rufus-2.5p.exe

Rufus

Akeo Consulting (http://akeo.ie)

The executable rufus-2.5p.exe has been detected as malware by 9 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from rufus.akeo.ie.
Publisher:
Akeo Consulting (http://akeo.ie)

Product:
Rufus

Version:
2.5.799

MD5:
94f1d7035f04015d545de78be3d4cadb

SHA-1:
71d228ce621d6adba3efe2d6ee988fc6c9d4972d

SHA-256:
121a406d3b9d59441d3008ed7c8299c5f6e05fe09373091b1dcc19b7b6ba4ba7

Scanner detections:
9 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/24/2024 12:01:22 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160518-2

AVG
Win32/Sality
2015.0.4604

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.2886.0

Norman
Win32.Sality.3
22.05.2016 07:18:28

VIPRE Antivirus
Threat.4721115
50308

File size:
914.4 KB (936,360 bytes)

Product version:
2.5.799

Copyright:
© 2011-2015 Pete Batard (GPL v3)

Trademarks:
http://www.gnu.org/copyleft/gpl.html

Original file name:
rufus.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\rufus-2.5p.exe

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:DRsX4xt5STYdCgzYEnGAzgivSfCFqQofrkYC26amjNKgTwl5jCtgx:DRW4xt507GYGkZnrkYC26ZMgElRx

Entry address:
0x22E150

Entry point:
69, DA, 81, 91, F6, 70, 0F, AF, ED, 25, C1, 4B, CD, 61, 14, F8, C7, C7, 4B, 82, 76, AD, BA, 8A, 93, 98, E6, 4F, F2, 69, EE, E0, C8, 72, 75, B9, 4D, 6B, 00, 00, 80, C8, DB, 81, F1, BB, 6E, 00, 00, 87, DF, FF, CB, 8B, DB, 81, F1, 62, 0C, 00, 00, 31, DB, 80, DA, 1B, 03, F1, FE, CC, 81, EE, 4D, 02, 00, 00, 41, 3A, FA, 0F, AF, E8, 2A, EE, 0F, B7, FD, 24, ED, 89, C5, C6, C0, E4, 80, DC, C2, E8, A1, 00, 00, 00, 1D, CF, EB, 72, 45, 2C, DD, 22, F5, 80, E5, 2B, 84, FF, 85, F9, 0F, AF, C9, 14, A1, 49, 6A, 00, 5F, 4B...
 
[+]

Entropy:
7.9467  (probably packed)

Code size:
796 KB (815,104 bytes)

The file rufus-2.5p.exe has been seen being distributed by the following URL.

Remove rufus-2.5p.exe - Powered by Reason Core Security