t145233.exe

The application t145233.exe has been detected as a potentially unwanted program by 5 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dlt3.mail.ru.
MD5:
35e1f9a5924b3bbb72c818b376f2113d

SHA-1:
f03a6d173e68510b2a7528ba36f562ab927114c3

SHA-256:
2cf9dd44f8f40c67d3bfad0aa1b85da7273fbeda5d802b77327ed7954444eb2b

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 1:56:12 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:LoadMoney-AGH [PUP]
160708-3

Emsisoft Anti-Malware
Gen:Variant.Application.LoadMoney.76
11.5.0.6191

ESET NOD32
Win32/LoadMoney.A potentially unwanted application
7.0.302.0

F-Prot
W32/Agent.RC.gen!Eldorado (generic, damaged, not disinfectable)
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.225.1925.0

File size:
51.4 KB (52,672 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\t145233.exe

File PE Metadata
Compilation timestamp:
12/24/2012 5:42:49 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:Q2DUwYfXOhLW0WkWMtmBVuLZKVW6Dhfi2l/vH9Nw0NIUMpcnMFsPF1IK/:W/vsW0WkWHVwZMi2l/3IPAMQIO

Entry address:
0x1ECC

Entry point:
55, 8B, EC, 51, 51, 83, 65, FC, 00, 8D, 45, FC, 50, FF, 15, 74, 90, 40, 00, 50, FF, 15, C4, 90, 40, 00, 89, 45, F8, FF, 75, F8, FF, 75, FC, E8, A4, 3E, 00, 00, 59, 59, 50, FF, 15, 70, 90, 40, 00, C9, C3, 55, 8B, EC, 51, 89, 4D, FC, 8B, 45, FC, C7, 00, FC, 93, 40, 00, 6A, 00, FF, 15, 78, 90, 40, 00, 8B, 4D, FC, 89, 41, 04, 8B, 45, FC, 83, 60, 08, 00, 8B, 45, FC, 8B, 4D, 08, 89, 48, 0C, 8B, 45, FC, C9, C2, 04, 00, 55, 8B, EC, 51, 89, 4D, FC, 33, C0, C9, C3, 55, 8B, EC, 51, 89, 4D, FC, C9, C3, 55, 8B, EC, 51...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
32 KB (32,768 bytes)

The file t145233.exe has been seen being distributed by the following URL.

Remove t145233.exe - Powered by Reason Core Security