avast_secureline_setup.exe

The executable avast_secureline_setup.exe has been detected as malware by 7 anti-virus scanners. The file has been seen being downloaded from secureline.tools.avast.com.
MD5:
69c911843502b9850baa3f398a41b28a

SHA-1:
c84a805b6ed6a66d7f5a0eab61092c499cde7eaf

SHA-256:
8535b6ee3c1a50a9a7cb80a4e0f07439fc07c8d1c21d4a4b82fd4526f0551036

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
12/26/2024 11:39:26 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:AutoRun-CWJ [Trj]
160518-2

Dr.Web
Trojan.Siggen6.55368
9.0.1.05190

Emsisoft Anti-Malware
Trojan.Generic.KDV.391478
11.5.0.6191

ESET NOD32
Win32/AutoRun.Delf.LV worm
8.0.319.0

F-Prot
W32/Autorun.ZF
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.223.968.0

Norman
Trojan.Generic.KDV.391478
28.05.2016 13:03:37

File size:
824.5 KB (844,288 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\avast_secureline_setup.exe

File PE Metadata
Compilation timestamp:
8/9/2011 12:51:42 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:1wCBtLC+EptUpQ9SeSChq3YvxFBSSRMT8PTp4ehozED888888888888W8888888J:ZNzCtUpQ9WWPBSSRMTEpXNX

Entry address:
0xABD46

Entry point:
B9, 88, 42, 00, 00, 14, BD, EB, 0B, 00, 00, 00, 00, 05, C6, 00, 1A, 51, 00, E3, 80, EC, 8B, 39, C8, 85, C2, 8D, 95, 73, 26, CE, DA, 86, E6, F6, D2, F8, 81, A9, 00, A4, 4D, 00, 33, 09, F6, 84, EB, 9F, 00, 00, 00, BF, C9, 54, D0, 49, 66, 50, 00, 04, 89, 52, DD, 44, 4B, 4A, 81, 13, 00, 65, F1, 5C, 6C, 00, 26, 84, C8, FE, 5C, 0E, 6C, F6, 3B, 00, 55, A6, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5284

Code size:
682.5 KB (698,880 bytes)

The file avast_secureline_setup.exe has been seen being distributed by the following URL.

Remove avast_secureline_setup.exe - Powered by Reason Core Security