bosonnetsim6.exe

The executable bosonnetsim6.exe has been detected as malware by 16 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dc404.4shared.com.
MD5:
ef8fd32ff5f6eed28d703d6a1d2f94e8

SHA-1:
fb78562e0dd33fde2789180f19bbc5abfc138981

SHA-256:
ba2f15a17dc8263b295762c35d6a550318d3ec4c9a7a83caefc2008e894928b2

Scanner detections:
16 / 68

Status:
Malware

Analysis date:
11/24/2024 12:47:58 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Backdoor.Agent
7.1.1

Avira AntiVirus
SPR/Tool.Keygen.3201
7.11.180.154

AVG
BackDoor.Generic11
2017.0.2826

F-Prot
W32/Backdoor2.EXLD
v6.4.7.1.166

G Data
Win32.Trojan.Agent.8ZU22Y
16.2.24

IKARUS anti.virus
Backdoor.Win32.Beastdoor
t3scan.1.7.8.0

K7 AntiVirus
Trojan
13.184.13741

McAfee
W32/Mytob@MM!e
5600.6482

Microsoft Security Essentials
1.11104

Norman
Suspicious_Gen2.KUGJA
11.20160221

nProtect
Backdoor/W32.Agent.195072.Q
14.10.22.01

Quick Heal
(Suspicious) - DNAScan
2.16.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.11EC4F51!300699473
23.00.65.16219

VIPRE Antivirus
Trojan.Win32.Generic
34150

ViRobot
Backdoor.Win32.A.Hupigon.195072.B
2011.4.7.4223

Zillya! Antivirus
Backdoor.Beastdoor.Win32.797
2.0.0.1964

File size:
190.5 KB (195,072 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\bosonnetsim6.exe

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:eK6ROvb4GwkyvedPiOUJZbyRVvw5BOR5OE1EM2jASY1atZgn37zpnop2WtXvs3RG:eKOa4GwkyWllAbyDvw5y92NgvpnoJtE4

Entry address:
0x1000

Entry point:
68, 01, C0, 43, 00, E8, 01, 00, 00, 00, C3, C3, AF, 2A, D1, B8, A3, 6A, 92, C1, 4B, 81, 42, E7, 95, F8, 8B, 22, 77, 49, 56, C6, E5, E3, FE, 92, 93, 22, 43, 38, 22, 23, D4, E7, FA, FA, 0D, 4A, 58, E1, A2, 8F, 16, 5D, B0, 5D, 88, D6, 88, E4, 56, D1, 67, 7D, E7, B5, D5, 36, 53, DE, 1B, 3F, F5, 04, E9, 93, 0C, D8, 46, 82, 21, 7D, EF, 3C, 0A, 57, 3D, F6, 9C, 15, EE, B8, 26, 7C, CC, B7, EA, 5F, 18, 2F, 68, 8D, 82, 19, 62, AE, 19, 47, 0B, 6A, 09, A7, 9E, F1, 3C, 26, AA, 0A, E4, BF, E0, 19, 98, 28, E3, 7A, 52, 4F...
 
[+]

Entropy:
7.8403

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
43 KB (44,032 bytes)

The file bosonnetsim6.exe has been seen being distributed by the following URL.

Remove bosonnetsim6.exe - Powered by Reason Core Security