ferramentas e crypter vb6_vb.net.exe

The executable ferramentas e crypter vb6_vb.net.exe has been detected as malware by 27 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download2034.mediafire.com.
MD5:
770e5e0fe20aa7e05a5077d3db4ca5ea

SHA-1:
9b4a7098f81ac29616f6c0ea007e83e0eeddba7c

SHA-256:
43a344d0cf49854c034cf6cf43726279e9f09b42f47d03a24e8bca319e628dfb

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
12/26/2024 5:40:58 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.18617
892

Agnitum Outpost
Trojan.Agent
7.1.1

Avira AntiVirus
TR/Dropper.VB.Gen
7.11.166.78

avast!
Win32:Inject-ATA [Trj]
2014.9-140827

AVG
Dropper.Generic8
2015.0.3370

Baidu Antivirus
Trojan.Win32.VBKrypt
4.0.3.14827

Bitdefender
Gen:Variant.Symmi.18617
1.0.20.1195

Comodo Security
UnclassifiedMalware
19134

Dr.Web
Trojan.MulDrop3.16541
9.0.1.0239

Emsisoft Anti-Malware
Gen:Variant.Symmi.18617
8.14.08.27.07

ESET NOD32
Win32/Injector.ANCQ (variant)
8.10230

F-Prot
W32/VB.HE.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Symmi.18617
11.2014-27-08_4

G Data
Gen:Variant.Symmi.18617
14.8.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.6.1.0

K7 AntiVirus
Riskware
13.183.12998

Kaspersky
Trojan.Win32.VBKrypt
14.0.0.3344

Malwarebytes
Trojan.Refroso
v2014.08.27.07

Microsoft Security Essentials
Worm:Win32/Vobfus.gen!D
1.10802

MicroWorld eScan
Gen:Variant.Symmi.18617
15.0.0.717

NANO AntiVirus
Trojan.Win32.Vobfus.koceb
0.28.2.61349

nProtect
Trojan.Generic.KDV.183915
14.08.08.01

Quick Heal
Trojan.VB.g3
8.14.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.15213447!354497607
23.00.65.14825

Sophos
Mal/Generic-S
4.98

Vba32 AntiVirus
Trojan.VB.Levelup
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
32078

File size:
1.5 MB (1,579,446 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ferramentas e crypter vb6_vb.net.exe

File PE Metadata
Compilation timestamp:
12/17/2010 2:14:10 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:zZjlxO6FGTay3IA5cHqW2IG1S0a8NBxYwv6v:zZJxO6FGOBAyfpG1SR8NBfM

Entry address:
0xB2EC

Entry point:
E8, E3, FE, FF, FF, 33, C0, 50, 50, 50, 50, E8, 42, 2D, 00, 00, C3, 56, 57, 8B, 7C, 24, 0C, 8B, F1, 8B, CF, 89, 3E, E8, EE, A1, FF, FF, 89, 46, 08, 89, 56, 0C, 8B, 87, 1C, 0C, 00, 00, 89, 46, 10, 5F, 8B, C6, 5E, C2, 04, 00, 8B, C1, 8B, 08, 8B, 50, 10, 3B, 91, 1C, 0C, 00, 00, 75, 0D, 6A, 00, FF, 70, 0C, FF, 70, 08, E8, 01, A7, FF, FF, C3, 55, 8B, EC, 83, EC, 1C, 56, 33, F6, 56, 56, 56, 56, 8D, 45, E4, 50, FF, 15, 48, 32, 41, 00, 85, C0, 74, 21, 56, 56, 56, 8D, 45, E4, 50, FF, 15, 4C, 32, 41, 00, 8D, 45, E4...
 
[+]

Code size:
70 KB (71,680 bytes)

The file ferramentas e crypter vb6_vb.net.exe has been seen being distributed by the following URL.

Remove ferramentas e crypter vb6_vb.net.exe - Powered by Reason Core Security