download.exe

The application download.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.onlinemidia.com and multiple other hosts.
Version:
1.0.0.0

MD5:
f36203921909bbe2abe585e69613ce86

SHA-1:
4a4de1a877a5cb800c637bf97cfd7de668e3f036

SHA-256:
e6fe04e0f6e671e8cdaafef4426e9c54522922a8531d460204cac36511703c11

Scanner detections:
10 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 8:37:30 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen2
7.11.63.24

avast!
MSIL:Downloader-JC [PUP]
2014.9-160519

AVG
AdInstaller.R
2017.0.2739

Bitdefender
Trojan.Generic.KDZ.9374
1.0.20.700

ESET NOD32
MSIL/Adware.PCMega (variant)
10.8058

F-Secure
Trojan.Generic.KDZ.9374
11.2016-19-05_5

G Data
Trojan.Generic.KDZ.9374
16.5.22

Kaspersky
Trojan-Ransom.Win32.Foreign
14.0.0.189

Malwarebytes
MSIL.Downloader
v2016.05.19.06

MicroWorld eScan
Trojan.Generic.KDZ.9374
17.0.0.420

File size:
21 KB (21,504 bytes)

Product version:
1.0.0.0

Original file name:
hBfEOIzFzigsneBQyzaW.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\download.exe

File PE Metadata
Compilation timestamp:
2/26/2013 6:10:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:r8HkuhFeRm41De1y98U1ookQ7MuRVV/Wi/+ZtYRRBuYJOdTNeLNek+vD:muR5w9g/+ORBuzd

Entry address:
0x54AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
13.5 KB (13,824 bytes)

The file download.exe has been seen being distributed by the following 2 URLs.

http://www.onlinemidia.com/ids/.../download.exe

Remove download.exe - Powered by Reason Core Security