mata virus amvo usb.exe

The application mata virus amvo usb.exe has been detected as a potentially unwanted program by 23 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dc343.4shared.com and multiple other hosts.
MD5:
38c7e639b126af8b6cd087680d4414cd

SHA-1:
de5788bed2a86e2bd369cbd72525eaab7dc516b0

Scanner detections:
23 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 6:04:13 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Backdoor.Generic.744464
569

Agnitum Outpost
Backdoor.Agent
7.1.1

avast!
Win32:Trojan-gen
2014.9-150715

AVG
BackDoor.Generic_c
2016.0.3047

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.15715

Bitdefender
Backdoor.Generic.744464
1.0.20.980

Comodo Security
TrojWare.Win32.Trojan.Agent.~GAAC
21943

Dr.Web
Tool.Siggen.6796
9.0.1.0196

Emsisoft Anti-Malware
Backdoor.Generic.744464
8.15.07.15.04

F-Secure
Backdoor.Generic.744464
11.2015-15-07_4

G Data
Backdoor.Generic.744464
15.7.25

IKARUS anti.virus
Backdoor.Win32.SuspectCRC
t3scan.1.8.9.0

McAfee
Artemis!38C7E639B126
5600.6703

MicroWorld eScan
Backdoor.Generic.744464
16.0.0.588

NANO AntiVirus
Riskware.Win32.Siggen.dikprl
0.30.24.1357

Norman
Delfiles.BP
11.20150715

nProtect
Trojan/W32.Agent.211456.HZ
15.04.29.01

Panda Antivirus
Trj/CI.A
15.07.15.04

Qihoo 360 Security
Win32/Backdoor.b31
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R002C0EJQ14
7.2.196

Trend Micro
TROJ_GEN.R002C0EJQ14
10.465.15

VIPRE Antivirus
Trojan.Win32.Generic
39804

ViRobot
Trojan.Win32.Agent.48128.BB[h]
2014.3.20.0

File size:
206.5 KB (211,456 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\documents and settings\administrador\escritorio\mata virus amvo usb.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.25

CTPH (ssdeep):
1536:W9wvQUreUbyzABq2mLha2OeQ4VE6vxP2OdEHidFE4+QG06Qf7kl6zgCCNPxGXwB6:6A/yzv2mLh8eQ4VLIjuS4+QdYJCaB6

Entry address:
0xA0C0

Entry point:
55, 8B, EC, B9, 06, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, A1, EC, B3, 40, 00, C6, 00, 01, B8, 58, A0, 40, 00, E8, 04, A9, FF, FF, 33, C0, 55, 68, B0, A4, 40, 00, 64, FF, 30, 64, 89, 20, A1, C0, B2, 40, 00, 33, D2, 89, 10, 8D, 45, EC, E8, 75, F8, FF, FF, 8B, 55, EC, B8, 50, C9, 40, 00, E8, 50, 99, FF, FF, 8D, 55, E8, A1, 50, C9, 40, 00, E8, 7B, F7, FF, FF, 8B, 55, E8, B8, 50, C9, 40, 00, E8, 36, 99, FF, FF, B8, 54, C9, 40, 00, BA, 00, 08, 00, 00, E8, 97, 9D, FF, FF, 68, 00, 08, 00, 00, A1, 54...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
37.5 KB (38,400 bytes)

The file mata virus amvo usb.exe has been seen being distributed by the following 2 URLs.

http://dc343.4shared.com/download/.../mata_virus_amvo_usb.exe

Remove mata virus amvo usb.exe - Powered by Reason Core Security