BotRanNew2.exe

Project1

Computer.,Co.Ltd.

The executable BotRanNew2.exe has been detected as malware by 5 anti-virus scanners. The file has been seen being downloaded from download1686.mediafire.com.
Publisher:
Computer.,Co.Ltd.

Product:
Project1

Version:
1.00

MD5:
b4d2a42a32fd0ac2e070ea1812a2e268

SHA-1:
c8052cb7fb3210ac744f57c349680e73757d4547

SHA-256:
8d8882a4d58f44e53ba65224651a4f8a3ea0105590db45c4158d6c6ffff699ed

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
12/26/2024 12:58:57 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160518-2

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.223.2717.0

VIPRE Antivirus
Threat.4721115
50324

File size:
136 KB (139,264 bytes)

Product version:
1.00

Original file name:
BotRanNew2.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\botrannew2.exe

File PE Metadata
Compilation timestamp:
10/9/2010 9:31:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:d4xkUKn65WssMMsDmUsipEJ+Ldnr/NSEcO3OaMEZgFS977KIANny5fC3sdl3:GksVEgdr/5ZMcgA977KVnylC8f3

Entry address:
0x1750

Entry point:
89, FD, 48, 01, EF, 81, D9, D7, 80, BA, 83, 2A, D4, 88, EE, C6, C0, A9, 0F, AF, E8, FF, C8, 0F, AF, F8, 0F, AF, DF, 48, 76, 02, 2C, 75, 78, 0E, F7, C1, 9C, 4B, 3A, F2, 81, CB, EA, 85, 93, 9E, 8B, C1, 8B, EB, 88, D7, 8B, F2, 85, CA, 8B, FD, 69, D9, B2, A8, F8, F3, 08, CB, 69, F5, 50, C3, 25, CE, 0B, EF, 8B, D7, B4, 14, BE, 83, 83, B2, EE, 0F, AF, EF, 8D, 35, 94, E3, 3E, 9E, 8A, E4, 33, CA, 89, C0, 86, DF, 81, C7, CC, 46, 9F, 3F, 85, E8, 78, 02, FE, CB, BE, B9, E9, 28, 22, 03, FF, BF, 88, BF, D6, 86, 84, D3...
 
[+]

Entropy:
6.7261

Code size:
56 KB (57,344 bytes)

The file BotRanNew2.exe has been seen being distributed by the following URL.

Remove BotRanNew2.exe - Powered by Reason Core Security