_SPNR.09HT12
7.2.196

Trend Micro
TROJ_SPNR.09HT12
10.465.14

Vba32 AntiVirus
SScope.Trojan-Downloader.Win32.Banload.bfn
3.12.20.2

VIPRE Antivirus
Trojan.Win32.Packer.NTkrnl0.1
17110

ViRobot
Trojan.Win32.A.Downloader.1048064.D
2011.4.7.4223

File size:
1023.5 KB (1,048,064 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\users\{user}\downloads\adele - set fire to the rain - lancamento - 2012.mp3.exe

File PE Metadata
Compilation timestamp:
8/17/2001 5:52:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.160

CTPH (ssdeep):
24576:54kpdQcjzKv+xmDSVxDZ5JGJW0/kqsefmwTmq3ENtP:7dQcj2v+xeAZ5JmW0/q3EED

Entry address:
0x1061

Entry point:
68, 95, 81, 4F, 00, E8, 01, 00, 00, 00, C3, C3, 96, 60, 8E, DC, 93, EB, E1, D8, 83, 63, A8, D4, BB, D5, BA, 50, 95, E8, D5, 6C, 89, 7F, 64, 68, 77, D0, 4E, 0C, CA, EB, 29, 60, F7, CA, F2, 7C, 8E, 97, A6, CA, E2, EA, A5, 74, 4D, 83, A0, 64, 60, 06, C4, 3C, 60, 69, E2, 86, 7F, BA, EF, 87, 6D, 25, F5, 11, 98, FB, 60, A9, D3, BB, 3E, 2C, 8E, 99, 70, 72, 8E, C3, C2, 11, BD, 58, CB, 4F, 21, 0C, 50, AC, 0E, FF, 17, 36, 0B, AE, 98, 4B, 27, AF, 3E, 3B, CE, F6, 91, A9, 70, FF, 61, 44, 5C, 27, E4, BC, AE, 4C, C1, 7C...
 
[+]

Code size:
2.7 MB (2,859,008 bytes)

The file adele - set fire to the rain - lancamento - 2012.mp3.exe has been seen being distributed by the following URL.