statie.exe

Rambler Internet Holdings LLC

Publisher:
Rambler Internet Holdings LLC  (signed and verified)

MD5:
aeb057e3d88d2e3e83374fe6483653f0

SHA-1:
837312828f65c0bd4013f4c2519daed280ae328d

SHA-256:
de093b4cfe09ef933270b2d22ca927d536f62bd1aece0b6b655250c66c495a1e

Scanner detections:
5 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/15/2024 1:45:13 PM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
Trojan-Spy.Zbot
t3scan.1.9.5.0

McAfee
Artemis!AEB057E3D88D
5600.6254

Panda Antivirus
Trj/Genetic.gen
16.10.06.01

Trend Micro House Call
Suspicious_GEN.F47V0515
7.2.280

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
336.8 KB (344,856 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\statie.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
10/18/2012 3:00:00 AM

Valid to:
11/18/2014 2:59:59 AM

Subject:
CN=Rambler Internet Holdings LLC, OU=Secure Application Development, O=Rambler Internet Holdings LLC, L=Moscow, S=Russian Federation, C=RU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1F16C544CA274B10D7E261A60524E806

File PE Metadata
Compilation timestamp:
3/5/2013 3:26:01 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:u6ch235h6taul/MkkNED0on/gmAtXsOZbGTBp9CREeWH5BiMPbYHOoXgpH95zb4:nO6ca+UkHenbGM2H5BiMPqa5

Entry address:
0x122E

Entry point:
E8, FF, 15, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, F8, A5, 40, 00, FF, 15, 1C, 60, 40, 00, 85, C0, 75, 18, 56, E8, B1, 16, 00, 00, 8B, F0, FF, 15, 18, 60, 40, 00, 50, E8, 61, 16, 00, 00, 59, 89, 06, 5E, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 04, 8B, 4C, 24, 08, F7, C2, 03, 00, 00, 00, 75, 3C, 8B, 02, 3A, 01, 75, 2E, 0A, C0, 74, 26, 3A, 61, 01, 75, 25, 0A, E4, 74, 1D, C1, E8, 10, 3A, 41, 02, 75, 19, 0A, C0, 74...
 
[+]

Code size:
18 KB (18,432 bytes)

Scan statie.exe - Powered by Reason Core Security