vortexmine.exe

The executable vortexmine.exe has been detected as malware by 2 anti-virus scanners. The file has been seen being downloaded from fs13n5.sendspace.com.
MD5:
a6bccddc029909e60d10cb4e7ebaad0c

SHA-1:
b1f575d71cc3fdb6229590b1d427d2517178d903

SHA-256:
2485a32f9458b94ecb56d018d018211fe104735155f7b1653579530d44ac4134

Scanner detections:
2 / 68

Status:
Malware

Analysis date:
12/26/2024 12:07:58 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/Bladabindi.BC trojan
8.0.319.0

Microsoft Security Essentials
Threat.Undefined
1.225.610.0

File size:
192 KB (196,608 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\vortexmine.exe

File PE Metadata
Compilation timestamp:
5/29/2016 8:53:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:Mq420+4quYrgtyonMcd++lCpPEqOU5NHl1M7DlPQ2x0LnfkY2RpOIgdH7U:J4quY27nMQ+oiNHIKVcY2vUH

Entry address:
0x747E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5780

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
21.5 KB (22,016 bytes)

The file vortexmine.exe has been seen being distributed by the following URL.

Remove vortexmine.exe - Powered by Reason Core Security