cheat.exe

The executable cheat.exe has been detected as malware by 8 anti-virus scanners. This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘NetworkInformer’. The file has been seen being downloaded from 73167214217878.akvariumchik.ru.
MD5:
70550e18c4a7b9a0475ebe8bce52beca

SHA-1:
96b7c227b911355e8e2de0c19970e318fd8c5378

SHA-256:
8dcf285be8044194ff8dd3495150c935790d097639af77ad2216c2b519aab8aa

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
12/27/2024 8:02:34 PM UTC  (today)

Scan engine
Detection
Engine version

Bitdefender
Gen:Variant.Razy.56808
1.0.20.695

Emsisoft Anti-Malware
Gen:Variant.Razy.56808
8.16.05.18.10

ESET NOD32
Win32/Injector.CYQM (variant)
10.13510

G Data
Gen:Variant.Razy.56808
16.5.25

McAfee
PWSZbot-FARB!70550E18C4A7
5600.6395

MicroWorld eScan
Gen:Variant.Razy.56808
17.0.0.417

Qihoo 360 Security
QVM20.1.Malware.Gen
1.0.0.1120

Rising Antivirus
Malware.Generic!l00uxUZFPRP@2 (Thunder)
23.00.65.16516

File size:
1 MB (1,060,143 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\cheat.exe

File PE Metadata
OS version:
15.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
3.0

CTPH (ssdeep):
24576:c4yNxS4z0clW77RLNvB9rF6U0hvjfkhaQ0iVJGv7Ziql0:c4EB8799rQ1rfHQJGv7F0

Entry address:
0x172A

Entry point:
55, 8B, EC, 6A, 90, 68, B0, 22, 40, 00, 68, 6A, 19, 40, 00, 64, A1, 00, 00, 00, 00, 60, 64, 89, 25, 90, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, 5F, 57, FF, 15, C8, 43, 40, 00, 59, 83, 0D, 0C, 3C, 40, 00, FF, 83, 90, 10, 3C, 40, 00, FF, FF, 15, C4, 43, 40, 00, 8B, 0D, 00, 3C, 40, 00, 89, 08, FF, 15, C0, 43, 40, 00, 8B, 0D, FC, 3B, 40, 00, 89, 08, A1, BC, 43, 40, 00, 8B, 00, A3, 08, 3C, 40, 00, E8, 7E, FD, FF, FF, 90, 1D, 20, 3B, 40, 00, 75, 0C, 68, 66, 19, 40, 00, FF, 15...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
4 KB (4,096 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NetworkInformer

Command:
C:\users\{user}\downloads\cheat.exe


The file cheat.exe has been seen being distributed by the following URL.

Remove cheat.exe - Powered by Reason Core Security