LeagueIP.exe

LeagueIP

The executable LeagueIP.exe has been detected as malware by 16 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dc598.4shared.com and multiple other hosts.
Product:
LeagueIP

Version:
1.0.0.0

MD5:
00bc1983e766d7940ec10f93e2756f05

SHA-1:
34e4a24e1515065c41620e4156b4d53fdf29b5f4

SHA-256:
bfc45829ecfd942c26e44cd8991acb1a5675d2c01780fecb0e56d4d2a4327e6a

Scanner detections:
16 / 68

Status:
Malware

Analysis date:
11/16/2024 11:26:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.14680535
599

Avira AntiVirus
TR/Agent.240640.80
8.3.1.6

Arcabit
Trojan.Generic.DE001D7
1.0.0.425

avast!
Win32:Malware-gen
2014.9-150616

Bitdefender
Trojan.Generic.14680535
1.0.20.835

Dr.Web
Trojan.DownLoader13.14668
9.0.1.0167

Emsisoft Anti-Malware
Trojan.Generic.14680535
8.15.06.16.08

F-Secure
Trojan.Generic.14680535
11.2015-16-06_3

G Data
Trojan.Generic.14680535
15.6.25

IKARUS anti.virus
Trojan.Agent
t3scan.1.9.5.0

McAfee
Artemis!00BC1983E766
5600.6733

MicroWorld eScan
Trojan.Generic.14680535
16.0.0.501

nProtect
Trojan.Generic.14680535
15.06.15.01

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R08OH09FE15
7.2.167

VIPRE Antivirus
Trojan.Win32.Generic
41174

File size:
235 KB (240,640 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
LeagueIP.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
4/22/2015 9:32:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:xMNydmrM27Uv/R0UcgMu82Yxz1Ti1DkHiI2drbQz2P3Pa:WNyp/HL582Yxz1Ti1DkHihbo

Entry address:
0x873E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
26 KB (26,624 bytes)

The file LeagueIP.exe has been seen being distributed by the following 2 URLs.

Remove LeagueIP.exe - Powered by Reason Core Security