mc antycheat bypass.exe

ifBtxzmomg

JJYDwstuk

The executable mc antycheat bypass.exe has been detected as malware by 23 anti-virus scanners. This is a setup program which is used to install the application. Accoriding to the detections, this has been classified as a kyelogger which is capable of recoring a user's keystrokes. The file has been seen being downloaded from www119.zippyshare.com.
Publisher:
JJYDwstuk

Product:
ifBtxzmomg

Version:
3.5.464.4067

MD5:
98d587c7e2fc77527fb34264f9651e23

SHA-1:
de19fa58f6fe0a5edb84b0ec22f4d94a40ecaaee

SHA-256:
4809c161f1b21209f45469af207e711796a18657f0e03438330dad44d4fe01c2

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
12/25/2024 5:37:06 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.MSILKrypt.4
386

Avira AntiVirus
TR/Dropper.MSIL.243612
8.3.2.4

Arcabit
Trojan.MSILKrypt.4
1.0.0.642

avast!
Win32:Malware-gen
2014.9-160115

AVG
MSIL9
2017.0.2864

Bitdefender
Gen:Variant.MSILKrypt.4
1.0.20.75

Dr.Web
Trojan.KeyLogger.37120
9.0.1.015

Emsisoft Anti-Malware
Gen:Variant.MSILKrypt
8.16.01.15.03

ESET NOD32
MSIL/Injector.MUE (variant)
10.12862

Fortinet FortiGate
MSIL/Injector.MUE!tr
1/15/2016

F-Secure
Gen:Variant.MSILKrypt.4
11.2016-15-01_6

G Data
Gen:Variant.MSILKrypt
16.1.25

IKARUS anti.virus
Trojan.MSIL.Injector
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.212.18418

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.814

McAfee
Artemis!98D587C7E2FC
5600.6520

Microsoft Security Essentials
VirTool:MSIL/Injector.HL
1.1.12400.0

MicroWorld eScan
Gen:Variant.MSILKrypt.4
17.0.0.45

Panda Antivirus
Trj/CI.A
16.01.15.03

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1077

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16113

Sophos
Mal/MSIL-PL
4.98

VIPRE Antivirus
Trojan.Win32.Generic
46478

File size:
2.2 MB (2,351,104 bytes)

Product version:
3.5.464.4067

Copyright:
Copyright (C) 2004-2013 enzoL zCEyJcnQskyYpCy

Original file name:
ejVBchp.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
1/8/2016 7:35:07 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:rJg3Nca86m93kfZ3pbwWjjkO7wqGaVZb:oF86eiZ3pEoDpp

Entry address:
0x23BC19

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.2 MB (2,334,720 bytes)

The file mc antycheat bypass.exe has been seen being distributed by the following URL.

Remove mc antycheat bypass.exe - Powered by Reason Core Security