Nodus.exe

The executable Nodus.exe has been detected as malware by 28 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download2171.mediafire.com and multiple other hosts.
Description:
Nodus

Version:
7.13.0.2

MD5:
6b95c229b1bd9e0e598ea6394a3c7dc1

SHA-1:
08a17fced1e215d845d7d8bfcb67f92d61183277

SHA-256:
f30d8e808edcd49f0ea1977dd4af99a1e826ede1fb0b4dfc30169b020f18b8bd

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
12/26/2024 4:06:10 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12223006
536

avast!
MSIL:GenMalicious-HJ [Trj]
2014.9-150817

Baidu Antivirus
Backdoor.Win32.Farfli
4.0.3.15817

Bitdefender
Trojan.Generic.12223006
1.0.20.1145

Comodo Security
UnclassifiedMalware
22130

Emsisoft Anti-Malware
Trojan.Generic.12223006
8.15.08.17.03

ESET NOD32
MSIL/Injector.ESS (variant)
9.11634

Fortinet FortiGate
MSIL/Injector.FBF!tr
8/17/2015

F-Secure
Trojan.Generic.12223006
11.2015-17-08_2

G Data
Trojan.Generic.12223006
15.8.25

IKARUS anti.virus
Backdoor.Win32.Farfli
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.203.15929

Kaspersky
Backdoor.Win32.Farfli
14.0.0.1567

Malwarebytes
Backdoor.Agent.FRTGen
v2015.08.17.03

McAfee
Artemis!6B95C229B1BD
5600.6670

Microsoft Security Essentials
Backdoor:Win32/Fynloski
1.1.11602.0

MicroWorld eScan
Trojan.Generic.12223006
16.0.0.687

NANO AntiVirus
Trojan.Win32.Farfli.dracwj
0.30.24.1357

Norman
Suspicious_Gen4.IGSUS
11.20150817

nProtect
Trojan.Generic.12223006
15.05.15.01

Panda Antivirus
Trj/Chgt.J
15.08.17.03

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R047C0DE115
7.2.229

Trend Micro
TROJ_GEN.R047C0DE115
10.465.17

VIPRE Antivirus
Trojan.Win32.Generic
40264

ViRobot
Backdoor.Win32.A.Farfli.5745664[h]
2014.3.20.0

Zillya! Antivirus
Backdoor.Farfli.Win32.1768
2.0.0.2179

File size:
5.5 MB (5,745,664 bytes)

Product version:
7.13.0.2

Copyright:
Copyright Nodus

Original file name:
Nodus.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\nodus.exe

File PE Metadata
Compilation timestamp:
8/15/2014 1:07:42 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:6d3hMXsj02FpwT+WvCr6UEFSc6UH56D9kXKMPFtpqANXn70wn97/G6yosNTOFFv:O6WJFST+WarU6UH56a6IFnRXn70k/G6n

Entry address:
0x57AD2E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
5.5 MB (5,737,984 bytes)

The file Nodus.exe has been seen being distributed by the following 2 URLs.

Remove Nodus.exe - Powered by Reason Core Security