images.exe

The executable images.exe has been detected as malware by 15 anti-virus scanners. While running, it connects to the Internet address ip-160-153-47-192.ip.secureserver.net on port 21.
MD5:
5dee25e94aabb0d9d5569eab5de449e4

SHA-1:
39b21caae7b7b57d458f8d0b6b4fd0346468da7f

SHA-256:
37d9bdd19307f4620f88e269dfe9be5b94df226fd30fb3696419cb24849453c7

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
11/25/2024 12:43:10 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Fakon.N2117090762
3.7.5.15

Avira AntiVirus
TR/Blocker.fkhu
8.3.3.4

avast!
Win32:Malware-gen
2014.9-161026

AVG
Luhe.Fiha.E
2017.0.2579

Bkav FE
W32.Clod55f.Trojan
1.3.0.8383

G Data
Win32.Worm.Autorun.A@gen
16.10.25

Kaspersky
Trojan-Ransom.Win32.Blocker
14.0.0.-612

McAfee
Artemis!5DEE25E94AAB
5600.6235

Panda Antivirus
Generic Suspicious
16.10.26.11

Qihoo 360 Security
HEUR/QVM41.1.0000.Malware.Gen
1.0.0.1120

Rising Antivirus
Ransom.Blocker!8.12A-EAQ2PDf1CrF (cloud)
23.00.65.161024

Trend Micro House Call
Ransom_Blocker.R08NH0CIS16
7.2.300

Vba32 AntiVirus
Malware-Cryptor.Win32.General.4
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
52650

Zillya! Antivirus
Trojan.Blocker.Win32.35379
2.0.0.3071

File size:
5.5 MB (5,787,921 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
11/10/2008 2:40:35 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:H8/Te8kgMYsdMwHBFVY1/ql4qa8gOiQOjlfZgEYhI/pcDN0NdpRzIE02:c/68ceSy8CjjrgNhvN2/zIo

Entry address:
0x2C61

Entry point:
E8, 72, 03, 00, 00, E9, 36, FD, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, 00, 81, 38, 63, 73, 6D, E0, 75, 2A, 83, 78, 10, 03, 75, 24, 8B, 40, 14, 3D, 20, 05, 93, 19, 74, 15, 3D, 21, 05, 93, 19, 74, 0E, 3D, 22, 05, 93, 19, 74, 07, 3D, 00, 40, 99, 01, 75, 05, E8, C7, 03, 00, 00, 33, C0, 5D, C2, 04, 00, 68, 6B, 2C, 40, 00, FF, 15, 20, 40, 40, 00, 33, C0, C3, CC, FF, 25, 10, 41, 40, 00, 6A, 14, 68, 30, 42, 40, 00, E8, 5E, 02, 00, 00, FF, 35, A0, 66, 40, 00, 8B, 35, B0, 40, 40, 00, FF, D6, 59, 89, 45, E4, 83...
 
[+]

Entropy:
7.6630

Code size:
8.5 KB (8,704 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (FTP):
Connects to ip-160-153-47-192.ip.secureserver.net  (160.153.47.192:21)

TCP (HTTP):
Connects to ip-184-168-131-233.ip.secureserver.net  (184.168.131.233:80)

TCP (HTTP):
Connects to static.khi77.pie.net.pk  (221.120.207.34:80)

Remove images.exe - Powered by Reason Core Security