screen doom d'écron.exe

The executable screen doom d'écron.exe has been detected as malware by 18 anti-virus scanners. This backdoor trojan may be used to conduct distributed denial of service attacks, or used to install additional trojans or other forms of malicious software as well as can steal your sensitive information. The file has been seen being downloaded from www5.zippyshare.com.
MD5:
fe263886bcf0cdc3d7badd841ea498cc

SHA-1:
c3c9f08e4731c6d246a6df77b62979577b78c77c

SHA-256:
601a94986ec6970a9f39e5f7d9efd79ee31f1e2e945bc9dba0d93b18e4e55a19

Scanner detections:
18 / 68

Status:
Malware

Analysis date:
2/25/2025 9:11:26 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.365272
210

Avira AntiVirus
TR/Dropper.Gen7
8.3.3.4

Arcabit
Trojan.Kazy.D592D8
1.0.0.696

avast!
MSIL:Agent-BKZ [Trj]
2014.9-160709

AVG
Win32/Hedo
2017.0.2688

Baidu Antivirus
MSIL.Backdoor.Bladabindi
4.0.3.1679

Bitdefender
Gen:Variant.Kazy.365272
1.0.20.955

Emsisoft Anti-Malware
Gen:Variant.Kazy.365272
8.16.07.09.02

ESET NOD32
MSIL/Bladabindi.BI (variant)
10.13617

F-Secure
Gen:Variant.Kazy.365272
11.2016-09-07_7

G Data
Gen:Variant.Kazy.365272
16.7.25

IKARUS anti.virus
Trojan.MSIL.Bladabindi
t3scan.2.0.9.0

K7 AntiVirus
Trojan
13.227.19861

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi.AJ
1.1.12805.0

MicroWorld eScan
Gen:Variant.Kazy.365272
17.0.0.573

Qihoo 360 Security
HEUR/QVM03.0.0000.Malware.Gen
1.0.0.1120

Rising Antivirus
Backdoor.MSIL.Bladabindi!1.9E49
23.00.65.16707

Sophos
Troj/Bbindi-W
4.98

File size:
184 KB (188,416 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\screen doom d'écron.exe

File PE Metadata
Compilation timestamp:
6/7/2016 9:40:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:GMf6srFnk0a3jVrdsXUbpfm9FTp8v6/k6wWKSVoZev0rxvhHDf29w:3f6srK0a3jVrdRV4p8v6/k6wW4ZeQJHZ

Entry address:
0x2EED5

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3430

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
180 KB (184,320 bytes)

The file screen doom d'écron.exe has been seen being distributed by the following URL.

Remove screen doom d'écron.exe - Powered by Reason Core Security