bbcbb v1.0.0 made by muyeco.exe

Remote Service Application

Microsoft Corp.

The executable bbcbb v1.0.0 made by muyeco.exe has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from fs12n1.sendspace.com.
Publisher:
Microsoft Corp.

Product:
Remote Service Application

Version:
1, 0, 0, 1

MD5:
d3c3d6d97c979b8b593fe3f99fa9289a

SHA-1:
94b43d16a1a5ca54f78cfa30597694255f5ded2e

SHA-256:
c0fe4033fac06780bbc45b6917fc8f001b12d0a7e0a35948f5ecaea212736a63

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/27/2024 5:19:15 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Trojan.Backdoor (M)
16.7.16.8

File size:
828.5 KB (848,384 bytes)

Product version:
4, 0, 0, 0

Copyright:
Copyright (C) 1999

Original file name:
MSRSAAP.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\bbcbb v1.0.0 made by muyeco.exe

File PE Metadata
Compilation timestamp:
3/19/2012 4:56:30 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:40QRWoJEfg0oChGdJQbjPbNW5tYeP+GFdSg3qaW3K7:TQRV2o3MPY5AjgBWG

Entry address:
0x8D888

Entry point:
55, 8B, EC, B9, 31, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, 28, CA, 48, 00, E8, 30, 9E, F7, FF, 33, C0, 55, 68, 20, E6, 48, 00, 64, FF, 30, 64, 89, 20, 6A, 00, E8, 1B, 27, F8, FF, A1, 68, 23, 49, 00, C6, 00, 01, E8, 6A, BD, FF, FF, B2, 01, A1, C8, C4, 48, 00, E8, 62, EC, FF, FF, A3, E4, A3, 49, 00, 33, D2, 55, 68, 08, DA, 48, 00, 64, FF, 32, 64, 89, 22, 8D, 4D, EC, BA, 38, E6, 48, 00, A1, E4, A3, 49, 00, E8, B1, EC, FF, FF, 8B, 55, EC, A1, F0, 25, 49, 00, E8, 80, 7C, F7, FF, 8D, 55, E0, 33...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
566.5 KB (580,096 bytes)

The file bbcbb v1.0.0 made by muyeco.exe has been seen being distributed by the following URL.

Remove bbcbb v1.0.0 made by muyeco.exe - Powered by Reason Core Security