liderancacobrancaapjc0f6ajjavwls-pdf.exe

The executable liderancacobrancaapjc0f6ajjavwls-pdf.exe has been detected as malware by 23 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.liderancacobrancas.ru.
Version:
0.0.0.0

MD5:
ca0fc659a452230af1651f2a023b22d1

SHA-1:
4636e6ca48962bf0fa18a44568ad2fa7f3d2812a

SHA-256:
a1521607472edec7878e515bea87c89ab761e391e63aa35a501b8bd509ddebaa

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
11/15/2024 9:57:46 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.777780
387

Avira AntiVirus
TR/Dropper.MSIL.231997
8.3.2.4

Arcabit
Trojan.Kazy.DBDE34
1.0.0.629

avast!
Win32:Trojan-gen
2014.9-160114

AVG
Pakes2_c
2017.0.2865

Baidu Antivirus
Trojan.Win32.Generik
4.0.3.16114

Bitdefender
Gen:Variant.Kazy.777780
1.0.20.70

Emsisoft Anti-Malware
Gen:Variant.Kazy.777780
8.16.01.14.04

ESET NOD32
MSIL/TrojanDownloader.Agent.BGK (variant)
10.12710

Fortinet FortiGate
Generik.HBZUSNB!tr
1/14/2016

F-Secure
Gen:Variant.Kazy.777780
11.2016-14-01_5

G Data
Gen:Variant.Kazy.777780
16.1.25

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.9.5.0

K7 AntiVirus
Trojan-Downloader
13.212.18087

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.819

Malwarebytes
Trojan.Dropper.FSHRD
v2016.01.14.04

McAfee
RDN/Generic.dx
5600.6521

MicroWorld eScan
Gen:Variant.Kazy.777780
17.0.0.42

NANO AntiVirus
Trojan.Win32.Agent.dyzunl
1.0.10.5081

Panda Antivirus
Trj/CI.A
16.01.14.04

Rising Antivirus
PE:Trojan.Zesec!1.999B [F]
23.00.65.16112

Trend Micro
TROJ_GEN.R047C0EL715
10.465.14

VIPRE Antivirus
Trojan.Win32.Generic
45770

File size:
672 KB (688,128 bytes)

Product version:
0.0.0.0

Original file name:
Loader-NNBZQBBUGX.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\liderancacobrancaapjc0f6ajjavwls-pdf.exe

File PE Metadata
Compilation timestamp:
12/1/2015 1:37:40 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:iBYrQXXhZT1KeplN5rY/7i/m4qP9H3A0qEH:ioChZT13DUvQ+

Entry address:
0x5A25E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
356 KB (364,544 bytes)

The file liderancacobrancaapjc0f6ajjavwls-pdf.exe has been seen being distributed by the following URL.

Remove liderancacobrancaapjc0f6ajjavwls-pdf.exe - Powered by Reason Core Security