OneHitCF 11.7.exe

Jet

BKHN

The application OneHitCF 11.7.exe has been detected as a potentially unwanted program by 25 anti-malware scanners. While running, it connects to the Internet address i2-h0-s1001.p1-iad.cdngp.net on port 443.
Publisher:
BKHN

Product:
Jet

Version:
1.00

MD5:
db5f9e1e0c891a89f787ae6f27fb9f94

SHA-1:
42c01636fb0fff252f802cdf9a3c543657736aac

SHA-256:
117d9bfa4d8ddf4216bc436c9bfd1c9d7870beb0e327155d2b7eb0a94477058b

Scanner detections:
25 / 68

Status:
Potentially unwanted

Analysis date:
12/30/2024 9:29:04 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
RiskWare.AdClickCF
7.1.1

AhnLab V3 Security
Trojan/Win32.Agent
2013.08.26

Avira AntiVirus
TR/Spy.61440.1351
7.11.98.48

avast!
Win32:HackTool-FO [PUP]
2014.9-160120

Bitdefender
Gen:Trojan.Heur.VP.dm0@ausytgdi
1.0.20.100

Comodo Security
UnclassifiedMalware
16825

Dr.Web
Trojan.DownLoader8.20208
9.0.1.020

Emsisoft Anti-Malware
Gen:Trojan.Heur.VP.dm0@ausytgdi
8.16.01.20.08

ESET NOD32
Win32/RiskWare.AdClickCF (variant)
10.8727

Fortinet FortiGate
W32/RiskWare_AdClickCF.A
1/20/2016

F-Secure
Gen:Trojan.Heur.VP.dm0@ausytgdi
11.2016-20-01_4

G Data
Gen:Trojan.Heur.VP.dm0@ausytgdi
16.1.22

IKARUS anti.virus
Worm.Win32.VBNA
t3scan.2.0.127

K7 AntiVirus
Riskware
13.170.9377

Kaspersky
Trojan.Win32.Agent
14.0.0.786

McAfee
Generic.dx!DB5F9E1E0C89
5600.6514

MicroWorld eScan
Gen:Trojan.Heur.VP.dm0@ausytgdi
17.0.0.60

Norman
GameHack.AR
11.20160120

Panda Antivirus
Trj/OCJ.D
16.01.20.08

Sophos
Mal/Generic-S
4.91

SUPERAntiSpyware
Trojan.Agent/Gen-Alient
9373

Trend Micro House Call
TROJ_GEN.RCBCPD7
7.2.20

Trend Micro
TROJ_GEN.RCBCPD7
10.465.20

Vba32 AntiVirus
Trojan.Agent
3.12.22.3

VIPRE Antivirus
Trojan.Win32.Generic
20890

File size:
60 KB (61,440 bytes)

Product version:
1.00

Original file name:
OneHitCF 11.7.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
3/3/2013 12:06:10 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:BXyQlQ9cPJnwkVYbGaoGJZMnWhBk3pIPjjKe3oKesXyQ26:zPwQYC50Zpk576

Entry address:
0x115C

Entry point:
68, 28, 35, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 6C, 66, 02, 3E, 0E, 02, 79, 49, B4, 1F, 45, 06, BE, 4A, 19, 9C, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 46, 2D, 41, 37, 45, 42, 4A, 65, 74, 00, 30, 43, 30, 35, 00, 00, 00, 00, FF, CC, 31, 00, 14, AA, 05, B6, 27, C7, 52, 3C, 4C, A2, 36, 3B, 15, F6, 55, 2A, E6, D0, 7F, 16, 9D, 97, 5D, 86, 44, A3, 75, 61, E2, 4F, AB, BD, 90, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00, AA, 00, 60, D3, 93, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
48 KB (49,152 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to unallocated.barefruit.co.uk  (92.242.143.8:80)

TCP (HTTP):
Connects to ec2-52-1-32-25.compute-1.amazonaws.com  (52.1.32.25:80)

TCP (HTTP SSL):
Connects to i2-h0-s1001.p1-iad.cdngp.net  (174.35.27.81:443)

TCP (HTTP):
Connects to ec2-54-85-149-135.compute-1.amazonaws.com  (54.85.149.135:80)

Remove OneHitCF 11.7.exe - Powered by Reason Core Security