b96a6d.exe

The executable b96a6d.exe has been detected as malware by 9 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘B96A6D’.
MD5:
874d7c2c30731e7ba262203010aac6cf

SHA-1:
62dcd2779f1936831e5b2f0ec3ed27655676e4c2

SHA-256:
a529f74908a661e10581857da542cc01b370448474fac9a5bf82015224a971b2

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
11/30/2024 8:53:05 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:EvilEPL [Cryp]
160917-0

AVG
Win32/Heur
2013.0.4477

Clam AntiVirus
Win.Worm.FlyStudio-17
0.98/22392

Dr.Web
Win32.HLLW.Autoruner.26035
9.0.1.05190

ESET NOD32
Win32/Flyagent.NDA trojan
6.3.12010.0

F-Prot
W32/Nuj.A.gen
4.6.5.141

F-Secure
Trojan-Dropper:W32/Peed.gen!A
5.15.154

Kaspersky
Trojan-Downloader.Win32.FlyStudio
15.0.2.529

Microsoft Security Essentials
Backdoor:Win32/FlyAgent.F
1.229.1461.0

File size:
1.3 MB (1,407,794 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\1f22ec\b96a6d.exe

File PE Metadata
Compilation timestamp:
12/24/1972 9:33:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
4.0

CTPH (ssdeep):
24576:UrPFuUh7HmhZWPW/3AD0+ea7vHA//gGAsSw4+STEomHDgJf24UI:QIXZWuP40+BTHA//PDfNsMVI

Entry address:
0x140B

Entry point:
50, 83, E0, 00, 53, 51, 52, 56, 57, 0F, 84, FC, FE, FF, FF, 80, 7D, 75, B1, 85, 9B, C7, 26, 25, 14, 7F, DC, 61, 8E, 0B, 2E, 75, 9B, 3F, A7, EA, 14, 16, 26, 25, 18, FB, AC, 4C, FC, 87, A6, B4, 91, E7, F7, 72, 10, FC, 27, 22, 84, 0A, A6, 24, 63, 4C, F3, 49, 64, FC, A2, 61, 93, C0, AB, BC, 68, 87, 96, E3, FE, FC, A2, A1, 10, 70, E7, EC, 60, 00, A6, 34, 9B, 44, AB, E4, 09, FD, 20, 99, 9B, FE, A5, 24, 9B, 76, A7, 8C, DF, 4D, 26, 51, 18, CD, 92, E5, D2, 04, D6, 2A, 93, FB, A3, D5, 2B, 62, 2E, 6C, 93, BE, A5, 58...
 
[+]

Entropy:
7.9645  (probably packed)

Code size:
24 KB (24,576 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
B96A6D

Command:
C:\Windows\System32\1f22ec\b96a6d.exe


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-52-0-217-44.compute-1.amazonaws.com  (52.0.217.44:80)

Remove b96a6d.exe - Powered by Reason Core Security