Food.exe

Food

Product:
Food

Version:
1.0.0.0

MD5:
17aa5d8e241d7f7068371615a6cc02d4

SHA-1:
81867eb487f93cf46d602374ae2fb2b0e4e6bc98

SHA-256:
2ea9cd3389da3478cd04444b50f9a3f0cbc026236b7e5e56c8727cdfad07dfdb

Scanner detections:
7 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/23/2024 2:35:51 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
UnclassifiedMalware
21733

McAfee
Artemis!17AA5D8E241D
5600.6708

Norman
Suspicious_Gen2.VXACO
11.20150710

Qihoo 360 Security
Win32/Trojan.Dropper.c9f
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R002C0OIR14
7.2.191

Trend Micro
TROJ_GEN.R002C0OIR14
10.465.10

VIPRE Antivirus
Trojan.Win32.Generic
39258

File size:
22 KB (22,528 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
Food.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\food\food.exe

File PE Metadata
Compilation timestamp:
5/31/2014 10:47:50 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:oe93786tZQffshfEqjjLf45QxgybQffK8qo59aNk:oyL86PmQE8XAWU9qk

Entry address:
0x635E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.1619

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
17 KB (17,408 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to parkingpage.namecheap.com  (198.54.117.212:80)

Scan Food.exe - Powered by Reason Core Security