magebotsetupvt1090.exe

The executable magebotsetupvt1090.exe has been detected as malware by 19 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.magebot.net.
MD5:
bb9c679ce716f969358ad7db75cf27d8

SHA-1:
2aee20777c036396999489a43944017a79e779de

SHA-256:
f96a63a99619af785af9c322b24259336d2ad85135caa3ad083bb22875d7ecec

Scanner detections:
19 / 68

Status:
Malware

Analysis date:
12/16/2025 12:50:14 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2982390
369

Arcabit
Trojan.Generic.D2D81F6
1.0.0.642

avast!
Win32:Malware-gen
2014.9-160201

Bitdefender
Trojan.GenericKD.2982390
1.0.20.160

Bkav FE
W32.HfsAtITPSINF
1.3.0.7400

Emsisoft Anti-Malware
Trojan.GenericKD.2982390
8.16.02.01.12

ESET NOD32
Win32/Obfuscated.Autoit
10.12884

Fortinet FortiGate
W32/Inject.B!tr
2/1/2016

F-Secure
Trojan.GenericKD.2982390
11.2016-01-02_2

G Data
Trojan.GenericKD.2982390
16.2.25

IKARUS anti.virus
Trojan.Win32.Obfuscated
t3scan.1.9.5.0

Kaspersky
Trojan.Win32.Inject
14.0.0.730

Microsoft Security Essentials
Trojan:Win32/Dynamer!ac
1.1.12400.0

MicroWorld eScan
Trojan.GenericKD.2982390
17.0.0.96

nProtect
Trojan.GenericKD.2982390
16.01.15.02

Quick Heal
TrojanAPT.Crypt.r5
2.16.14.00

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16130

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic
46588

File size:
2.9 MB (3,053,326 bytes)

Original file name:
JWNSENh.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\magebotsetupvt1090.exe

File PE Metadata
Compilation timestamp:
12/24/2008 3:00:07 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:9e2PJLa+QYGdhXidn2OZOMmnpuJkb9jm5g+w5ImYeBgFBdLWY82GW7PNc3/p6III:9e2PJGlHin2OokShYmbBeLW4HPudII

Entry address:
0x17770

Entry point:
E8, C4, AF, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, C1, 8B, 4D, 08, C7, 00, 88, DA, 47, 00, 8B, 09, 83, 60, 08, 00, 89, 48, 04, 5D, C2, 08, 00, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, F1, C7, 06, 88, DA, 47, 00, 8B, 43, 08, 89, 46, 08, 85, C0, 8B, 43, 04, 57, 74, 31, 85, C0, 74, 27, 50, E8, EF, D3, FF, FF, 8B, F8, 47, 57, E8, 10, D3, FF, FF, 59, 59, 89, 46, 04, 85, C0, 74, 18, FF, 73, 04, 57, 50, E8, F2, AF, 00, 00, 83, C4, 0C, EB, 09, 83, 66, 04, 00, EB, 03, 89, 46, 04, 5F, 8B, C6, 5E, 5B...
 
[+]

Entropy:
7.7859  (probably packed)

Code size:
495.5 KB (507,392 bytes)

The file magebotsetupvt1090.exe has been seen being distributed by the following URL.

Remove magebotsetupvt1090.exe - Powered by Reason Core Security