force+op+1.8.9.exe

ƒÿ驼æÁ³æÙ«¾àÃ

The executable force+op+1.8.9.exe has been detected as malware by 2 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from api.ge.tt.
Product:
ƒÿ驼®æÁ³æÙ«¾àÃ

Version:
1.00

MD5:
929482f5a99a69da170ccdbcab41dd5b

SHA-1:
60188741e51b0fcba19c099113e91d582e58fa16

SHA-256:
903c03f1c606f95ee36e6816dc9d1985cb54f469680959cea77480a5045ed5a9

Scanner detections:
2 / 68

Status:
Malware

Analysis date:
12/27/2024 5:30:08 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160518-2

ESET NOD32
Win32/Injector.CLZV trojan
8.0.319.0

File size:
744 KB (761,856 bytes)

Product version:
1.00

Original file name:
3.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\force+op+1.8.9.exe

File PE Metadata
Compilation timestamp:
10/27/2015 3:30:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:Q7nhFtw/hbfZBFPfaAtbykAYDHfYzrtAqaEpLPZVV+RV5C613SEvrwGiOdopn5Sq:ojakScK6gQVw06NSETikopn5SZqP4c9f

Entry address:
0x1100

Entry point:
68, 8C, 2B, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 6A, F4, DB, 41, 30, 36, E2, 43, BC, FE, F7, B8, 70, 18, 52, 55, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, CC, F4, FC, FF, D5, F6, 83, FF, E9, A9, BC, AE, E6, C1, B3, E6, D9, AB, BE, E0, C3, 00, 00, 00, 00, 00, FF, CC, 31, 00, 00, 79, 6F, BB, 44, B2, 80, D3, 43, A2, 75, 5B, AC, B9, 01, 85, FA, CF, 40, 20, 10, 9F, 8A, 69, 4D, BA, 06, FA, 49, E8, 66, B9, 67, 72, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
72 KB (73,728 bytes)

The file force+op+1.8.9.exe has been seen being distributed by the following URL.

Remove force+op+1.8.9.exe - Powered by Reason Core Security