vosteran.exe

The application vosteran.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. This file is typically installed with the program Vosteran which is a potentially unwanted software program.
Version:
31.0.1650.23

MD5:
6a29bbb10b6149f6aa0df401173e6ddc

SHA-1:
835bfdf14eb012fbfaea30b5a1a637ac2a1166c0

SHA-256:
f64d8507d8bf351426bef222488987d28523dd8c852e151e9d5d91e37718b2f3

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 2:23:16 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Browser.FakeBrowser.A
739

Baidu Antivirus
Hacktool.Win32.ADInstaller
4.0.3.15311

Bitdefender
Application.Browser.FakeBrowser.A
1.0.20.130

Emsisoft Anti-Malware
Trojan.Generic.12750616
8.15.03.11.01

F-Secure
Application.Browser.FakeBrowser
11.2015-26-01_2

G Data
Application.Browser.FakeBrowser
15.1.25

Kaspersky
not-a-virus:RiskTool.Win32.ADInstaller
14.0.0.2362

Malwarebytes
PUP.Optional.Vosteran
v2015.01.26.09

MicroWorld eScan
Application.Browser.FakeBrowser.A
16.0.0.78

Panda Antivirus
Generic Suspicious
15.03.11.01

Qihoo 360 Security
Win32/Virus.RiskTool.a62
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.11.13

File size:
990.5 KB (1,014,272 bytes)

Product version:
31.0.1650.23

Original file name:
vosteran.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\vosteran\application\vosteran.exe

File PE Metadata
Compilation timestamp:
1/24/2015 10:07:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:9CKE094hiiSJ92W9WaJPY7yEYtMOwvmyzppFZE2uXyYz60QT+EMeYtjtPR1FvO0B:Us7y7SMOwvmyFpbCIhTBcjpFloWb

Entry address:
0x47242

Entry point:
E8, 58, B2, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, 35, FC, 32, 46, 00, 57, FF, 35, 74, 35, 49, 00, FF, D6, FF, 35, 70, 35, 49, 00, 8B, D8, 89, 5D, FC, FF, D6, 8B, F0, 3B, F3, 0F, 82, 81, 00, 00, 00, 8B, FE, 2B, FB, 8D, 47, 04, 83, F8, 04, 72, 75, 53, E8, AE, B2, 00, 00, 8B, D8, 8D, 47, 04, 59, 3B, D8, 73, 48, B8, 00, 08, 00, 00, 3B, D8, 73, 02, 8B, C3, 03, C3, 3B, C3, 72, 0F, 50, FF, 75, FC, E8, E6, 44, 00, 00, 59, 59, 85, C0, 75, 16, 8D, 43, 10, 3B, C3, 72, 3E, 50, FF, 75, FC, E8...
 
[+]

Entropy:
5.9303

Code size:
392 KB (401,408 bytes)

Shell Open Command
Open type:
ftp

Command:
"C:\users\{user}\appdata\local\vosteran\application\vosteran.exe" -- "%1"


The file vosteran.exe has been discovered within the following program.

Vosteran  by Vosteran
87% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP:
Connects to bc.47.c0ad.ip4.static.sl-reverse.com  (173.192.71.188:42013)

TCP (HTTP SSL):
Connects to pc-pool.flickr.vip.gq1.yahoo.com  (74.6.47.80:443)

TCP (HTTP SSL):
Connects to ec2-184-73-164-31.compute-1.amazonaws.com  (184.73.164.31:443)

TCP (HTTP):
Connects to ec2-52-48-202-137.eu-west-1.compute.amazonaws.com  (52.48.202.137:80)

TCP (HTTP):
Connects to ec2-50-16-250-178.compute-1.amazonaws.com  (50.16.250.178:80)

Remove vosteran.exe - Powered by Reason Core Security