s1a0

The file s1a0 has been detected as malware by 13 anti-virus scanners. The file has been seen being downloaded from cssetti.pl and multiple other hosts.
MD5:
e95f3d8e1705a6954bb5424c083568ee

SHA-1:
90115b7cd19582fed8963247a6f5b666895189d9

SHA-256:
9013781108825792b529f64422e2d426f4ff9565071a29b63ce084751851a52a

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
11/17/2024 9:33:40 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Kazy
7.1.1

Avira AntiVirus
TR/Kazy.145408.5
8.3.1.6

avast!
Win32:Malware-gen
2014.9-160215

Comodo Security
UnclassifiedMalware
22763

Fortinet FortiGate
W32/Dx.D2G!tr
2/15/2016

G Data
Win32.Trojan.Agent.9EJBW5
16.2.25

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.9.5.0

McAfee
RDN/Generic.dx!d2g
5600.6489

NANO AntiVirus
Trojan.Win32.Kazy.dmlugv
0.30.24.2487

Qihoo 360 Security
Win32/Trojan.aaf
1.0.0.1015

Trend Micro
TROJ_GEN.R00UC0EAP15
10.465.15

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
42004

File size:
142 KB (145,408 bytes)

Common path:
C:\users\{user}\appdata\local\virtualstore\s1a0

File PE Metadata
Compilation timestamp:
1/7/2015 12:50:18 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.22

CTPH (ssdeep):
3072:i683mpk7RfuARSek11f1SbYFvuJLm68KG+eOMq+IommJkyAaLkCT99FhRp9:9YCk713k1K09E8D+EIoRWrgbFhRp

Entry address:
0x92190

Entry point:
80, 7C, 24, 08, 01, 0F, 85, F9, 01, 00, 00, 60, BE, 15, F0, 1A, 69, 8D, BE, EB, 1F, F9, FF, C7, 87, 58, 50, 08, 00, 22, D8, 38, 92, 57, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03...
 
[+]

Code size:
144 KB (147,456 bytes)

The file s1a0 has been seen being distributed by the following 2 URLs.

Remove s1a0 - Powered by Reason Core Security