patcher.exe

The executable patcher.exe has been detected as malware by 12 anti-virus scanners. The file has been seen being downloaded from 9jj2jl.1fichier.com.
MD5:
5ac7a39b64595b0454b829d035db9f07

SHA-1:
63c54a8fce75e64c5e3476c25817c151176ea107

SHA-256:
71462e0e4ef2b1e54eeb0db530e3e51a1a467b5a23786b005e7fca92bffae67a

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
12/27/2024 8:27:54 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Agent.477184.62
8.3.2.4

avast!
Win32:Malware-gen
2014.9-160103

F-Prot
W32/Injector.EQ.gen
v6.4.7.1.166

G Data
Win32.Trojan.Agent.LMP5D7
16.1.25

IKARUS anti.virus
Trojan.Agent
t3scan.1.9.5.0

McAfee
Artemis!5AC7A39B6459
5600.6532

NANO AntiVirus
Trojan.Win32.Agent.dtucfa
1.0.14.5317

Quick Heal
(Suspicious) - DNAScan
1.16.14.00

Sophos
Mal/HckPk-D
4.98

Trend Micro
TROJ_GEN.R047C0EHE15
10.465.03

VIPRE Antivirus
Trojan.Win32.Generic
45948

ViRobot
Patcher.Cadence.477184[h]
2014.3.20.0

File size:
466 KB (477,184 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\patcher.exe

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:/LxW6fdzdLojxlTCMEI5rPQfgPfrFIfqSWYZZ+L:jxW6fdz1Qxl2kPsg7OfqSWK+L

Entry address:
0x114000

Entry point:
BE, FF, 17, 50, 00, 83, C6, 01, FF, E6, 00, 00, 00, 90, 64, D7, 01, 03, 00, 00, 00, 70, 02, 94, 04, 00, 10, 00, 00, 00, 00, 94, 04, 40, 01, 00, 00, D0, F0, 18, 00, B2, 4F, 45, 00, 00, F4, 18, 00, EF, 4F, 45, 00, D0, F0, 18, 00, 8C, D1, 42, 00, 64, 56, D7, 01, 00, 64, D7, 01, 50, 63, D7, 01, 3C, 25, D7, 01, 74, 24, D7, 01, D8, 24, D7, 01, 34, 50, 45, 00, 00, 64, D7, 01, FF, FF, 00, 00, 60, 24, D7, 01, A8, 35, D7, 01, F8, 35, D7, 01, 40, 00, 00, C0, 00, 00, 94, 04, 6C, 01, 00, 00, 40, 01, 00, 00, 64, 1E, D7...
 
[+]

Entropy:
7.5273

Packer / compiler:
UPXFreak V0.1

Code size:
396 KB (405,504 bytes)

The file patcher.exe has been seen being distributed by the following URL.

Remove patcher.exe - Powered by Reason Core Security