auto tune evo vst setup.exe

The executable auto tune evo vst setup.exe has been detected as malware by 9 anti-virus scanners. The program is a setup application that uses the Nullsoft Scriptable Install System installer, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from auto-tune-evo-vst.soft32.com.
MD5:
0766e4989b4ffbc78100ef5677c32880

SHA-1:
d8185ef15e2f284505c1b582d148089d2ef6cacb

SHA-256:
5f2331a49b5bd6065741bb63f403d48a739e6784177f589f98a7ecbe92b88d0a

Scanner detections:
9 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
12/28/2024 2:37:48 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160119-0

AVG
Win32/Sality
2015.0.4489

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

McAfee
Virus.SoftDropper
18.0.204.0

Norman
Win32.Sality.3
18.01.2016 17:20:53

VIPRE Antivirus
Threat.4721115
46830

File size:
599.2 KB (613,536 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\downloads\auto tune evo vst setup.exe

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:nA5oQNYn+gch3CiVFH4YqdmiwpYJxEMHeFieFY3myR:AGi3XVV5hY+QeieFqm

Entry address:
0x30FA

Entry point:
C7, C1, 39, 73, 01, 02, FE, C4, 70, 03, C6, C1, C5, 69, FB, DB, 08, 58, 6D, 0F, BE, F9, F2, F6, C5, F3, 8B, D5, 8B, C0, FF, C6, 69, FF, 5B, 3B, 6A, 99, B5, CC, FF, CD, 0F, B7, C9, 0F, AF, DD, 88, E5, 68, 03, 97, C4, 00, 8B, CF, 89, CE, E8, 2C, 00, 00, 00, F7, C6, 74, 09, 34, 10, 80, FE, 24, 89, E9, FE, CD, FF, C9, EB, 05, 15, 90, 40, 79, 8B, 68, BB, 58, 0C, 00, FE, CB, 87, F8, 5E, 0F, BF, C8, 0F, AF, EE, 81, F6, E3, B4, 0C, 00, 5F, 84, CB, 09, F2, 68, 14, 35, BB, 00, 48, 84, E1, 85, D2, 72, 02, 87, CA, 31...
 
[+]

Entropy:
7.9347  (probably packed)

Code size:
23.5 KB (24,064 bytes)

The file auto tune evo vst setup.exe has been seen being distributed by the following URL.

Remove auto tune evo vst setup.exe - Powered by Reason Core Security