RC7 Exploit.exe

Google Chrome

LunarG, Inc.

The executable RC7 Exploit.exe has been detected as malware by 11 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www96.zippyshare.com.
Publisher:
Google Inc.  (signed by LunarG, Inc.)

Product:
Google Chrome

Version:
50.0.2661

MD5:
54b9ce77048234509448cf649891a0ff

SHA-1:
98d5fd44df6d62fb01d920fce63b44af4e3c8809

SHA-256:
a9015c31742bbd7f315a5273b02e1752dbdf78d95bba41562179645b84091216

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
11/24/2024 10:00:28 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.MSIL.ulso
8.3.3.4

AVG
Luhe.MSIL.D
2017.0.2687

Dr.Web
Trojan.Fsysna.3434
9.0.1.0191

ESET NOD32
MSIL/Injector.PKT (variant)
10.13591

Fortinet FortiGate
MSIL/Kryptik.GEC!tr
7/9/2016

K7 AntiVirus
Trojan
13.227.19805

McAfee
Artemis!54B9CE770482
5600.6343

Microsoft Security Essentials
Trojan:Win32/Dynamer!ac
1.1.12805.0

NANO AntiVirus
Trojan.Win32.Fsysna.ecyqlp
1.0.30.8482

Qihoo 360 Security
HEUR/QVM03.0.0000.Malware.Gen
1.0.0.1120

Rising Antivirus
Trojan.FakeChrome!1.9C7B
23.00.65.16707

File size:
1.1 MB (1,133,848 bytes)

Product version:
50.0.2661

Copyright:
Copyright 2015 Google Inc. All rights reserved.

Original file name:
RC7 Exploit.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\rc7 exploit.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
4/30/2015 3:00:00 AM

Valid to:
7/6/2016 3:00:00 PM

Subject:
CN="LunarG, Inc.", O="LunarG, Inc.", L=Fort Collins, S=Colorado, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0E6604A4FB50DA2058E2F0B6006ABABB

File PE Metadata
Compilation timestamp:
5/30/2016 7:54:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:j900HmZpak0EKConDE/Sl1GmWfvwz2KHoZq4bDvKiKK:GrKC7zvKiKK

Entry address:
0xDEE0E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
884 KB (905,216 bytes)

The file RC7 Exploit.exe has been seen being distributed by the following URL.

Remove RC7 Exploit.exe - Powered by Reason Core Security