Shield.exe

Shield Application

The executable Shield.exe has been detected as malware by 12 anti-virus scanners. While running, it connects to the Internet address conformite-logiciels.com on port 80 using the HTTP protocol.
Product:
Shield Application

Version:
1.0.0.13

MD5:
f5f1df8e53eee0960bddc189d391396a

SHA-1:
a9ae2d20a2138e7cf163fb64512add6eaf3759d6

SHA-256:
74fa177d0818c3f676ced701438052286dd6e78f8726aaacfb5dd889db729db8

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
11/23/2024 7:46:14 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur2.JP.jw0@aKaQfGfO
320

Avira AntiVirus
TR/Patched.Gen
8.3.3.2

Arcabit
Trojan.Heur2.JP.E7A036
1.0.0.662

avast!
Win32:Xpirat-B
2014.9-160321

Bitdefender
Gen:Trojan.Heur2.JP.jw0@aKaQfGfO
1.0.20.405

Bkav FE
HW32.Packed
1.3.0.7744

Emsisoft Anti-Malware
Gen:Trojan.Heur2.JP.jw0@aKaQfGfO
8.16.03.21.11

F-Secure
Gen:Trojan.Heur2.JP.jw0@aKaQfGfO
11.2016-21-03_2

G Data
Gen:Trojan.Heur2.JP.jw0@aKaQfGfO
16.3.25

IKARUS anti.virus
Virus.Win32.Tanatos
t3scan.2.0.9.0

MicroWorld eScan
Gen:Trojan.Heur2.JP.jw0@aKaQfGfO
17.0.0.243

Qihoo 360 Security
Win32/Trojan.3c4
1.0.0.1120

File size:
2.2 MB (2,259,456 bytes)

Product version:
1.0.0.13

Copyright:
Copyright (C) 2014

Original file name:
Shield.exe

File type:
Executable application (Win32 EXE)

Language:
Polish (Poland)

File PE Metadata
Compilation timestamp:
3/5/2016 5:40:57 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:S/HfsPT82RcDmVdPSPdSRcDGztIRiQOziZf:S/k/RvP+SRpeAziZf

Entry address:
0x3E27B

Entry point:
E8, 4C, 46, 01, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 00, 29, 48, 00, E8, 4F, 54, 00, 00, E8, D0, 06, 00, 00, 0F, B7, F0, 6A, 02, E8, DF, 45, 01, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, F7, 58, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
446 KB (456,704 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to conformite-logiciels.com  (134.170.185.46:80)

Remove Shield.exe - Powered by Reason Core Security