update_mrs_fath_3.1.2_rev-1.exe

The executable update_mrs_fath_3.1.2_rev-1.exe has been detected as malware by 13 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.mrstools.com.
MD5:
4e8bf63df0bc430b585d24c64bcb8273

SHA-1:
186acb4de0ce35d5e43639ce0682835a2a2079da

SHA-256:
23272b509cf3d07bacc464e6270a53a08f86087618472065fdd2f07ffbb1b580

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
12/27/2024 5:31:44 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/RLPack
7.1.1

avast!
Win32:Malware-gen
2014.9-151030

AVG
Win32/PolyCrypt
2016.0.2940

Comodo Security
UnclassifiedMalware
23320

F-Prot
W32/Bredolab.O.gen
v6.4.7.1.166

F-Secure
Gen:Packer.RLPack.D.HjWaaek1pcai
11.2015-30-10_6

G Data
Win32.Trojan.Agent.6BH9Z6
15.10.25

IKARUS anti.virus
Win32.PolyCrypt
t3scan.1.9.5.0

Malwarebytes
Trojan.Agent
v2015.10.30.04

McAfee
Artemis!4E8BF63DF0BC
5600.6596

Qihoo 360 Security
HEUR/Malware.QVM18.Gen
1.0.0.1015

Trend Micro
TROJ_GEN.R0CBC0ECJ15
10.465.30

VIPRE Antivirus
Trojan.Win32.Generic
44136

File size:
13.7 MB (14,366,408 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\programs\update_mrs_fath_3.1.2_rev-1.exe

File PE Metadata
Compilation timestamp:
8/16/2009 1:05:35 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
393216:JTsWJ03OPMRVaDkWElbCW4/xxkITe6/vmmykl6G0:JsWJ03KMRoDkTVCh5xkIT1WmYv

Entry address:
0x117F0

Entry point:
EB, 02, 90, 90, 90, E9, 06, F8, 04, 00, C3, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9968

Packer / compiler:
FSG v1.10 (Microsoft Visual C++ 6.0 / 7.0)

Code size:
66 KB (67,584 bytes)

The file update_mrs_fath_3.1.2_rev-1.exe has been seen being distributed by the following URL.

Remove update_mrs_fath_3.1.2_rev-1.exe - Powered by Reason Core Security