irsengine.exe

Integrated Reload System

PT.Aviana Sinar Abadi

The executable irsengine.exe has been detected as malware by 10 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from dc357.4shared.com.
Publisher:
PT.Aviana Sinar Abadi

Product:
Integrated Reload System

Description:
Engine

Version:
6.0.0.0

MD5:
9c3b83ef0f34d6ceba0a81dbc50a37bc

SHA-1:
77ea6934e2d5d2aead88a957a104a4e12b2964c0

SHA-256:
5950d7fa3c1a3168b27651e2a37c3bc955bc6802629d46a5c9bac230b531f936

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
12/29/2024 6:46:15 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160518-2

AVG
Win32/Sality
2015.0.4604

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.E.gen
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.2949.0

Norman
Win32.Sality.3
22.05.2016 07:18:28

VIPRE Antivirus
Threat.4721115
50324

File size:
1.2 MB (1,237,504 bytes)

Product version:
5.0

Trademarks:
IRS

File type:
Executable application (Win32 EXE)

Language:
Indonesian (Indonesia)

Common path:
C:\users\{user}\downloads\irsengine.exe

File PE Metadata
Compilation timestamp:
2/28/2016 9:57:06 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:i/Y/UKlzc2qKrgP7ptktR/ep4aNEUtme5BCx/OsBEO/QIznlyYGnr:iwdK4reaR7a6ScVOO/Bzly1r

Entry address:
0x1000

Entry point:
60, 69, DD, 0E, B8, 00, 4F, 8D, 3D, F5, 2E, C9, 49, 8D, 1D, AE, C2, 6D, B9, 81, FE, ED, 81, 00, 00, 72, 0A, B6, AC, 12, E0, 69, F0, 26, F6, 0F, C9, 3D, 18, 94, 00, 00, 72, 0B, 0A, D1, 69, FD, CF, 70, 9A, 84, 0F, AF, C7, 2A, F7, F2, 3D, B7, F5, B8, 73, F6, C6, 7C, F3, 0F, BF, F9, 70, 08, 8A, E3, 8D, 35, 33, 0F, D4, C0, 0F, AF, FF, 80, D1, 5F, 10, E0, EB, 03, C6, C4, 8B, 8A, EC, F3, C7, C0, 76, 01, 50, 96, 8D, 7D, 00, 09, E8, F2, 2B, F6, 86, E8, 8D, 0D, 0B, 84, 4B, DF, F6, C7, B7, 0F, C1, FE, C7, C1, E7, 93...
 
[+]

Code size:
2.9 MB (3,043,328 bytes)

The file irsengine.exe has been seen being distributed by the following URL.

Remove irsengine.exe - Powered by Reason Core Security