hahaha.exe

The executable hahaha.exe has been detected as malware by 2 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www12.speedyshare.com.
MD5:
95fb82fb65b092d7ee9a89f5cc3797a1

SHA-1:
153f6bb1735d816ead2ae365a58a3a4e35d90a2f

SHA-256:
0b00a7f6c57b7b31af88480237108fd01454a2db82df6b90a1aabbb543d5f47f

Scanner detections:
2 / 68

Status:
Malware

Analysis date:
12/26/2024 3:14:27 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
VBS/HackTool.Skype.B trojan
8.0.319.0

F-Prot
W32/Trojan2.NTOP
4.6.5.141

File size:
248.5 KB (254,464 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\hahaha.exe

File PE Metadata
Compilation timestamp:
1/12/2011 4:07:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:DQB8OI6NmOa/aK/EdlNcNdZye6DxQA0vOcYY4DfNT+ak1qrd/rP:DQB8OIua/aK/rZ36DxzHfNTb

Entry address:
0xCB10

Entry point:
55, 8B, EC, 81, EC, B4, 03, 00, 00, 56, 6A, 00, FF, 15, 8C, 10, 41, 00, 89, 85, 8C, FE, FF, FF, C7, 85, A0, FE, FF, FF, 00, 00, 00, 00, C7, 45, F8, 01, 00, 00, 00, C7, 85, B8, FE, FF, FF, 00, 00, 00, 00, FF, 15, EC, 10, 41, 00, A3, 70, 68, 41, 00, 68, 04, 01, 00, 00, 68, B8, 6E, 41, 00, 6A, 01, 8B, 85, 8C, FE, FF, FF, 50, FF, 15, 8C, 11, 41, 00, 6A, 08, 68, 9C, 6C, 41, 00, 6A, 11, 8B, 8D, 8C, FE, FF, FF, 51, FF, 15, 8C, 11, 41, 00, 68, C8, 00, 00, 00, 8D, 95, C0, FE, FF, FF, 52, 68, 9C, 6C, 41, 00, E8, FD...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
63 KB (64,512 bytes)

The file hahaha.exe has been seen being distributed by the following URL.

Remove hahaha.exe - Powered by Reason Core Security