instaboost.exe

{Emissary} NET

SmartFTP Client

The executable instaboost.exe has been detected as malware by 13 anti-virus scanners.
Publisher:
{Emissary} Solutions  (signed by SmartFTP Client)

Product:
{Emissary} NET

Description:
netClient

Version:
1.0.0.0

MD5:
33f8ed160166c2c6bef45cd1fc90b524

SHA-1:
a658489118255883f5db22660262e8b49adc3ec3

SHA-256:
13e26868ed2e285c4f706d8b342c738a2e7a41d4eb00e6dfe2683195d7fba35e

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
1/13/2025 6:41:26 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.10207882
873

avast!
Win32:Malware-gen
2014.9-140914

Bitdefender
Trojan.Generic.10207882
1.0.20.1285

Comodo Security
UnclassifiedMalware
18373

Emsisoft Anti-Malware
Trojan.Generic.10207882
8.14.09.14.09

ESET NOD32
MSIL/Troob.AA (variant)
8.9867

F-Secure
Trojan.Generic.10207882
11.2014-14-09_1

G Data
Trojan.Generic.10207882
14.9.24

McAfee
Artemis!33F8ED160166
5600.7007

MicroWorld eScan
Trojan.Generic.10207882
15.0.0.771

NANO AntiVirus
Trojan.Win32.Troob.cuficx
0.28.0.59921

nProtect
Trojan.Generic.10207882
14.05.29.01

Qihoo 360 Security
Win32/Trojan.Spy.8d0
1.0.0.1015

File size:
174.2 KB (178,392 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © {Emissary} Solutions 2013

Original file name:
netClient.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\instaboost.exe

Digital Signature
Signed by:

Authority:
SmartFTP Client

Valid from:
7/30/2013 1:22:01 PM

Valid to:
7/30/2113 1:22:00 PM

Subject:
CN=SmartFTP Client

Issuer:
CN=SmartFTP Client

Serial number:
1DBAED5705BF9C8A4450EF065372A411

File PE Metadata
Compilation timestamp:
8/27/2013 6:19:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:jbvAtWXcydoCyPlagAb6dXs75wLEj8hV0vpHkbffepI1zkkhH:jbvAtzy3yPlap6daYj0vSbffepjC

Entry address:
0x2B84E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.0227

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
166.5 KB (170,496 bytes)

Remove instaboost.exe - Powered by Reason Core Security