soufi.exe

soufi

The executable soufi.exe has been detected as malware by 27 anti-virus scanners. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from www.exeupp.com.
Product:
soufi

Version:
1.0.0.0

MD5:
8786d5c9cdacc97012f56d901d3076ab

SHA-1:
863b4af1d91234d5151ec028a03e579cb35d3910

SHA-256:
46d0eae4445f638364dfe4625b8c38faa23a95fd4857793be9c5b09202a8f1c2

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
11/27/2024 8:51:17 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.3013732
312

AegisLab AV Signature
Troj.W32.Gen
2.1.4+

Agnitum Outpost
Trojan.Zapchast
7.1.1

Avira AntiVirus
TR/Downloader.A.28989
8.3.3.2

Arcabit
Trojan.Generic.D2DFC64
1.0.0.653

avast!
Win32:Malware-gen
2014.9-160329

AVG
Downloader.MSIL
2017.0.2790

Baidu Antivirus
Trojan.MSIL.Agent
4.0.3.16329

Bitdefender
Trojan.GenericKD.3013732
1.0.20.445

Dr.Web
Trojan.DownLoader17.55704
9.0.1.089

Emsisoft Anti-Malware
Trojan.GenericKD.3013732
8.16.03.29.10

ESET NOD32
MSIL/TrojanDownloader.Agent.AOV (variant)
10.13012

Fortinet FortiGate
MSIL/Agent.BEL!tr.dldr
3/29/2016

F-Secure
Trojan.GenericKD.3013732
11.2016-29-03_3

G Data
Trojan.GenericKD.3013732
16.3.25

IKARUS anti.virus
Trojan-Downloader.MSIL.Agent
t3scan.2.0.6.0

Kaspersky
Trojan.MSIL.Zapchast
14.0.0.443

McAfee
RDN/Generic Downloader.x
5600.6446

Microsoft Security Essentials
Trojan:Win32/Skeeyah.A!rfn
1.1.12400.0

MicroWorld eScan
Trojan.GenericKD.3013732
17.0.0.267

nProtect
Trojan.GenericKD.3013732
16.02.05.01

Panda Antivirus
Trj/CI.A
16.03.29.10

Qihoo 360 Security
Win32/Trojan.Downloader.06f
1.0.0.1120

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16327

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R00XC0DAU16
10.465.29

VIPRE Antivirus
Trojan.Win32.Generic
47128

File size:
26.5 KB (27,136 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2016

Original file name:
soufi.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\soufi.exe

File PE Metadata
Compilation timestamp:
1/25/2016 10:30:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:Z7qQm8SyFsuVvF2phloXvwB7c3IRLk245nuoj/V17KSQhSpf:Z7qWnsiqlEswIFRmpf

Entry address:
0x508E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.6343

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
12.5 KB (12,800 bytes)

The file soufi.exe has been seen being distributed by the following URL.

Remove soufi.exe - Powered by Reason Core Security