love.exe

The executable love.exe has been detected as malware by 34 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from s1.directxex.com.
Version:
0.0.0.0

MD5:
7dab7febbcb7e8dd51790579f630450d

SHA-1:
f91ac55df2e535b7165cfd3017d4295b79ea44ba

SHA-256:
657d8119f2b448def9f4db0517a6bb0c9f7a97af621930b6d878b808d06faa94

Scanner detections:
34 / 68

Status:
Malware

Analysis date:
11/30/2024 3:27:18 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.47803
786

Agnitum Outpost
Trojan.Agent
7.1.1

AhnLab V3 Security
Trojan/Win32.Spnr
2014.11.13

Avira AntiVirus
TR/Strictor.47803.2
7.11.185.18

avast!
Win32:Malware-gen
2014.9-141210

AVG
MSIL3
2015.0.3264

Baidu Antivirus
Trojan.MSIL.Agent
4.0.3.141210

Bitdefender
Gen:Variant.Strictor.47803
1.0.20.1720

Comodo Security
UnclassifiedMalware
20070

Dr.Web
Trojan.Fsysna.6225
9.0.1.0344

Emsisoft Anti-Malware
Gen:Variant.Strictor.47803
8.14.12.10.02

ESET NOD32
MSIL/Bladabindi
8.10717

Fortinet FortiGate
MSIL/Injector.BQY!tr
12/10/2014

F-Prot
W32/Trojan2.OJYO
v6.4.7.1.166

F-Secure
Gen:Variant.Strictor.47803
11.2014-10-12_4

G Data
Gen:Variant.Strictor.47803
14.12.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.3.0

K7 AntiVirus
Trojan
13.185.14007

Kaspersky
Trojan.MSIL.Agent
14.0.0.2817

Malwarebytes
Trojan.MSIL
v2014.12.10.02

McAfee
Artemis!7DAB7FEBBCB7
5600.6920

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi
1.11104

MicroWorld eScan
Gen:Variant.Strictor.47803
15.0.0.1032

NANO AntiVirus
Trojan.Win32.Agent.dbffke
0.28.6.63362

Norman
Agent.AZKRJ
11.20141210

Panda Antivirus
Generic Malware
14.12.10.02

Qihoo 360 Security
Win32/Trojan.951
1.0.0.1015

Quick Heal
Trojan.MSI.r3
12.14.14.00

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNR.35GA14
7.2.344

Trend Micro
TROJ_SPNR.35GA14
10.465.10

Vba32 AntiVirus
Trojan.MSIL.Agent
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
34752

Zillya! Antivirus
Trojan.Agent.Win32.468839
2.0.0.1982

File size:
652.5 KB (668,160 bytes)

Product version:
0.0.0.0

Original file name:
Server.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\love.exe

File PE Metadata
Compilation timestamp:
6/7/2014 1:26:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:Il067mO3KUfCEHdKveYvH1m/7lM80bNVs5b6vog10jaXgNAywDoKLfbqW1Mf51vq:qbC8sV869XDfxMR

Entry address:
0x832AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
517 KB (529,408 bytes)

The file love.exe has been seen being distributed by the following URL.

Remove love.exe - Powered by Reason Core Security