super.exe

MD5:
980d5a850081f46db12070888e6edb89

SHA-1:
2d76804b622f8bf9a78fb2ddcc94330ea74f2e74

Scanner detections:
5 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/26/2024 2:03:08 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.CDB
1.3.0.4246

Comodo Security
Packed.Win32.MPEC.Gen
16997

Malwarebytes
Trojan.Downloader
v2014.05.16.03

Quick Heal
(Suspicious) - DNAScan
5.14.12.00

ViRobot
Trojan.Win32.A.ShipUp.698368
2011.4.7.4223

File size:
682 KB (698,368 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\erightsoft-super\super\super.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:MmT1qBhN6AaINqJKA9DQHHVDmRrVPWVWS1IckzNWg6fUGu8qAjhJDGbZPuDjN:BT07YdINqjDQnVDm9dwhLkgLfUZ8qqhd

Entry address:
0x526BD6

Entry point:
E9, 25, E4, FF, FF, 00, 00, 00, 10, 61, 71, CB, 1E, 6C, 52, 00, 00, 00, 00, 00, 00, 00, 00, 00, 3E, 6C, 52, 00, 2E, 6C, 52, 00, 26, 6C, 52, 00, 00, 00, 00, 00, 00, 00, 00, 00, 4B, 6C, 52, 00, 36, 6C, 52, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 56, 6C, 52, 00, 00, 00, 00, 00, 69, 6C, 52, 00, 00, 00, 00, 00, 56, 6C, 52, 00, 00, 00, 00, 00, 69, 6C, 52, 00, 00, 00, 00, 00, 6B, 65, 72, 6E, 65, 6C, 33, 32, 2E, 64, 6C, 6C, 00, 75, 73, 65, 72, 33, 32, 2E, 64, 6C, 6C, 00...
 
[+]

Packer / compiler:
tElock v0.98

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to erightsoft.info  (167.114.71.77:80)

Scan super.exe - Powered by Reason Core Security