margonemhack.exe

WindowsApplication1

GLABIS studio

The executable margonemhack.exe has been detected as malware by 8 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from s6536.chomikuj.pl.
Publisher:
GLABIS studio

Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
31d7d4c0b0249e5fe55d6b064a02c73c

SHA-1:
126f2065e471fb985b99e1fbc1aea2bbeb1e3876

SHA-256:
8d725b7350970263bd88fcb122c0483bf5270dccfeba8268041dd466e573c339

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
12/29/2024 6:01:17 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Spy.A.7750
7.11.177.0

AVG
PSW.MSIL
2017.0.2817

Baidu Antivirus
Trojan.MSIL.InfoStealer
4.0.3.1631

Comodo Security
UnclassifiedMalware
19729

ESET NOD32
MSIL/PSW.Agent.NFI (variant)
10.10522

Fortinet FortiGate
MSIL/Agent.OFU!tr
3/1/2016

McAfee
Artemis!31D7D4C0B024
5600.6473

Rising Antivirus
PE:Trojan.Win32.Generic.17604FB7!392187831
23.00.65.16228

File size:
129.5 KB (132,608 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © GLABIS studio 2014

Original file name:
Margonem Hack.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\margonemhack.exe

File PE Metadata
Compilation timestamp:
2/27/2014 8:07:34 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:+ikm1B7S6LKy+9EGfVpzIDwOgDVfhSnkiPXXDJayd2Ca:+jmdLKy+NVK+MkiPjJau

Entry address:
0x2119E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, F6, 8C, 0F, 53, 00, 00, 00, 00, 02, 00, 00, 00, 7A, 00, 00, 00, 1C, 20, 02, 00, 1C, F6, 01, 00, 52, 53...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
124.5 KB (127,488 bytes)

The file margonemhack.exe has been seen being distributed by the following URL.

Remove margonemhack.exe - Powered by Reason Core Security