extreme loader.exe

The executable extreme loader.exe has been detected as malware by 13 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.dosya.tc.
MD5:
a1288c50f0de018698374d8fd6dc532d

SHA-1:
b041d4fb73857f00ac03058861ea7b9735395b18

SHA-256:
3b5c2b501e0b0d8ffec454388b0658e16e6a5394b7554b9a555a0f62b890e425

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
11/27/2024 1:19:20 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Black.Gen2
8.3.2.4

avast!
Win32:Malware-gen
151228-1

AVG
Win32/Blacked
2015.0.4489

Bkav FE
HW32.Packed
1.3.0.7400

Emsisoft Anti-Malware
Trojan.Generic.15558865
10.0.0.5366

ESET NOD32
Win32/Packed.VMProtect.ABO trojan
7.0.302.0

F-Secure
Trojan.Generic.15558865
5.05.7110

McAfee
Trojan.Artemis!A1288C50F0DE
18.0.204.0

Norman
Trojan.Generic.15558865
05.01.2016 05:35:50

Qihoo 360 Security
HEUR/QVM16.0.Malware.Gen
1.0.0.1077

Quick Heal
(Suspicious) - DNAScan
1.16.14.00

Sophos
Virus 'Mal/VMProtBad-A'
5.22

VIPRE Antivirus
Threat.4150696
46110

File size:
901.5 KB (923,136 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\prohile\wolfextreme\extreme loader.exe

File PE Metadata
Compilation timestamp:
1/5/2016 3:25:42 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:bs1JBe65P37xWTx3j2Ydg0BVgfOInfZLIt8hkH3Ey:bs1K6FxWTpjLdPBVF+fZLIyhkHU

Entry address:
0xF1A75

Entry point:
9C, C7, 04, 24, 9C, 65, C5, 86, E8, 4D, C5, 0C, 00, 43, 55, 4A, 41, 72, A5, 92, 51, 6E, 61, 75, AD, 6E, 31, B2, 65, 2A, 61, 1A, 71, 82, B0, 17, 00, 57, 34, 7F, 0C, 5F, 2C, 7B, 10, 7F, 0C, 63, 28, 7F, 98, 47, 5E, F1, 3A, 61, 3E, 16, E4, CB, 2C, F2, 87, 07, 1A, CA, 51, 28, C4, FD, F9, 74, B8, E7, 64, 9B, 25, 82, 45, 8B, B0, 1B, 14, 63, AB, FC, 3B, FA, FE, 88, FF, 5A, F2, 25, AF, FB, A4, F3, 98, 37, FC, E5, F6, 73, C5, 70, 46, 6B, 25, 9F, 00, 67, 24, AB, 4B, 9F, BD, 97, 95, BB, 99, 75, 40, 73, 6D, EA, 16, 15...
 
[+]

Code size:
48.5 KB (49,664 bytes)

The file extreme loader.exe has been seen being distributed by the following URL.

Remove extreme loader.exe - Powered by Reason Core Security