bor.exe

The application bor.exe has been detected as a potentially unwanted program by 26 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from idse.imss.gob.mxii.cf.
MD5:
8a11e7fd0753e518802b4f8a592d1ac7

SHA-1:
c7a4deb06f4db35fe1277e49a9ccb153df6d2771

SHA-256:
f55b3642a6061cc410242ca6ceb2ff4c68dbea3a306752c393d77239702bda8f

Scanner detections:
26 / 68

Status:
Potentially unwanted

Analysis date:
1/13/2025 8:37:58 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Agiala.12
322

AhnLab V3 Security
Malware/Win32.Generic
2015.12.19

Avira AntiVirus
TR/Crypt.ZPACK.Gen4
8.3.2.4

Arcabit
Trojan.Agiala.12
1.0.0.629

avast!
Win32:Malware-gen
2014.9-160318

AVG
Inject3
2017.0.2800

Baidu Antivirus
Trojan.Win32.Ransom
4.0.3.16318

Bitdefender
Gen:Variant.Agiala.12
1.0.20.390

Comodo Security
TrojWare.Win32.Carberp.D
23790

Emsisoft Anti-Malware
Gen:Variant.Agiala.12
8.16.03.18.09

ESET NOD32
Win32/Injector.CMEG (variant)
10.12744

Fortinet FortiGate
W32/Injector.CMZS!tr
3/18/2016

F-Secure
Gen:Variant.Agiala.12
11.2016-18-03_6

G Data
Gen:Variant.Agiala.12
16.3.25

Kaspersky
Trojan-Ransom.Win32.Cryakl
14.0.0.495

Malwarebytes
Trojan.Crypt
v2016.03.18.09

McAfee
Artemis!8A11E7FD0753
5600.6456

Microsoft Security Essentials
Trojan:Win32/Skeeyah.A!rfn
1.1.12400.0

MicroWorld eScan
Gen:Variant.Agiala.12
17.0.0.234

NANO AntiVirus
Trojan.Win32.Cryakl.dyqsaj
1.0.10.5081

Panda Antivirus
Trj/Genetic.gen
16.03.18.09

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R00XC0DLH15
10.465.18

Vba32 AntiVirus
Heur.Malware-Cryptor.Filecoder
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Filecoder.dga
45916

Zillya! Antivirus
Adware.Eorezo.Win32.17874
2.0.0.2569

File size:
337 KB (345,088 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\bor.exe

File PE Metadata
Compilation timestamp:
11/10/2015 9:16:15 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:A/6Wg5slps+Dqy9uCD+oMPuuQqN09tH8K3rv/K:AY5gtqAuCBu109R7vC

Entry address:
0x1688D

Entry point:
E8, BE, 26, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, A3, D0, E3, 41, 00, 5D, C3, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 88, D9, 41, 00, 33, C5, 89, 45, FC, 53, 8B, 5D, 08, 57, 83, FB, FF, 74, 07, 53, E8, 20, 27, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 6A, 4C, 8D, 85, E4, FC, FF, FF, 6A, 00, 50, E8, 2D, 27, 00, 00, 8D, 85, E0, FC, FF, FF, 89, 85, D8, FC, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, DC, FC, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8...
 
[+]

Entropy:
7.6780

Code size:
110 KB (112,640 bytes)

The file bor.exe has been seen being distributed by the following URL.

Remove bor.exe - Powered by Reason Core Security