tibicam ng 1.3.exe

NGSoft

The application tibicam ng 1.3.exe, “TibiCam NG Setup ” has been detected as a potentially unwanted program by 23 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from s10002.chomikuj.pl.
Publisher:
NGSoft

Description:
TibiCam NG Setup

MD5:
94d2a2ab9934a8503e2c5165e9b08582

SHA-1:
63264988d0d172a4734a7bc9b4eec77f05348820

SHA-256:
4f67ebb292d034e1330136e477c877604090d19ce5e6bdba758f2ede81006009

Scanner detections:
23 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 8:03:20 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.IS.562302
308

Agnitum Outpost
Backdoor.Msynky
7.1.1

Avira AntiVirus
TR/Spyware.GEO
7.11.214.42

avast!
Win32:Msynky [PUP]
2014.9-160402

AVG
BackDoor.Generic9
2017.0.2786

Bitdefender
Trojan.Generic.IS.562302
1.0.20.465

Clam AntiVirus
Win.Trojan.Agent-647525
0.98/21511

Comodo Security
Backdoor.Win32.Msynky.f
21311

Dr.Web
BackDoor.Siggen.13804
9.0.1.093

Emsisoft Anti-Malware
Trojan.Generic.IS.562302
8.16.04.02.01

F-Prot
W32/Backdoor2.CSTW
v6.4.7.1.166

F-Secure
Trojan.Generic.IS.562302
11.2016-02-04_7

G Data
Trojan.Generic.IS.562302
16.4.25

IKARUS anti.virus
Trojan.Injector
t3scan.1.8.6.0

MicroWorld eScan
Trojan.Generic.IS.562302
17.0.0.279

NANO AntiVirus
Trojan.Win32.Msynky.bdszr
0.30.0.296

Norman
Suspicious_Gen2.TPEDE
11.20160402

nProtect
Trojan.Generic.IS.562302
15.03.06.01

Qihoo 360 Security
Win32/Trojan.Spy.a6a
1.0.0.1015

Quick Heal
Backdoor.Msynky.f.n6
4.16.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.12533AA3!307444387
23.00.65.16331

Vba32 AntiVirus
TrojanPWS.Banker
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
38168

File size:
1.1 MB (1,173,539 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\tibicam ng 1.3.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:xjRG7outdRQcJKrHpvafAmtTvupTwaS1aOGFq2daMtXo1XGfHStW5ibT:TG7oKArHAfAmtz2w5gf3o12fH15if

Entry address:
0xBD78

Entry point:
55, 8B, EC, 83, C4, AC, 53, 56, 57, 33, C0, 89, 45, C8, 89, 45, C4, 89, 45, C0, 89, 45, AC, 89, 45, CC, 89, 45, D0, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 80, BC, 40, 00, E8, 58, 8A, FF, FF, 33, C0, 55, 68, 37, C4, 40, 00, 64, FF, 30, 64, 89, 20, E8, B9, 8B, FF, FF, 33, D2, 55, 68, E0, C3, 40, 00, 64, FF, 32, 64, 89, 22, A1, 10, E7, 40, 00, E8, 59, FD, FF, FF, E8, 0C, F9, FF, FF, 8D, 55, EC, 33, C0, E8, 42, CC, FF, FF, 8B, 55, EC, B8, 20, F1, 40, 00, E8, 01, 7B, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 20...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
45.5 KB (46,592 bytes)

The file tibicam ng 1.3.exe has been seen being distributed by the following URL.

Remove tibicam ng 1.3.exe - Powered by Reason Core Security