totalvpn.exe

The executable totalvpn.exe has been detected as malware by 7 anti-virus scanners. The file has been seen being downloaded from my.totalvpn.com.
MD5:
070a80dd0880bfd1654e76761270dcf9

SHA-1:
f44ca4fb27ecbc89e7d49ef07be9338da50279e4

SHA-256:
e310e0ce99278a7fd0af4eee531e6e5ec00542ad7b4b181a30f2d7bba2e56edc

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
11/24/2024 10:22:31 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:AutoRun-CWJ [Trj]
160503-1

Dr.Web
Trojan.Siggen6.55368
9.0.1.05190

ESET NOD32
Win32/AutoRun.Delf.LV worm
8.0.319.0

F-Prot
W32/Autorun.ZF
4.6.5.141

F-Secure
Trojan.Generic.KDV.391478
5.15.96

Microsoft Security Essentials
Threat.Undefined
1.223.850.0

Norman
Trojan.Generic.KDV.391478
22.05.2016 07:18:28

File size:
824.5 KB (844,288 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\totalvpn.exe

File PE Metadata
Compilation timestamp:
8/9/2011 12:51:42 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:1wCBtLC+EptUpQ9SeSChq3YvxFBSSRMT8PTp4ehozEq888888888888W8888888J:ZNzCtUpQ9WWPBSSRMTEpXNw

Entry address:
0xABD46

Entry point:
B9, 88, 42, 00, 00, 14, BD, EB, 0B, 00, 00, 00, 00, 05, C6, 00, 1A, 51, 00, E3, 80, EC, 8B, 39, C8, 85, C2, 8D, 95, 73, 26, CE, DA, 86, E6, F6, D2, F8, 81, A9, 00, A4, 4D, 00, 33, 09, F6, 84, EB, 9F, 00, 00, 00, BF, C9, 54, D0, 49, 66, 50, 00, 04, 89, 52, DD, 44, 4B, 4A, 81, 13, 00, 65, F1, 5C, 6C, 00, 26, 84, C8, FE, 5C, 0E, 6C, F6, 3B, 00, 55, A6, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5228

Code size:
682.5 KB (698,880 bytes)

The file totalvpn.exe has been seen being distributed by the following URL.

Remove totalvpn.exe - Powered by Reason Core Security