Messanger.exe

The executable Messanger.exe has been detected as malware by 16 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from webprod21.megashares.com.
Version:
0.0.0.0

MD5:
a1e0365a6fdf855d2bf6fb021ec8058b

SHA-1:
8b9f02b198d6dc405689fcda2614296fb5e8ead0

SHA-256:
76f2e06d972aadc2d2b36f5c0f90bc6a7ed4244dfbcc0a2633acca52ae59cec4

Scanner detections:
16 / 68

Status:
Malware

Analysis date:
11/27/2024 3:35:16 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-150511

Baidu Antivirus
Hacktool.MSIL.Confuser
4.0.3.15511

ESET NOD32
MSIL/Packed.Confuser.P suspicious (variant)
9.11594

Fortinet FortiGate
W32/Generic!tr
5/11/2015

F-Prot
W32/A-57056955
v6.4.7.1.166

IKARUS anti.virus
Trojan.MSIL.Injector
t3scan.1.8.9.0

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.2056

McAfee
Artemis!A1E0365A6FDF
5600.6768

Norman
Obfuscated.gen!r
11.20150511

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Sophos
Generic PUA IL
4.98

Trend Micro House Call
TROJ_GEN.R047H07E715
7.2.131

File size:
186.5 KB (190,976 bytes)

Product version:
0.0.0.0

Original file name:
Messanger.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\messanger.exe

File PE Metadata
Compilation timestamp:
5/7/2015 9:36:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:+4I7Q990Ge1gJHfQMN8Pmbti4VRZFcJ76ZQxbu7Ur9+K:+Mxe1o3tNzIdxb9J

Entry address:
0x1F3FE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
117.5 KB (120,320 bytes)

The file Messanger.exe has been seen being distributed by the following URL.

Remove Messanger.exe - Powered by Reason Core Security