magebotvt109.exe

Colette

ICOFX SOFTWARE SRL

The executable magebotvt109.exe has been detected as malware by 19 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from docs.google.com.
Publisher:
ICOFX SOFTWARE SRL  (signed and verified)

Product:
Colette

Version:
1.00

MD5:
f0675d31c43ccd508c461a93b6b3f56c

SHA-1:
70ca6a43aa01642a96766c9421dad1cff59fe1ea

SHA-256:
80b70b19d72c8b1133e8867846c44159de356b539b02ab903b861f421adeeee9

Scanner detections:
19 / 68

Status:
Malware

Analysis date:
12/27/2024 1:04:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.3235198
262

Avira AntiVirus
TR/Dropper.VB.ardj
8.3.3.4

Arcabit
Trojan.Generic.D315D7E
1.0.0.680

avast!
Win32:Malware-gen
2014.9-160518

AVG
Inject3
2017.0.2740

Bitdefender
Trojan.GenericKD.3235198
1.0.20.695

Emsisoft Anti-Malware
Trojan.GenericKD.3235198
8.16.05.18.01

ESET NOD32
Win32/Injector.CYHT (variant)
10.13493

Fortinet FortiGate
W32/VBKryjetor.CYHT!tr
5/18/2016

F-Secure
Trojan.GenericKD.3235198
11.2016-18-05_4

G Data
Trojan.GenericKD.3235198
16.5.25

IKARUS anti.virus
Trojan.Win32.Injector
t3scan.2.0.9.0

Kaspersky
Trojan.Win32.VBKryjetor
14.0.0.195

McAfee
Artemis!F0675D31C43C
5600.6396

MicroWorld eScan
Trojan.GenericKD.3235198
17.0.0.417

Panda Antivirus
Trj/Genetic.gen
16.05.18.01

Qihoo 360 Security
HEUR/QVM03.0.0000.Malware.Gen
1.0.0.1120

Trend Micro
TROJ_GEN.R0CCC0VEF16
10.465.18

VIPRE Antivirus
Trojan.Win32.Generic
49404

File size:
1.8 MB (1,931,448 bytes)

Product version:
1.00

Original file name:
Geordie Gabry Mone.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\magebotvt109.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/3/2013 10:00:00 PM

Valid to:
2/4/2016 9:59:59 PM

Subject:
CN=ICOFX SOFTWARE SRL, O=ICOFX SOFTWARE SRL, STREET=str. Teilor nr. 10 sc. 2 ap. 24, L=Floresti, S=Cluj, PostalCode=407280, C=RO

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00DE9F0854CD6936A239D0FF5B81756164

File PE Metadata
Compilation timestamp:
5/12/2016 5:04:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:pzitsalT8Go1EFkQcgF8g+bbWROQQzDxY40AM2hVrW1K:IKKuEFbSg+biWNWU

Entry address:
0x11E0

Entry point:
68, 08, F2, 5C, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, B9, A1, 74, 19, A2, D6, C8, 48, AB, 38, 50, 76, E3, F5, AA, 90, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 54, 68, 6F, 72, 6E, 70, 72, 6F, 6F, 66, 37, 00, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 03, 3D, 3B, 26, 31, 52, 17, B5, 4B, BA, C8, 24, DB, 07, EE, F3, E2, 53, 44, 78, FE, 1B, 46, 66, 44, B7, 0F, 4A, 49, 1C, 47, 48, B7, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
1.8 MB (1,912,832 bytes)

The file magebotvt109.exe has been seen being distributed by the following URL.

Remove magebotvt109.exe - Powered by Reason Core Security