paypal money.exe

WindowsApplication1

The executable paypal money.exe has been detected as malware by 20 anti-virus scanners. The file has been seen being downloaded from download616.mediafire.com.
Publisher:
Microsoft*  (Invalid match)

Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
c833cc71acc25751fbb9f9fb79840e77

SHA-1:
7bdc9ec591ad1237131b2e5ef7631b71cf0ccad8

SHA-256:
0ce010ae12eef1738bdd1f44b038300386ab2facc3db752fcfb1e824f0437f21

Scanner detections:
20 / 68

Status:
Malware

Analysis date:
12/26/2024 7:05:39 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1617117
274

Agnitum Outpost
Trojan.FakeTool
7.1.1

Avira AntiVirus
TR/Rogue.77826
7.11.141.156

AVG
MSIL2
2017.0.2752

Baidu Antivirus
Trojan.MSIL.FakeTool
4.0.3.1656

Bitdefender
Trojan.GenericKD.1617117
1.0.20.635

Emsisoft Anti-Malware
Trojan.GenericKD.1617117
8.16.05.06.10

ESET NOD32
MSIL/FakeTool.FM
10.9639

Fortinet FortiGate
MSIL/FakeTool.FM
5/6/2016

F-Secure
Trojan.GenericKD.1617117
11.2016-06-05_6

G Data
Trojan.GenericKD.1617117
16.5.24

IKARUS anti.virus
Trojan.MSIL2
t3scan.2.2.29

K7 AntiVirus
Hacktool
13.176.11663

McAfee
Artemis!C833CC71ACC2
5600.6408

MicroWorld eScan
Trojan.GenericKD.1617117
17.0.0.381

Norman
Suspicious_Gen5.ANMSU
11.20160506

nProtect
Trojan.GenericKD.1617117
14.04.06.01

Qihoo 360 Security
Win32/Trojan.648
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R08NB01D114
7.2.127

VIPRE Antivirus
Trojan.Win32.Generic
28082

File size:
76 KB (77,826 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Microsoft 2013

Original file name:
Paypal Hack.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\paypal money.exe

File PE Metadata
Compilation timestamp:
12/1/2013 5:30:19 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:V6CdDDdDDdDDdDDdk5vW7gYyMlQ4UU43/wfFi6SydBYmd1gPYh:V6CdDDdDDdDDdDDdQvWTyKL6/wipydBf

Entry address:
0x13B3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.2446

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
71 KB (72,704 bytes)

The file paypal money.exe has been seen being distributed by the following URL.

Remove paypal money.exe - Powered by Reason Core Security