exclusive buyer agency agreement.exe

The executable exclusive buyer agency agreement.exe has been detected as malware by 24 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.alamls.info.
MD5:
8acb331804d181402ba2854e2027fb48

SHA-1:
cb926996f35f5963180c44efbdb97ef2154ed3c6

SHA-256:
1db236439bf8210ca5d86f3d4ed5dd4993a169da683b545a42005aab0fc6547a

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
12/27/2024 4:53:12 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.8610383
798

Agnitum Outpost
Trojan.Agent
7.1.1

Avira AntiVirus
TR/Rogue.8610383.6
7.11.99.136

avast!
Win32:Trojan-gen
2014.9-141113

AVG
Generic32
2015.0.3291

Bitdefender
Trojan.Generic.8610383
1.0.20.1585

Clam AntiVirus
Win.Trojan.8610383
0.98/21411

Dr.Web
Trojan.MulDrop4.16791
9.0.1.0317

Emsisoft Anti-Malware
Trojan.Generic.8610383
8.14.11.13.05

F-Prot
W32/GenTroj.BN.gen
v6.4.7.1.166

F-Secure
Trojan.Generic.8610383
11.2014-13-11_5

G Data
Trojan.Generic.8610383
14.11.22

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.2.0.127

K7 AntiVirus
Riskware
13.170.9438

McAfee
Artemis!8ACB331804D1
5600.6947

MicroWorld eScan
Trojan.Generic.8610383
15.0.0.951

NANO AntiVirus
Trojan.Win32.MulDrop4.cqjarb
0.28.6.63362

Norman
Suspicious_Gen2.VLOEM
11.20141113

nProtect
Trojan.Generic.8610383
14.11.13.01

Panda Antivirus
Trj/CI.A
14.11.13.05

Qihoo 360 Security
Malware.QVM07.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.11.28.14

Trend Micro House Call
TROJ_GEN.RC9H1AM
7.2.317

VIPRE Antivirus
Trojan.Win32.Generic
21034

File size:
652.5 KB (668,110 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\exclusive buyer agency agreement.exe

File PE Metadata
Compilation timestamp:
2/3/1998 8:58:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.2

CTPH (ssdeep):
12288:vihQBFOloBkG8/RnWvy9uNZVXBRkgAMoQ6rl5Xd5Nx8RtBq3aoH8UZa2/cHe1:viQQON8cvyQjXMNMul5t5NwcKo53/cO

Entry address:
0x21E0

Entry point:
55, 8B, EC, 6A, FF, 68, 00, 70, 40, 00, 68, B8, 41, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, C4, A8, 53, 56, 57, 89, 65, E8, FF, 15, 5C, 01, 41, 00, 33, D2, 8A, D4, 89, 15, 08, CD, 40, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 04, CD, 40, 00, C1, E1, 08, 03, CA, 89, 0D, 00, CD, 40, 00, C1, E8, 10, A3, FC, CC, 40, 00, E8, 44, 1E, 00, 00, 85, C0, 75, 0A, 6A, 1C, E8, 69, 01, 00, 00, 83, C4, 04, C7, 45, FC, 00, 00, 00, 00, E8, 0A, 10, 00, 00, E8, 15, 1E, 00, 00, FF, 15, 58, 01, 41...
 
[+]

Entropy:
7.9546

Developed / compiled with:
Microsoft Visual C++

Code size:
20.5 KB (20,992 bytes)

The file exclusive buyer agency agreement.exe has been seen being distributed by the following URL.

Remove exclusive buyer agency agreement.exe - Powered by Reason Core Security