doulci server 2014.exe

Update

This is a setup program which is used to install the application. The file has been seen being downloaded from dc364.4shared.com.
Product:
Update

Version:
1.0.0.0

MD5:
c1a072f1044804a8eae0c5299b133d39

SHA-1:
7bcfa2f61d470546e9e052732f6f964cb20348ea

SHA-256:
86ba12cf3801282f715c2ff512c72651b27695107c7644c9c3e3174e6ac29b6e

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/16/2024 12:54:15 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
150414-0

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.2017

File size:
3.1 MB (3,250,586 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
Update.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\doulci server 2014.exe

File PE Metadata
Compilation timestamp:
10/21/2014 6:35:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:CfG5w+tS76UwzQJQWtkhMuFqELk24jXPlra3XECjDec68R:dWz6LQJQqYgI2XPXA

Entry address:
0x5DEE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 45, 99, 46, 54, 00, 00, 00, 00, 02, 00, 00, 00, 1C, 01, 00, 00, 1C, 60, 00, 00, 1C, 42, 00, 00, 52, 53, 44, 53, 2D, C9, 26, 17, 76, 08, FE, 4C, 86, 2F, 1E, 93, E1, 4C, B0, D6, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 58, 62, 6F, 78, 5C, 44, 6F, 63, 75, 6D, 65, 6E, 74, 73, 5C, 56, 69, 73, 75, 61, 6C, 20, 53, 74, 75, 64, 69, 6F, 20, 32, 30, 31, 32, 5C, 50, 72, 6F, 6A, 65, 63, 74, 73, 5C, 55, 70, 64, 61, 74, 65...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
15.5 KB (15,872 bytes)

The file doulci server 2014.exe has been seen being distributed by the following URL.

Scan doulci server 2014.exe - Powered by Reason Core Security