torrent_shazam_1.exe

The executable torrent_shazam_1.exe has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from ojv0enbdgnltq50.vrnserver.ru.
Version:
1.0.0.0

MD5:
1a6c5dc95e3286a4562c0c64241a0d45

SHA-1:
c3aa0f56c040ddf90c2a50df82f45ccd2e46a5e9

SHA-256:
512378562f51cc7f928c81a41fc65ee0deafd08b61185a2cc7d7afb5440f57de

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/25/2024 12:53:07 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.2.3.5

File size:
7.4 MB (7,773,440 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\torrent_shazam_1.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:FmCdJmZIHFhDsvfAPXvewzSIXvewzSY0stAQmFcm:LdJmWkYPX2wlX2wRtwp

Entry address:
0x30BAD0

Entry point:
55, 8B, EC, 83, C4, EC, 53, B8, 00, AF, 70, 00, E8, DB, BF, CF, FF, 33, C0, 55, 68, 82, BC, 70, 00, 64, FF, 30, 64, 89, 20, E8, AC, AF, DF, FF, 85, C0, 74, 1D, E8, A3, AF, DF, FF, 0F, B7, 04, 45, 66, B9, 72, 00, 89, 45, EC, DB, 45, EC, E8, 40, 72, CF, FF, E8, 4B, 94, CF, FF, B8, CC, 4A, 73, 00, E8, FD, 94, CF, FF, A1, CC, 4A, 73, 00, E8, C3, 97, CF, FF, 8B, D8, E8, 70, AF, DF, FF, 3B, D8, 0F, 85, E4, 00, 00, 00, C7, 05, C8, 4A, 73, 00, 20, 00, 00, 00, A1, C8, 4A, 73, 00, E8, A0, D3, CF, FF, 68, D0, 4A, 73...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3 MB (3,190,272 bytes)

The file torrent_shazam_1.exe has been seen being distributed by the following URL.

Remove torrent_shazam_1.exe - Powered by Reason Core Security