aim+wh.exe

Mamba

The application aim+wh.exe has been detected as a potentially unwanted program by 32 anti-malware scanners. The file has been seen being downloaded from www76.zippyshare.com and multiple other hosts.
Publisher:
Mamba

Product:
Mamba

Description:
SSE Build

Version:
1.0.0.0

MD5:
93def87bcce91b4b5140718506e89a12

SHA-1:
d364df85735e4e3dfda7acdeb06bb0e7524d2d62

SHA-256:
c7a1dbea10221236aebca4af91640428c12db04e9dd134f34def17dd798317e2

Scanner detections:
32 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 5:35:06 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.15331884
367

Agnitum Outpost
Trojan.Agent
7.1.1

AhnLab V3 Security
Trojan/Win32.Kazy
2016.01.02

Avira AntiVirus
TR/Dropper.MSIL.Gen
8.3.2.4

Arcabit
Trojan.Generic.DE9F22C
1.0.0.637

avast!
MSIL:Stealer-O [Trj]
2014.9-160203

AVG
MSIL6
2017.0.2845

Baidu Antivirus
Trojan.MSIL.Steamilik
4.0.3.1623

Bitdefender
Trojan.Generic.15331884
1.0.20.170

Bkav FE
HW32.Packed
1.3.0.7400

Comodo Security
UnclassifiedMalware
23898

Emsisoft Anti-Malware
Trojan.Generic.15331884
8.16.02.03.09

ESET NOD32
MSIL/Stimilik.DI (variant)
10.12804

Fortinet FortiGate
W32/Generic!tr
2/3/2016

F-Secure
Trojan.Generic.15331884
11.2016-03-02_4

G Data
Trojan.Generic.15331884
16.2.25

IKARUS anti.virus
PUA.MSIL.Confuser
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.212.18299

Kaspersky
Trojan.MSIL.Steamilik
14.0.0.718

Malwarebytes
Trojan.PasswordStealer.Steam
v2016.02.03.09

McAfee
RDN/Generic PUP.x!cqz
5600.6501

Microsoft Security Essentials
Trojan:MSIL/Stimilini.H
1.1.12400.0

MicroWorld eScan
Trojan.Generic.15331884
17.0.0.102

NANO AntiVirus
Trojan.Win32.Confuser.dliwjd
1.0.14.5380

nProtect
Trojan.Generic.15331884
15.12.31.01

Panda Antivirus
Trj/CI.A
16.02.03.09

Quick Heal
Trojan.Generic.r5
2.16.14.00

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16201

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic
46220

ViRobot
Trojan.Win32.Z.Steamilik.502272.A[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Steamilik.Win32.755
2.0.0.2591

File size:
490.5 KB (502,272 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (c) 2014

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\aim+wh.exe

File PE Metadata
Compilation timestamp:
12/24/2014 9:09:08 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:IAIwVbyGFDlPvxsJ1LX1keftWP/mrNa5vsq:T5y6lHxsJB1zoPeM2

Entry address:
0x8000A

Entry point:
FF, 25, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.9500

Code size:
15.5 KB (15,872 bytes)

The file aim+wh.exe has been seen being distributed by the following 11 URLs.

http://www76.zippyshare.com/d/55015737/.../Aim WH.exe

http://www76.zippyshare.com/d/55015737/.../Aim WH.exe

Remove aim+wh.exe - Powered by Reason Core Security