blessing.exe

The executable blessing.exe has been detected as malware by 23 anti-virus scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from s10579.chomikuj.pl.
MD5:
c0236ca85726c628fa057741d9b4217d

SHA-1:
e7333bcd3b923afe15172dfa64ffa74d6c115722

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
1/14/2025 9:50:38 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Uds.Dangerousobject.Multi!c
2.1.4+

Agnitum Outpost
Trojan.Swizzor
7.1.1

Avira AntiVirus
TR/Swizzor.xgh
8.3.2.4

AVG
Downloader.Swizzor
2017.0.2826

Clam AntiVirus
Win.Trojan.Swizzor-24739
0.98/21511

Fortinet FortiGate
W32/Malware_fam.NB
2/21/2016

G Data
Win32.Trojan.Agent.F8JU2L
16.2.25

IKARUS anti.virus
Trojan-Downloader.Swizzor
t3scan.2.0.4.0

K7 AntiVirus
Riskware
13.213.18557

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.626

Malwarebytes
Trojan.Agent
v2016.02.21.07

McAfee
Generic.gi
5600.6482

Microsoft Security Essentials
1.1.12400.0

NANO AntiVirus
Trojan.Win32.Swizzor.dodalv
1.0.14.5798

nProtect
Trojan/W32.Swizzor.31232
16.01.27.03

Panda Antivirus
Trj/CI.A
16.02.21.07

Qihoo 360 Security
Win32/Trojan.f1c
1.0.0.1077

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16219

Sophos
Keygen (PUA)
4.98

Trend Micro
TROJ_GEN.R047C0EH615
10.465.21

VIPRE Antivirus
Trojan.Win32.Generic
46786

ViRobot
Trojan.Win32.Z.Swizzor.31232[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Swizzor.Win32.166639
2.0.0.2633

File size:
30.5 KB (31,232 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\documents and settings\a m\pulpit\nowy folder\sibelius 5\blessing.exe

File PE Metadata
Compilation timestamp:
7/26/2007 1:37:28 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
384:ezRHMunfaIBxU+E/1Ha2JTN6Lk3WvMpFGbsvXsbTwc+IyrbTl+JHW6NdogkyT9a/:eRnfayUxawh06GYSTB9yrqP6gkyJai

Entry address:
0x13D10

Entry point:
60, BE, 00, D0, 40, 00, 8D, BE, 00, 40, FF, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
28 KB (28,672 bytes)

The file blessing.exe has been seen being distributed by the following URL.

Remove blessing.exe - Powered by Reason Core Security