conquer_v6075_p2p.exe

Conquer Online Downloader

TQ Digital Entertainment

The executable conquer_v6075_p2p.exe has been detected as malware by 22 anti-virus scanners. The file has been seen being downloaded from co-cdn.download.99.com.
Publisher:
TQ Digital Entertainment

Product:
Conquer Online Downloader

Version:
1, 0, 2, 2

MD5:
03eabb04344d063e03a04ccdbb318002

SHA-1:
afa4aa86d2e707e4c8583a91f01abcc61b75c8eb

SHA-256:
c4ce115e34f01f72c0a669969f9421d153384d7922a57309eff6e1401cb29616

Scanner detections:
22 / 68

Status:
Malware

Analysis date:
11/24/2024 5:55:17 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.14532939
611

Agnitum Outpost
Trojan.DownLoader
7.1.1

Avira AntiVirus
TR/Rogue.1138176.3
8.3.1.6

Arcabit
Trojan.Generic.DDDC14B
1.0.0.425

Bitdefender
Trojan.Generic.14532939
1.0.20.775

Comodo Security
UnclassifiedMalware
22324

Dr.Web
Trojan.DownLoader11.64449
9.0.1.0155

Emsisoft Anti-Malware
Trojan.Generic.14532939
8.15.06.04.12

Fortinet FortiGate
W32/GenericR.DJZ!tr
6/4/2015

F-Secure
Trojan.Generic.14532939
11.2015-04-06_5

G Data
Trojan.Generic.14532939
15.6.25

IKARUS anti.virus
Trojan.Rogue
t3scan.1.9.5.0

McAfee
GenericR-DJZ!03EABB04344D
5600.6745

MicroWorld eScan
Trojan.Generic.14532939
16.0.0.465

NANO AntiVirus
Trojan.Win32.DownLoader11.dquknb
0.30.24.1636

nProtect
Trojan.Generic.14532939
15.06.02.01

Panda Antivirus
Trj/CI.A
15.06.04.12

Qihoo 360 Security
Win32/Trojan.463
1.0.0.1015

SUPERAntiSpyware
Trojan.Agent/Generic
9835

Trend Micro House Call
TROJ_GEN.R0C1C0PEG15
7.2.155

Trend Micro
TROJ_GEN.R0C1C0PEG15
10.465.04

VIPRE Antivirus
Trojan.Win32.Generic
40804

File size:
1.1 MB (1,138,176 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2010

Original file name:
Downloader.EXE

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\users\{user}\downloads\programs\conquer_v6075_p2p.exe

File PE Metadata
Compilation timestamp:
10/11/2014 9:19:31 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:BY2pSjUmFiCbp1RD1zE8auFv6rA9eU5wKxO:JzmFiC3RRzPawffwKw

Entry address:
0x694D3

Entry point:
E8, 01, 1C, 01, 00, E9, 78, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, A0, C4, 4B, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, A0, C4, 4B, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Entropy:
7.0240

Code size:
616 KB (630,784 bytes)

The file conquer_v6075_p2p.exe has been seen being distributed by the following URL.

Remove conquer_v6075_p2p.exe - Powered by Reason Core Security