价앗샌ol癩릅燎.exe

Indigo Rose Software Design Corporation

The application 价앗샌ol癩릅燎.exe by Indigo Rose Software Design has been detected as a potentially unwanted program by 20 anti-malware scanners.
Publisher:

MD5:
8c520243ac2f9a6a107b067482f12ee0

SHA-1:
f63e245319b149a33976c5cebe6ba3c1c571d82b

SHA-256:
e32f1a84c82a1fbf478a58d1f97ebbb27a2062c7d12db18b597e1a42a783977e

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 7:33:32 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.4042863
17.01.27

AegisLab AV Signature
Troj.W32.Gen.lDM4
2.1.4+

Avira AntiVirus
TR/Spy.Banbra.gykkb
8.3.3.4

Arcabit
Trojan.Generic.D3DB06F
1.0.0.793

Bitdefender
Trojan.GenericKD.4042863
1.0.20.135

Comodo Security
TrojWare.Win32.Agent.OSCF
26460

Emsisoft Anti-Malware
Trojan.GenericKD.4042863
8.17.01.27.06

ESET NOD32
Win32/FlyStudio.Packed.A potentially unwanted (variant)
11.14781

F-Secure
Trojan.GenericKD.4042863
11.2017-27-01_6

G Data
Trojan.GenericKD.4042863
17.1.25

K7 AntiVirus
Adware
13.248.22117

Kaspersky
Trojan-Banker.Win32.Banbra
14.0.0.-1076

McAfee
Artemis!8C520243AC2F
5600.6142

MicroWorld eScan
Trojan.GenericKD.4042863
18.0.0.81

NANO AntiVirus
Trojan.Win32.Banbra.ejuwsd
1.0.70.14475

Panda Antivirus
Trj/CI.A
17.01.27.06

Qihoo 360 Security
Trojan.Generic
1.0.0.1120

Rising Antivirus
Malware.Strealer!8.1EF-Kw4Le9JN9NR (cloud)
23.00.65.17125

Sophos
Generic PUA PG (PUA)
4.98

Trend Micro House Call
TROJ_GEN.R047H07LR16
7.2.27

File size:
4 MB (4,230,480 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\价앗샌ol癩릅燎.exe

Digital Signature
Authority:
Indigo Rose Software Design Corporation

Valid from:
2/1/2015 1:00:00 AM

Valid to:
2/1/2025 1:00:00 AM

Subject:
CN=Indigo Rose Software Design Corporation, OU=Security Labs, O=Indigo Rose Software Design Corporation, L=Indigo, S=Indigo, C=CN

Issuer:
CN=Indigo Rose Software Design Corporation, OU=Security Labs, O=Indigo Rose Software Design Corporation, L=Indigo, S=Indigo, C=CN

Serial number:
AD28393F864B19B04844E94E34F5987E

File PE Metadata
Compilation timestamp:
9/6/2016 11:35:40 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x4D5B2B

Entry point:
68, CF, 4D, C2, 2A, E8, 19, CE, 3A, 00, 4B, 03, F4, 7D, 80, 61, DA, F1, 4E, 87, 26, 95, 60, A9, 89, 39, 1C, 95, BA, 35, D3, 7E, 07, 91, 55, 4D, 7E, 93, 02, E8, F1, 96, B3, 80, 86, 7F, 45, 4A, 12, BA, 60, B5, FC, 4E, 66, 0E, 3E, 1B, 6D, 26, 4F, 78, 2B, 4E, CE, 04, 09, C9, 71, D7, 44, 6E, 3F, 99, AA, AF, 3E, 86, BA, 74, 02, 74, 1F, 58, 09, D9, 3E, 09, 39, 18, 24, 40, 93, 2B, A6, E2, 0E, C5, B5, C1, 2B, 2D, 2A, 8E, 70, 0C, D9, 00, 1E, 28, F8, 18, 06, D3, F3, EC, 61, 82, 9C, 16, 29, F6, 27, DB, 5D, 97, 59, DD...
 
[+]

Entropy:
7.8189  (probably packed)

Code size:
8.5 MB (8,925,184 bytes)

Remove 价앗샌ol癩릅燎.exe - Powered by Reason Core Security