imo free video calls and chat for pc.exe

The executable imo free video calls and chat for pc.exe has been detected as malware by 1 anti-virus scanner. The file has been seen being downloaded from a.allstate-final.xyz.
MD5:
7c7f1fcfe289064c528a08f150b013a9

SHA-1:
4c7b401e836e595c23c45acdf4c35a6635dd93fd

SHA-256:
486c3fc96fa40670d122b76b453104100614c577c7a23ca9bd8b9eba709f1f72

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/27/2024 3:00:22 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.7.17.17

File size:
376 KB (385,024 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\imo free video calls and chat for pc.exe

File PE Metadata
Compilation timestamp:
11/29/2012 6:52:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:IL0aAN0oTEvOiNt5JJR55qGBZpw3a/ov/AEd5WqL41GIzmvZE2y6q6H4Fe/VyFXZ:80RC+a1Nt5JJDZUa/oQhqOXL

Entry address:
0x1E76B

Entry point:
E8, 54, 12, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 60, B3, 43, 00, E8, 5F, 17, 00, 00, E8, 21, 14, 00, 00, 0F, B7, F0, 6A, 02, E8, E7, 11, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, C8, 0B, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.1712

Code size:
142 KB (145,408 bytes)

The file imo free video calls and chat for pc.exe has been seen being distributed by the following URL.

Remove imo free video calls and chat for pc.exe - Powered by Reason Core Security