mypicture.exe

ait0e5d9LyZg

aYOgYAVELww

The executable mypicture.exe has been detected as malware by 4 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download1513.mediafire.com.
Publisher:
aYOgYAVELww

Product:
ait0e5d9LyZg

Description:
aji48Q2XlcA

Version:
8.10.13.52

MD5:
a3ad1094e1aef8ddb71a8f0e2b96b034

SHA-1:
176457bbe1e53fc53cf21c0aa71e360f51be23f4

SHA-256:
241a0f5aa3dc3f50bd807479755790456d5e7f7fc4f0f2d8ebe572d7d19b9f9b

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
11/23/2024 7:45:29 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160708-3

Dr.Web
Trojan.MulDrop6.34802
9.0.1.05190

ESET NOD32
MSIL/Packed.Confuser.P suspicious application
7.0.302.0

VIPRE Antivirus
Threat.4657539
50880

File size:
334 KB (342,016 bytes)

Product version:
8.10.13.52

Copyright:
Copyright © 2002

Trademarks:
aMv4iv4zEVny

Original file name:
mypicture.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\mypicture.exe

File PE Metadata
Compilation timestamp:
3/26/2016 2:24:36 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:wnXmWiDqgv3CU5J7gHVV+IW7BHBN/vwFsS/jIBnG:w2jDqg//5J7IL+IW7BjvwFQBG

Entry address:
0x400AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
248.5 KB (254,464 bytes)

The file mypicture.exe has been seen being distributed by the following URL.

Remove mypicture.exe - Powered by Reason Core Security