birds-01-48.exe

The executable birds-01-48.exe has been detected as malware by 6 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from oracleireland.com.
MD5:
0ddf6af63dddf4c7db192af23ef0fade

SHA-1:
296207944535d48ebb504af3700caa21a9c82b5c

SHA-256:
88826792372140b52c6ab602589583f9c3bc7562c97bacc97660a0288de76baa

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
12/27/2024 1:55:24 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.MulDrop
7.1.1

Dr.Web
Trojan.MulDrop4.20681
9.0.1.074

McAfee
Artemis!0DDF6AF63DDD
5600.6461

NANO AntiVirus
Trojan.Win32.MulDrop4.cznklz
0.30.24.1636

SUPERAntiSpyware
Trojan.Agent/Gen-Muldrop
9266

Trend Micro House Call
Suspicious_GEN.F47V0316
7.2.74

File size:
686 KB (702,428 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\birds-01-48.exe

File PE Metadata
Compilation timestamp:
8/20/2007 2:57:33 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:WW5/m2TTvOMioCHVCm2AxqAXZMMp3TXwSI/zuOGJv0SSkDKZUNbt36VFRNSeHEUK:WWVm2TSMHiVQA0AXLp3TwSISOGJv0don

Entry address:
0x1DD0

Entry point:
6A, 01, FF, 15, 0C, 70, 40, 00, 50, 6A, 00, 6A, 00, FF, 15, 10, 70, 40, 00, 50, E8, FB, F2, FF, FF, 50, FF, 15, 14, 70, 40, 00, 55, 8B, EC, 8B, 55, 10, 53, 56, 57, 6A, 03, 33, FF, 59, 33, DB, 23, D1, 33, F6, 33, C0, 80, FA, 01, 75, 0A, 6A, 01, B8, 00, 00, 00, 80, 5E, EB, 20, F6, 45, 10, 04, 74, 07, B8, 00, 00, 00, C0, EB, 13, F6, 45, 10, 08, 74, 0A, 6A, 02, B8, 00, 00, 00, C0, 59, EB, 03, 8B, 4D, 10, 39, 7D, 0C, 74, 3C, 3B, C7, 74, 38, 57, 57, 51, 57, 56, 50, FF, 75, 0C, FF, 15, 50, 70, 40, 00, 8B, F0, 83...
 
[+]

Entropy:
7.9691

Packer / compiler:
FASM v1.3x

Code size:
23 KB (23,552 bytes)

The file birds-01-48.exe has been seen being distributed by the following URL.

Remove birds-01-48.exe - Powered by Reason Core Security