setup1838881717.exe

The executable setup1838881717.exe has been detected as malware by 2 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from baraovascu.sslblindado.com and multiple other hosts.
Version:
0.0.0.0

MD5:
949d881fc219c545259d39ad3b6f5b95

SHA-1:
5b04fda59c250ea59461f320f8b78469689600fc

SHA-256:
3c2f6390af0d58b38be6c20f6711d413b104a20f8f11fc48039e95e0acb228da

Scanner detections:
2 / 68

Status:
Malware

Analysis date:
11/14/2024 9:11:33 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/TrojanDownloader.Agent.BGK trojan
8.0.319.0

Norman
Gen:Variant.Razy.30489
29.03.2016 06:29:16

File size:
394 KB (403,456 bytes)

Product version:
0.0.0.0

Original file name:
Loader-OXGLPKOGTB.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup1838881717.exe

File PE Metadata
Compilation timestamp:
3/28/2016 7:31:15 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:1WbJFyoxhGCP3auHJWYVn7tXd0KfudyKF8D9fkjfGG+4GGbeGGFeGGAGwGWGGEGk:/9qNdmdyKFA9fkji66TRmaKdM2

Entry address:
0x598C2

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
350.5 KB (358,912 bytes)

The file setup1838881717.exe has been seen being distributed by the following 2 URLs.

http://86.105.227.161/flashplayer_versoes.php

Remove setup1838881717.exe - Powered by Reason Core Security