conquer_v5987_p2p.exe

Conquer Online Downloader

TQ Digital Entertainment

The executable conquer_v5987_p2p.exe has been detected as malware by 17 anti-virus scanners.
Publisher:
TQ Digital Entertainment

Product:
Conquer Online Downloader

Version:
1, 0, 2, 2

MD5:
b94d1bf1d0acf8493f91e416c0e920c9

SHA-1:
3a6e2eb9921d1145b30f5381135bb79e5de0015a

SHA-256:
a9aa11826a47c6c8f86bc0b415c1e7b2a2782fbad3aaf3dbfb69c117536415d2

Scanner detections:
17 / 68

Status:
Malware

Analysis date:
12/27/2024 3:28:18 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12225993
757

Agnitum Outpost
Trojan.Rogue
7.1.1

Avira AntiVirus
TR/Rogue.1138176.3
7.11.199.42

avast!
Win32:Malware-gen
2014.9-150109

Bitdefender
Trojan.Generic.12225993
1.0.20.45

Emsisoft Anti-Malware
Trojan.Generic.12225993
8.15.01.09.03

Fortinet FortiGate
PossibleThreat.SB!tr.dldr
1/9/2015

F-Secure
Trojan.Generic.12225993
11.2015-09-01_6

G Data
Trojan.Generic.12225993
15.1.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.8.5.0

McAfee
Artemis!B94D1BF1D0AC
5600.6891

MicroWorld eScan
Trojan.Generic.12225993
16.0.0.27

Norman
Suspicious_Gen2.WAQKC
11.20150109

nProtect
Trojan.Generic.12225993
15.01.02.01

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R0C1H09L414
7.2.9

VIPRE Antivirus
Win32.Malware!Drop
36320

File size:
1.1 MB (1,138,176 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2010

Original file name:
Downloader.EXE

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\conquer_v5987_p2p.exe

File PE Metadata
Compilation timestamp:
10/11/2014 2:19:31 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:BY2pSjUmFiCbp1RD1zE8auFv6kA9eU5wKxO:JzmFiC3RRzPaw6fwKw

Entry address:
0x694D3

Entry point:
E8, 01, 1C, 01, 00, E9, 78, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, A0, C4, 4B, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, A0, C4, 4B, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Entropy:
7.0241

Code size:
616 KB (630,784 bytes)

The file conquer_v5987_p2p.exe has been seen being distributed by the following 2 URLs.

ftp://94.236.25.182/.../Conquer_v5987_P2P.exe

Remove conquer_v5987_p2p.exe - Powered by Reason Core Security