bé hack.exe

WindowsApplication1

The executable bé hack.exe has been detected as malware by 23 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download1022.mediafire.com and multiple other hosts.
Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
c17c9e19979676e229cee030e4f92e8f

SHA-1:
4b0866255dd65109fb5ae5646124d483d4f9bfbf

SHA-256:
7a747ba12c2858eca044e0fc07b712bfa38fbcaea67e13addbbe84f4b46a1205

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
11/5/2024 4:43:16 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Spy.Gen
8.3.2.2

Arcabit
Trojan.Generic.DE6ACCC
1.0.0.582

avast!
Win32:Malware-gen
2014.9-160319

AVG
PSW.MSIL
2017.0.2799

Baidu Antivirus
Trojan.MSIL.Agent
4.0.3.16319

Bitdefender
Trojan.Generic.15117516
1.0.20.395

Comodo Security
UnclassifiedMalware
23418

Emsisoft Anti-Malware
Trojan.Generic.15117516
8.16.03.19.01

ESET NOD32
MSIL/PSW.Agent.NFI (variant)
10.12411

Fortinet FortiGate
MSIL/Agent.OFU!tr
3/19/2016

F-Secure
Trojan.Generic.15117516
11.2016-19-03_7

G Data
Trojan.Generic.15117516
16.3.25

IKARUS anti.virus
Trojan.MSIL.PSW
t3scan.1.9.5.0

K7 AntiVirus
Password-Stealer
13.210.17540

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.492

McAfee
Artemis!C17C9E199796
5600.6455

Microsoft Security Essentials
Trojan:Win32/Skeeyah.A!bit
1.1.12101.0

MicroWorld eScan
Trojan.Generic.15117516
17.0.0.237

NANO AntiVirus
Trojan.Win32.Agent.dxvnru
0.30.26.3947

nProtect
Trojan.Generic.15117516
15.10.15.02

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R00XC0EJ715
10.465.19

VIPRE Antivirus
Trojan.Win32.Generic
44546

File size:
701.5 KB (718,336 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
WindowsApplication1.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\bé hack.exe

File PE Metadata
Compilation timestamp:
8/2/2015 12:08:36 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
80.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:8ybq2t78qmlKzlH6H4JgfyxkC9Fqi29rsILQHS6Hl0AGnB:VfB7mlKzlHpJg6r9FqiSrsJNlJ0

Entry address:
0xB0A02

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
699 KB (715,776 bytes)

The file bé hack.exe has been seen being distributed by the following 2 URLs.

Remove bé hack.exe - Powered by Reason Core Security