ar2hginj.exe

The file ar2hginj.exe has been detected as malware by 12 anti-virus scanners. The file has been seen being downloaded from palmadeouro.edanfe.ru and multiple other hosts.
Version:
0.0.0.0

MD5:
76fbd12b62f511d45b36106e13486e98

SHA-1:
a227533c2db2171b9580d88e154d508f34fe1468

SHA-256:
4921e7828dfb956ce442a4c15a897ab8eec38619d5aa32a74689ff5f24ccb5f8

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
11/15/2024 8:53:42 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Razy.16934
343

Arcabit
Trojan.Razy.D4226
1.0.0.656

Bitdefender
Gen:Variant.Razy.16934
1.0.20.285

Emsisoft Anti-Malware
Gen:Variant.Razy.16934
8.16.02.26.11

ESET NOD32
MSIL/TrojanDownloader.Agent.AHG (variant)
10.13092

Fortinet FortiGate
MSIL/Agent.BGK!tr.dldr
2/26/2016

F-Secure
Gen:Variant.Razy.16934
11.2016-26-02_6

G Data
Gen:Variant.Razy.16934
16.2.25

Microsoft Security Essentials
TrojanDownloader:MSIL/Banload.AF
1.1.12400.0

MicroWorld eScan
Gen:Variant.Razy.16934
17.0.0.171

Panda Antivirus
Trj/CI.A
16.02.26.11

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1120

File size:
500 KB (512,000 bytes)

Product version:
0.0.0.0

Original file name:
Loader-MCXXGMYSKA.exe

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\ar2hginj.exe.part

File PE Metadata
Compilation timestamp:
2/26/2016 3:16:16 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:x/WArWGyxlkjeg5okhIpq23jSGGjGgGPvRGGNPG4GgGuMGGoGGE/o/dfGGTGGWaF:5aViwjV+g/MtP32xjRAU9

Entry address:
0x57D8E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
344 KB (352,256 bytes)

The file ar2hginj.exe has been seen being distributed by the following 2 URLs.

http://palmadeouro.edanfe.ru/index.php?id=PALMADEOURO

Remove ar2hginj.exe - Powered by Reason Core Security