f_0067b7

Vkontakte DJ Installer

The file f_0067b7 has been detected as a potentially unwanted program by 6 anti-malware scanners. The file has been seen being downloaded from downloadmusicapp.eu and multiple other hosts.
Product:
Vkontakte DJ Installer

Version:
1.9.1.24

MD5:
3893bd2ec6d39215cd0b55eca28855fe

SHA-1:
a89dae3b529484162ab30c046a6cd02de9cd4a94

SHA-256:
bcbe40b0284fa2e3c184e83f9e599dc7d49b110d1bf2901fa5d04eb2ca831dca

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 6:53:52 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
PUA.MSIL.VKontakteDJ
4.0.3.151115

ESET NOD32
MSIL/VKontakteDJ.A potentially unwanted (variant)
9.12567

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1117

McAfee
Artemis!3893BD2EC6D3
5600.6580

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1077

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.151113

File size:
563.5 KB (577,024 bytes)

Product version:
1.9.1.24

Copyright:
Copyright © 2015

Original file name:
DjLoader.exe

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\temp\webkit\cache\f_0067b7

File PE Metadata
Compilation timestamp:
11/10/2015 1:18:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:TInBtFt4P7qsKQ0jnAt4BknkA3F2n0dscYBtFC:8nJt4DBKQ0jnpBknk62istJC

Entry address:
0x6AF4E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.4969

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
420 KB (430,080 bytes)

The file f_0067b7 has been seen being distributed by the following 50 URLs.

http://downloadmusicapp.eu/.../ZWMwMDAxMDBiNDAwMDMzZTAwMDAwMzRiMDAwMzRiMDAwMzRiMTdhNDhmMWNiYw==?name=Viennese waltz ( Walc Wiedenski - Studniówka Staszic, Biala Podlaska 2015 ).mp3

http://downloadmusicapp.eu/.../ZWMwMDAxMDBiNDAwMDMzZTAwMDAwMzRiMDAwMzRiMDAwMzRiMTdhNDhmMWNiYw==?name=D.masta - ??? ???????? ft. Booguy, Yanix [????? ???].mp3

http://downloadmusicapp.eu/.../ZWMwMDAxMDBiNDAwMDMzZTAwMDAwMzRiMDAwMzRiMDAwMzRiMTdhNDhmMWNiYw==?name=?????????-??????? ????? - ?????, ??-??-??, ?????.mp3

http://downloadmusicapp.eu/.../ZWMwMDAxMDBiNDAwMDMzZTAwMDAwMzRiMDAwMzRiMDAwMzRiMTdhNDhmMWNiYw==?name=Criolo & LCD Soundsystem - SP, I Love You But You're Bringing Me Down (Bertazi Mashup).mp3

http://downloadmusicapp.eu/.../ZWMwMDAxMDBiNDAwMDMzZTAwMDAwMzRiMDAwMzRiMDAwMzRiMTdhNDhmMWNiYw==?name=Eric Burdon - Rat Race.mp3

http://downloadmusicapp.eu/.../ZWMwMDAxMDBiNDAwMDMzZTAwMDAwMzRiMDAwMzRiMDAwMzRiMTdhNDhmMWNiYw==?name=??? ???? ? ?????? ????? - Sharazan.mp3

http://downloadmusicapp.eu/.../ZWMwMDAxMDBiNDAwMDMzZTAwMDAwMzRiMDAwMzRiMDAwMzRiMTdhNDhmMWNiYw==?name=Kana Hanazawa - Yuki ni Saku Hana (Shinsekai Yori ED2).mp3

http://downloadmusicapp.eu/arplit/.../?: ?????? 3 - May laif b? laik wap kengu.mp3

http://downloadmusicapp.eu/.../ZWMwMDAxMDBiNDAwMDMzZTAwMDAwMzRiMDAwMzRiMDAwMzRiMTdhNDhmMWNiYw==?name=Supuldziesma - Sesas Peles Miegu Vilka.mp3

http://downloadmusicapp.eu/.../ZWMwMDAxMDBiNDAwMDMzZTAwMDAwMzRiMDAwMzRiMDAwMzRiMTdhNDhmMWNiYw==?name=?. ?????????? - ???????? ?5 - ????.mp3

http://downloadmusicapp.eu/.../ZWMwMDAxMDBiNDAwMDMzZTAwMDAwMzRiMDAwMzRiMDAwMzRiMTdhNDhmMWNiYw==?name= Marisa Monte - Eu nao sou da sua rua — ????????? ??????? MP3 ????? ? 320 kbps # freeMP3now .mp3

Latest 30 of 54 download URLs

Remove f_0067b7 - Powered by Reason Core Security