parmis_support_downloader.exe

Parmis Support Downloader

ParmisIT

The executable parmis_support_downloader.exe has been detected as malware by 13 anti-virus scanners. While running, it connects to the Internet address h5-152-194-58.host.redstation.co.uk on port 21.
Publisher:
ParmisIT

Product:
Parmis Support Downloader

Description:
www.ParmisIT.com

Version:
1.00.0028

MD5:
7b522d66cbd9d02eb4e31a18e8fe9441

SHA-1:
2d1d90795acc6c300281a5d5d05eff630a64084c

SHA-256:
12c570c63c8191ae943e9205c917f88974b16ea0a00b1b84c786e3df640b9627

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
12/28/2024 8:42:02 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.VP.bq0@ayBhhvei
264

Arcabit
Trojan.Heur.VP.ED4B
1.0.0.666

avast!
Win32:Evo-gen [Susp]
2014.9-160516

Baidu Antivirus
Win32.Trojan.WisdomEyes.151026.9950
4.0.3.16516

Bitdefender
Gen:Trojan.Heur.VP.bq0@ayBhhvei
1.0.20.685

Emsisoft Anti-Malware
Gen:Trojan.Heur.VP.bq0@ayBhhvei
8.16.05.16.10

F-Secure
Gen:Trojan.Heur.VP.bq0@ayBhhvei
11.2016-16-05_2

G Data
Gen:Trojan.Heur.VP.bq0@ayBhhvei
16.5.25

K7 AntiVirus
Trojan
13.221.19208

MicroWorld eScan
Gen:Trojan.Heur.VP.bq0@ayBhhvei
17.0.0.411

Qihoo 360 Security
QVM11.1.Malware.Gen
1.0.0.1120

Quick Heal
(Suspicious) - DNAScan
5.16.14.00

Sophos
Mal/HckPk-A
4.98

File size:
27.5 KB (28,160 bytes)

Product version:
1.00.0028

Copyright:
2015

Original file name:
Parmis_Support_Downloader_p.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
1/26/2016 2:52:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
192:l3aAKCf3GoiprQPJ9YxpTI7mYdmTYPxzxn4RuVMJXpGXJRDcD5yCW:1ay29iPCFISSmTwxlntVMJ5EcDUC

Entry address:
0x14000

Entry point:
68, 58, 40, 41, 00, FF, 15, C4, 36, 41, 00, 68, 88, 40, 41, 00, 50, FF, 15, C8, 36, 41, 00, 8B, F8, BE, 92, 40, 41, 00, B9, F4, 01, 00, 00, F3, A6, 0F, 85, D5, BF, FE, FF, E9, E0, AE, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 50, 61, 72, 6D, 69, 73, 5F, 53, 75, 70, 70, 6F, 72, 74, 5F, 44, 6F, 77, 6E, 6C, 6F, 61, 64, 65, 72, 5F, 73, 6F, 66, 74, 6C, 6F, 63, 6B, 5C, 73, 6F, 66, 74, 6C...
 
[+]

Entropy:
5.7377

Code size:
12 KB (12,288 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (FTP):
Connects to h5-152-194-58.host.redstation.co.uk  (5.152.194.58:21)

Remove parmis_support_downloader.exe - Powered by Reason Core Security