lft-575558cdc54596e4ce425977463d7618-1463611450.exe

The executable lft-575558cdc54596e4ce425977463d7618-1463611450.exe has been detected as malware by 5 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from urldefense.proofpoint.com.
Version:
0.0.0.0

MD5:
75afd496a0fa6720cec0cece48205841

SHA-1:
94eae061090edf205333e9beb0b2d24efa5ed047

SHA-256:
a3131337c9de072e5d161b5e02302c663fc83a362ccbedb75ff5cc899e617c0f

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
11/15/2024 6:26:26 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160414-2

Emsisoft Anti-Malware
Gen:Variant.Kazy.54677
11.5.0.6191

Norman
Gen:Variant.Kazy.54677
19.05.2016 05:17:13

VIPRE Antivirus
Threat.4150696
48772

File size:
291.2 KB (298,176 bytes)

Product version:
0.0.0.0

Original file name:
CFBS.dll

File type:
Executable application (Win64 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
6/9/2011 7:28:51 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:2TdopLUgNcYLup/Xk+JFbaLeHvm8XwX69Mqt4LBx/30Uv1D+iE:2hopLUghL8/0+X2eHvm8Ap8cB5EgBE

Entry address:
0x4A002

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8365  (probably packed)

Code size:
288.5 KB (295,424 bytes)

The file lft-575558cdc54596e4ce425977463d7618-1463611450.exe has been seen being distributed by the following URL.