DeadLine's Virus Maker.exe

DeadLine's Virus Maker

DeadLine

The application DeadLine's Virus Maker.exe has been detected as a potentially unwanted program by 27 anti-malware scanners. While running, it connects to the Internet address no.rdns.ukservers.com on port 80 using the HTTP protocol.
Publisher:
DeadLine

Product:
DeadLine's Virus Maker

Version:
1.8.5.0

MD5:
aec98da277da67285829908de6b895ae

SHA-1:
240caca0d54f87746aee4abf10a6a44e5446f1bc

SHA-256:
53665a003591561734012c2a0664d6c568e5c3c9e4f6c1a8c3b8093f042f7ad5

Scanner detections:
27 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 4:31:06 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Heur.Bodegun.1
524

Agnitum Outpost
Trojan.Llac
7.1.1

Avira AntiVirus
TR/Llac.cvgi.2
8.3.1.6

Arcabit
Trojan.Bodegun.1
1.0.0.425

avast!
Win32:PUP-gen [PUP]
2014.9-150829

Baidu Antivirus
Trojan.MSIL.Binder
4.0.3.15829

Bitdefender
Gen:Heur.Bodegun.1
1.0.20.1205

Clam AntiVirus
WIN.Trojan.Agent-341572
0.98/21511

Comodo Security
UnclassifiedMalware
22681

Dr.Web
Trojan.DownLoader6.52335
9.0.1.0241

Emsisoft Anti-Malware
Gen:Heur.Bodegun
8.15.08.29.09

ESET NOD32
MSIL/TrojanDropper.Binder.AU (variant)
9.11894

Fortinet FortiGate
W32/Llac.CVGI!tr
8/29/2015

F-Secure
Gen:Heur.Bodegun.1
11.2015-29-08_7

G Data
Gen:Heur.Bodegun
15.8.25

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.9.5.0

Kaspersky
Trojan.MSIL.Agent
14.0.0.1506

Malwarebytes
Hacktool.Builder
v2015.08.29.09

McAfee
Artemis!AEC98DA277DA
5600.6658

MicroWorld eScan
Gen:Heur.Bodegun.1
16.0.0.723

NANO AntiVirus
Trojan.Win32.Llac.bbpzzh
0.30.24.2320

nProtect
Trojan/W32.Llac.1604096
15.07.03.02

Qihoo 360 Security
Win32/Trojan.629
1.0.0.1015

Quick Heal
Trojan.MSI.g4
8.15.14.00

Trend Micro
TROJ_GEN.R047C0ELK14
10.465.29

Vba32 AntiVirus
Trojan.MSIL.Agent
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
41758

File size:
1.5 MB (1,604,096 bytes)

Product version:
1.8.5.0

Copyright:
Copyright © DeadLine 2012

Original file name:
DeadLine's Virus Maker.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\deadline's virus maker.exe

File PE Metadata
Compilation timestamp:
10/8/2012 1:14:32 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:W3CP4HQSclGq2OVo/Dpnv8wlV4tDLi8OV:W3CP4HQSclGq2O+7pnvflV41i8O

Entry address:
0x1597EE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 02, 03, 04, 05, 06, 07, 08, 09, 01, 02, 03, 04, 05, 06, 07, 07, 06, 05, 04, 03, 02, 01, 09, 08, 07, 06, 05, 04, 03, 02, 01, 70, D6, DC, 0F, 89, 7A, 87, C3, 50, 33, 2F, A9, 2D, B6, E6, 7D, 7D, C3, E4, F4, B6, BA, FD, F6, 8F, 92, C9, DE, E6, AC, 8D, FD, AF, B1, DF, 6A, D3, 08, 5B, AA, 55, E0, 4E, 54, 4E, DD, C3, C9, 52, 66, 68, 6E, 20, 4D, 18, 22, 76, B5, 33, 11, 12, 33, 0C, 6D, 0A, 20, 4D, 18, 22, 9E, A1, 29, 61, 1C, 76, B5, 05, 19...
 
[+]

Entropy:
6.5393

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.3 MB (1,406,976 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to no.rdns.ukservers.com  (94.229.72.116:80)

Remove DeadLine's Virus Maker.exe - Powered by Reason Core Security