qgc19s5aww3.exe

IPv6Chat

MantaNet

Publisher:
MantaNet

Product:
IPv6Chat

Version:
1.00

MD5:
c34b6eaca47e5db4a3a931e39a9b3b75

SHA-1:
54ec1914089176ad8ec88014a1f35f8a9552eba9

SHA-256:
480df4b2f57671d495761976f7b5da4a80f703316fee8aed8063a5ebccf3e543

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
1/13/2025 8:37:49 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/VB.SDT trojan
8.0.319.0

File size:
88 KB (90,112 bytes)

Product version:
1.00

Original file name:
bana.exe

File type:
Executable application (Win32 EXE)

Language:
Spanish

Common path:
C:\users\{user}\appdata\local\temp\qgc19s5aww3.exe

File PE Metadata
Compilation timestamp:
5/30/2016 9:29:39 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:4s85WUM+Wnx94hhDyF5aQPgawomM9sSZrj:4L5WU8v4XDyD9+C

Entry address:
0x1BC8

Entry point:
68, EC, 1E, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 2C, 9E, 6A, BE, F6, A2, 51, 4D, BE, 05, 32, D0, 50, C8, AA, 9B, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 30, 32, 30, 34, 33, 30, 49, 50, 76, 36, 43, 68, 61, 74, 00, 30, 2D, 43, 30, 30, 30, 2D, 00, 00, 00, 00, FF, CC, 31, 00, 08, 76, 7A, 10, 49, 82, F3, 24, 45, B8, 59, EB, F7, A2, 82, D6, 82, FD, 20, C1, 9F, 26, 8A, 2E, 4C, B4, B1, DE, 61, 90, 56, 75, 09, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
5.2530

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
76 KB (77,824 bytes)

The file qgc19s5aww3.exe has been seen being distributed by the following URL.

Scan qgc19s5aww3.exe - Powered by Reason Core Security