smadav93.exe

The executable smadav93.exe has been detected as malware by 4 anti-virus scanners. The file has been seen being downloaded from www.unjuk.com.
MD5:
3208aef87870561b2222a72b9ee67abd

SHA-1:
7e31789811259d6c802c30a4f14bbc9d39412f21

SHA-256:
c0c28d99fa5e6b42e520320140fed58b0608013099287245f457836d00cf982d

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
11/27/2024 1:25:17 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
150717-0

AVG
Win32/Sality
2015.0.4545

Dr.Web
modification of Win32.Sector.21
9.0.1.05190

F-Prot
W32/Sality.gen2
4.6.5.141

File size:
194.3 KB (198,934 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\smadav93.exe

File PE Metadata
Compilation timestamp:
5/28/2011 11:04:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:m4lRkAehGfbmuqTPryFzcE8yiXG+LHzuWnFYoLcC:m4lRkAehaSuqT+FV8lXG+LHzuSFbYC

Entry address:
0xB480

Entry point:
86, EB, 88, C3, 3C, 82, 89, CE, 8B, DE, C7, C7, 54, 2A, 74, 20, 23, CD, C7, C6, 88, EC, 03, 9D, 34, 33, 03, D9, 8A, C1, 8A, E6, 89, F0, E8, 12, 00, 00, 00, 8D, 3D, EC, 15, 34, C0, 31, DD, F2, 75, 05, 0F, BF, F8, FF, C6, 3B, CF, 8A, EE, 04, DB, 89, EF, 0F, AF, FE, 72, 04, 89, C0, 89, EB, 88, FB, 8D, 13, 69, C3, 53, 61, C2, A0, 84, F3, B8, 26, D7, A2, 4B, B1, F0, 88, E5, 33, EA, F6, C4, BC, 59, EB, 0D, BB, BD, 8E, 52, 19, 87, FF, 69, E9, 9D, E6, 93, 5A, 8D, 1D, 50, 69, 56, 48, 0F, B7, F3, F6, C2, FD, C6, C2...
 
[+]

Entropy:
6.7474

Code size:
70.5 KB (72,192 bytes)

The file smadav93.exe has been seen being distributed by the following URL.

Remove smadav93.exe - Powered by Reason Core Security