lmaobox.exe

The application lmaobox.exe has been detected as a potentially unwanted program by 28 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from files.cloud.naver.com.
Version:
0.0.0.0

MD5:
5b36c9d24a21ec224a4590314762d521

SHA-1:
75ec14b092bfbef3701eedd5b854c490c9611b60

SHA-256:
b8c43775c2298ccd833a0f93d5401c0fac265653a2a5a82fea4bf83b39e29a7b

Scanner detections:
28 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 1:12:18 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.13185462
5519494

Agnitum Outpost
Trojan.Agent
7.1.1

Avira AntiVirus
TR/Dropper.MSIL.148052
8.3.1.6

avast!
Win32:Malware-gen
150414-0

AVG
MSIL7
2016.0.3106

Baidu Antivirus
Hacktool.MSIL.Confuser
4.0.3.15517

Bitdefender
Trojan.Generic.13185462
1.0.20.685

Bkav FE
HW32.Packed
1.3.0.6379

Comodo Security
UnclassifiedMalware
22145

Emsisoft Anti-Malware
Trojan.Generic.13185462
10.0.0.5366

ESET NOD32
MSIL/Packed.Confuser.J suspicious application
7.0.302.0

Fortinet FortiGate
W32/Generic!tr
5/17/2015

F-Secure
Trojan.Generic.13185462
5.13.68

G Data
Trojan.Generic.13185462
15.5.25

IKARUS anti.virus
PUA.MSIL.Confuser
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.204.15935

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.2026

McAfee
RDN/Generic.dx!dqq
5600.6762

MicroWorld eScan
Trojan.Generic.13185462
16.0.0.411

NANO AntiVirus
Trojan.Win32.Confuser.dqudzq
0.30.24.1357

Norman
Troj_Generic_2.BJRR
11.20150517

nProtect
Trojan.Generic.13185462
15.05.15.01

Panda Antivirus
Trj/CI.A
15.05.17.06

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Quick Heal
Trojan.Generic.r5
5.15.14.00

Sophos
Generic PUA HF
4.98

Trend Micro House Call
TROJ_GEN.R0C1C0EE215
7.2.137

Trend Micro
TROJ_GEN.R0C1C0EE215
10.465.17

File size:
255 KB (261,120 bytes)

Product version:
0.0.0.0

Original file name:
Loader.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\lmaobox.exe

File PE Metadata
Compilation timestamp:
4/13/2015 1:11:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:KrLyzNQDixLMkFp2LO6XRRvCEsWlFQS6aCjCsfhQlEo:Kr5DyjFp2le6lKSWjCsfhQlEo

Entry address:
0x4800A

Entry point:
FF, 25, 00, 80, 44, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
41.5 KB (42,496 bytes)

The file lmaobox.exe has been seen being distributed by the following URL.

Remove lmaobox.exe - Powered by Reason Core Security