magebotsetupvt1090.exe

MageBot

The executable magebotsetupvt1090.exe has been detected as malware by 14 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.magebot.net.
Product:
MageBot

Version:
...

MD5:
d78f47eada7820fd4583763fb43a8531

SHA-1:
ea362372ec58cf088406ee449f90d52556b4ccb9

SHA-256:
d1fd3042ca032b0ddac02dfc52251b54be280142c67e285c48b6f5f9137bbf3e

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
4/23/2025 10:23:15 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2988507
369

Avira AntiVirus
TR/Rogue.3053282
8.3.2.4

Arcabit
Trojan.Generic.D2D99DB
1.0.0.642

Bitdefender
Trojan.GenericKD.2988507
1.0.20.160

Bkav FE
W32.HfsAtITIST
1.3.0.7400

Dr.Web
Trojan.DownLoader18.55249
9.0.1.032

Emsisoft Anti-Malware
Trojan.GenericKD.2988507
8.16.02.01.12

ESET NOD32
Win32/Injector.Autoit.CAL (variant)
10.12877

F-Secure
Trojan.GenericKD.2988507
11.2016-01-02_2

G Data
Trojan.GenericKD.2988507
16.2.25

Kaspersky
Trojan.Win32.Inject
14.0.0.730

MicroWorld eScan
Trojan.GenericKD.2988507
17.0.0.96

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1077

Quick Heal
TrojanAPT.Crypt.r5
2.16.14.00

File size:
2.9 MB (3,053,282 bytes)

Product version:
...

Original file name:
XaAMAER.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\magebotsetupvt1090.exe

File PE Metadata
Compilation timestamp:
12/24/2008 3:00:07 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:Pe2PJLa+QdkdhXidn2OZOMmnpuJkb9jm5g+wyImYeBgFBdLjHaWE24vagWxPykhj:Pe2PJGQHin2OokShVmbBeL9le1WxzsK

Entry address:
0x17770

Entry point:
E8, C4, AF, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, C1, 8B, 4D, 08, C7, 00, 88, DA, 47, 00, 8B, 09, 83, 60, 08, 00, 89, 48, 04, 5D, C2, 08, 00, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, F1, C7, 06, 88, DA, 47, 00, 8B, 43, 08, 89, 46, 08, 85, C0, 8B, 43, 04, 57, 74, 31, 85, C0, 74, 27, 50, E8, EF, D3, FF, FF, 8B, F8, 47, 57, E8, 10, D3, FF, FF, 59, 59, 89, 46, 04, 85, C0, 74, 18, FF, 73, 04, 57, 50, E8, F2, AF, 00, 00, 83, C4, 0C, EB, 09, 83, 66, 04, 00, EB, 03, 89, 46, 04, 5F, 8B, C6, 5E, 5B...
 
[+]

Entropy:
7.7860  (probably packed)

Code size:
495.5 KB (507,392 bytes)

The file magebotsetupvt1090.exe has been seen being distributed by the following URL.

Remove magebotsetupvt1090.exe - Powered by Reason Core Security