lokalizator.exe

The application lokalizator.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.darmowa-lokalizacja-telefonu.pl.
MD5:
ace1d0a93e549f2e8b460fabec26e557

SHA-1:
f79b6332f4a66628aada438b7c256da7f893e1d1

SHA-256:
9b57a79a54b98a306069f419096fd84d61041050f770f164ccc024397b54804e

Scanner detections:
21 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 9:21:40 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.72303
324

avast!
Win32:Malware-gen
2014.9-160317

AVG
Skodna.ArchSMS
2017.0.2802

Baidu Antivirus
Trojan.Win32.ArchSMS
4.0.3.16317

Bitdefender
Gen:Variant.Strictor.72303
1.0.20.385

Comodo Security
UnclassifiedMalware
21273

Dr.Web
Trojan.Fakealert.47835
9.0.1.077

Emsisoft Anti-Malware
Gen:Variant.Strictor.72303
8.16.03.17.03

ESET NOD32
Win32/Hoax.ArchSMS.AGG (variant)
10.11260

Fortinet FortiGate
Riskware/SMS
3/17/2016

F-Prot
W32/A-b6aac9c2
v6.4.7.1.166

F-Secure
Gen:Variant.Strictor.72303
11.2016-17-03_5

G Data
Gen:Variant.Strictor.72303
16.3.25

IKARUS anti.virus
Trojan-Banker.Win32.Banker
t3scan.1.8.6.0

K7 AntiVirus
JokeProgram
13.200.15139

McAfee
GenericR-AVZ!ACE1D0A93E54
5600.6458

MicroWorld eScan
Gen:Variant.Strictor.72303
17.0.0.231

NANO AntiVirus
Riskware.Win32.FakeSMSLocate.cxkndh
0.30.0.296

Qihoo 360 Security
Win32/Trojan.Hoax.97e
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R047C0OKB14
7.2.77

VIPRE Antivirus
Trojan.Win32.Generic
38072

File size:
3.2 MB (3,338,752 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\lokalizator.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:4Rn0nDNm2rUYcgCp+CDyboTbTdD9CIwSVbYhP:4Rn0DNHrSCCebiCIwSVO

Entry address:
0x138254

Entry point:
55, 8B, EC, 83, C4, F0, B8, 5C, 7D, 53, 00, E8, 68, E4, EC, FF, A1, 28, 15, 54, 00, 8B, 00, E8, AC, B5, F2, FF, A1, 28, 15, 54, 00, 8B, 00, BA, CC, 82, 53, 00, E8, 93, B1, F2, FF, 8B, 0D, 90, 13, 54, 00, A1, 28, 15, 54, 00, 8B, 00, 8B, 15, 20, 5B, 53, 00, E8, 9B, B5, F2, FF, 8B, 0D, E0, 11, 54, 00, A1, 28, 15, 54, 00, 8B, 00, 8B, 15, 94, 7B, 53, 00, E8, 83, B5, F2, FF, A1, 28, 15, 54, 00, 8B, 00, E8, F7, B5, F2, FF, E8, 82, BF, EC, FF, 00, 00, FF, FF, FF, FF, 0B, 00, 00, 00, 4C, 6F, 6B, 61, 6C, 69, 7A, 61...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.2 MB (1,274,880 bytes)

The file lokalizator.exe has been seen being distributed by the following URL.

Remove lokalizator.exe - Powered by Reason Core Security