ellinia.exe

Launcher

The executable ellinia.exe has been detected as malware by 18 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from maple.ellinia.net.
Product:
Launcher

Version:
1.1.5510.25468

MD5:
8e4b6cbe54436979bd72872ded7a5c84

SHA-1:
b8a47cc9d2cb45a5b6ae07bbd0fb89c807a91db2

SHA-256:
9e3c182388a7788e21130d88cc3860b67535e4a782bdf6c7a1f9cebe44cff72b

Scanner detections:
18 / 68

Status:
Malware

Analysis date:
12/27/2024 4:14:11 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12768551
717

Agnitum Outpost
Trojan.Agent
7.1.1

Avira AntiVirus
TR/Confuser.2647552.2
7.11.210.60

Baidu Antivirus
Hacktool.MSIL.Confuser
4.0.3.15217

Bitdefender
Trojan.Generic.12768551
1.0.20.240

Bkav FE
HW32.Packed
1.3.0.6379

Emsisoft Anti-Malware
Trojan.Generic.12768551
8.15.02.17.04

Fortinet FortiGate
W32/Generic!tr
2/17/2015

F-Secure
Trojan.Generic.12768551
11.2015-17-02_3

G Data
Trojan.Generic.12768551
15.2.25

K7 AntiVirus
Trojan
13.194.14969

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.2472

McAfee
Artemis!8E4B6CBE5443
5600.6851

MicroWorld eScan
Trojan.Generic.12768551
16.0.0.144

nProtect
Trojan.Generic.12768551
15.02.13.01

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R08OB01BE15
7.2.48

VIPRE Antivirus
Trojan.Win32.Generic
37574

File size:
2.5 MB (2,647,552 bytes)

Product version:
1.1.5510.25468

Original file name:
Redirector.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
2/1/2015 2:08:56 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:Jj2QYjkwXSM5PYi0AO8iw5fpnXC2qZCbLDagu1+aV5dgtvmaFN/9OTm1rto+W:n8kwrYi0d3wBJS2+Cbf3B85ddaz/9O6s

Entry address:
0x28C08A

Entry point:
FF, 25, 80, C0, 68, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9976  (probably packed)

Code size:
29 KB (29,696 bytes)

The file ellinia.exe has been seen being distributed by the following URL.

Remove ellinia.exe - Powered by Reason Core Security