death quick.exe

The application death quick.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dc219.4shared.com and multiple other hosts.
MD5:
9f2b5beb726cf32a53650e7ab30c7a33

SHA-1:
6ed3ca8c3dc8ff96b507bf757591a345a42b4ecd

SHA-256:
9e0e8d0417fe26298acd8c13df31e5579a9c09afef829986f85bac4e364a7f40

Scanner detections:
21 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 7:40:24 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.HackTool
7.1.1

Avira AntiVirus
SPR/Injecter.aiq.1
3.6.1.96

AVG
HackTool
2016.0.3055

Baidu Antivirus
Hacktool.Win32.Injecter
4.0.3.1577

Comodo Security
UnclassifiedMalware
22069

Dr.Web
Trojan.Hosts.5690
9.0.1.0188

IKARUS anti.virus
HackTool.Win32.Injecter
t3scan.1.8.9.0

K7 AntiVirus
Riskware
13.203.15861

Kaspersky
HackTool.Win32.Injecter
14.0.0.1772

McAfee
Artemis!9F2B5BEB726C
5600.6711

NANO AntiVirus
Trojan.Win32.Injecter.pdueh
0.30.24.1357

Norman
Suspicious_Gen4.PGGD
11.20150707

nProtect
Trojan/W32.Agent.858624.AH
15.05.08.01

Panda Antivirus
Generic Malware
15.07.07.12

Qihoo 360 Security
Win32/Trojan.Hacktool.020
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.8.2.10

Rising Antivirus
PE:Trojan.Win32.Generic.12B55740!313874240
23.00.65.15705

Sophos
Generic PUA GO
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Frauc
9768

VIPRE Antivirus
Trojan.Win32.Generic
40116

Zillya! Antivirus
Tool.Injecter.Win32.402
2.0.0.2174

File size:
838.5 KB (858,624 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\death quick.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:xQA35FCg9tQT1poqFJ8AYvCBJOMHOTWL:xQAf8jJ8bKJOMHOTWL

Entry address:
0x1000

Entry point:
B8, 68, C8, 65, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 13, 5F, AC, 93, F6, DA, 0E, 4A, 3E, 62, 1D, 64, 84, 49, A8, 0C, 99, B2, F5, 69, 35, D4, 52, AF, E7, 82, B9, EB, DF, 2D, 10, 58, 9D, 2C, 53, 6F, DB, B4, BA, 04, CA, 57, 70, 2E, 65, 41, 62, 6B, E6, C4, 11, E3, A8, C2, 37, 69, F9, 84, 10, 02, 10, 38, 78, 14, 89, CE, DD, 95, 1C, 6A, FB, B9, 12, 6F, 24, BF, 66, E3, AD, 8E, 1C, 65, AF, 58, 61, ED, 98, BE, 0D, D1, 15, C9, 83...
 
[+]

Packer / compiler:
PECompact v2

Code size:
1013.5 KB (1,037,824 bytes)

The file death quick.exe has been seen being distributed by the following 7 URLs.

http://dc219.4shared.com/download/.../Death_Quick.exe

http://dc386.4shared.com/download/.../death_quick.exe

Remove death quick.exe - Powered by Reason Core Security