global loader atualizado.exe

Software

The executable global loader atualizado.exe has been detected as malware by 26 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from fs05n2.sendspace.com.
Publisher:
Software

Product:
Software

Version:
1.0.0.0

MD5:
11b642cb9a44775ebbfa174bd1e48e43

SHA-1:
4e5303239a622836a81cc375e931a84e59b5fe46

SHA-256:
febcb5cdc5ce7ac957805114121da3708494ae8ad8fdd039b5d18401beea0c91

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
11/15/2024 9:50:10 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.144222
188

AegisLab AV Signature
Troj.W32.Generic!c
2.1.4+

Avira AntiVirus
TR/Dropper.Gen
8.3.3.4

Arcabit
Trojan.Zusy.D2335E
1.0.0.741

avast!
Win32:Malware-gen
2014.9-160730

AVG
MSIL10
2017.0.2666

Baidu Antivirus
Win32.Trojan.WisdomEyes.151026.9950
4.0.3.16730

Bitdefender
Gen:Variant.Zusy.144222
1.0.20.1060

Dr.Web
Trojan.Starter.2890
9.0.1.0212

Emsisoft Anti-Malware
Gen:Variant.Zusy.144222
8.16.07.30.06

ESET NOD32
MSIL/Injector.IFO (variant)
10.13679

Fortinet FortiGate
MSIL/Injector.NII!tr
7/30/2016

F-Secure
Packed:W32/DonutCrypt.A
11.2016-30-07_7

G Data
Gen:Variant.Zusy.144222
16.7.25

IKARUS anti.virus
Trojan.MSIL.Injector
t3scan.2.1.6.0

K7 AntiVirus
Trojan
13.230.19987

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-174

Malwarebytes
Trojan.Reconyc
v2016.07.30.06

McAfee
GenericRXAA-GV!11B642CB9A44
5600.6322

MicroWorld eScan
Gen:Variant.Zusy.144222
17.0.0.636

NANO AntiVirus
Trojan.Win32.Starter.edguno
1.0.38.8881

Panda Antivirus
Trj/CI.A
16.07.30.06

Qihoo 360 Security
QVM03.0.Malware.Gen
1.0.0.1120

Sophos
Troj/MSIL-FMQ
4.98

Vba32 AntiVirus
TScope.Trojan.MSIL
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
50278

File size:
91.3 KB (93,542 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2016

Original file name:
Software.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\global loader atualizado.exe

File PE Metadata
Compilation timestamp:
6/3/2016 2:13:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:bCQlgqVlOXZAH69qzZP1Fo22ZZtP9/ZRgvWBjGre6XaCQ/H/X/qc:FnVw0d98PLRgeBjGHaJffv

Entry address:
0xD5BE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, C7, BA, 51, 57, 00, 00, 00, 00, 02, 00, 00, 00, 1C, 01, 00, 00, 1C, E0, 00, 00, 1C, BA, 00, 00, 52, 53, 44, 53, 2D, 01, DA, 69, 85, 0D, 2F, 43, A8, 28, F7, 0C, E7, EF, EB, 71, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 63...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
45.5 KB (46,592 bytes)

The file global loader atualizado.exe has been seen being distributed by the following URL.

Remove global loader atualizado.exe - Powered by Reason Core Security