beyluxe-hiden-emoticons-v2-www.bandari.ir.exe

Beyluxe Hiden Emoticons - www.Bandari.ir

BeyluXe Messenger

Publisher:
BeyluXe Messenger

Product:
Beyluxe Hiden Emoticons - www.Bandari.ir

Description:
Beyluxe Hiden Emoticons - By B e h n a M

Version:
2.00

MD5:
164abaed30da41442b67c4a6a3f594b9

SHA-1:
02a907e01bd3a0ed02e85c6193771f37574f369a

SHA-256:
46f5a914da49622c20fbffe120bd5fd65fea1691054c6f752de5b743313dba85

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/26/2024 3:10:58 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.W32.Gen
2.1.4+

Bkav FE
W32.Clodd28.Trojan
1.3.0.6185

File size:
1.4 MB (1,421,312 bytes)

Product version:
2.00

Original file name:
Beyluxe Hiden Emoticons- WwW.Bandari.iR.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
11/9/2011 12:18:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:R2wSw0N6MyPSXYOECzo1DqUmbruUcKg2PMtKldIF7YHqbz:R2wSwW6MyPSXYOECzo1DqUmbruUcKg2O

Entry address:
0x1E18

Entry point:
68, 1C, A9, 4D, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, C1, 2B, 8E, DC, 17, BB, F1, 40, 97, 71, F3, 8D, 47, 2C, C9, 90, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 41, 00, 40, 30, 41, 00, 42, 65, 79, 6C, 75, 78, 65, 48, 69, 64, 65, 6E, 45, 6D, 6F, 74, 69, 63, 6F, 6E, 73, 00, 82, 01, 00, 00, 00, 00, FF, CC, 31, 00, 69, E6, DF, B0, 99, B3, 60, 3E, 45, AC, 10, 92, C1, 19, 16, 1B, C3, 54, 55, 09, 4F, C1, E4, 8D, 4F, A6, 4D, 00, 25, 8D, 9B, 01, B1, 3A, 4F, AD...
 
[+]

Entropy:
5.3959

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
1.1 MB (1,114,112 bytes)

The file beyluxe-hiden-emoticons-v2-www.bandari.ir.exe has been seen being distributed by the following 2 URLs.

http://bandari.ir/Beyluxe-Hiden-Emoticons-V2-WwW.Bandari.iR.exe

Scan beyluxe-hiden-emoticons-v2-www.bandari.ir.exe - Powered by Reason Core Security