waxdy+zl4kn.exe

The executable waxdy+zl4kn.exe has been detected as malware by 20 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from xzone-reactor.com.
MD5:
00ef29afb3642a9d0a8317fb941a021d

SHA-1:
58be2af811b2555cf136aba2f6ef9181abd758de

SHA-256:
52995c7670285b6f1f050ae1ec6249012dc730c7489fb1dcf59330146e6e4ed4

Scanner detections:
20 / 68

Status:
Malware

Analysis date:
12/26/2024 2:25:53 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.68497
1132

Agnitum Outpost
Trojan.Kazy
7.1.1

AhnLab V3 Security
Trojan/Win32.Agent
2014.01.13

Avira AntiVirus
TR/DelfInject.A.57
7.11.124.216

AVG
Dropper.Generic9
2015.0.3595

Bitdefender
Gen:Variant.Kazy.68497
1.0.20.1820

Bkav FE
W32.HfsAutoA
1.3.0.4613

Comodo Security
UnclassifiedMalware
17599

Emsisoft Anti-Malware
Gen:Variant.Kazy.68497
8.13.12.30.07

F-Prot
W32/Downloader.K.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Kazy.263991
11.2013-30-12_2

G Data
Gen:Variant.Kazy.68497
13.12.22

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.2.29

McAfee
Artemis!00EF29AFB364
5600.7266

MicroWorld eScan
Gen:Variant.Kazy.263991
14.0.0.1092

Norman
Suspicious_Gen5.AKDKK
11.20131230

Panda Antivirus
Trj/CI.A
14.01.14.06

Trend Micro House Call
TROJ_GEN.R0CBC0OLV13
7.2.364

Trend Micro
TROJ_GEN.R0CBC0OLV13
10.465.14

VIPRE Antivirus
Trojan.Win32.Generic
25356

File size:
1.8 MB (1,875,456 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\waxdy+zl4kn.exe

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:DUyQJretI1davoi/qIqIhvxvKRhPV+yebQHOl7Tlvj4s:4yQJretaMvqRp0yebQupTlv0s

Entry address:
0x33644C

Entry point:
54, E9, A5, 46, 00, 00, 66, 0F, B6, F1, 8D, 34, A5, 51, A5, 36, 28, 68, B4, 39, 23, BC, F7, D6, F3, AB, 66, 0F, BE, CB, 8B, 75, 08, C7, 04, 24, 03, 7F, 51, EE, AC, 66, 0F, B3, C9, F5, 0F, 9E, C1, 66, F7, DF, F6, D8, 66, 0F, AC, E9, 0A, 34, 5E, 66, 0F, C9, 0F, CF, 0F, 98, C1, 0F, 99, C1, FE, C0, 66, BF, 97, 62, C0, C8, 07, C1, E7, 0D, C1, E1, 06, 66, 87, CF, 8D, B9, 93, 6F, B9, 84, 31, C0, 66, 89, CF, E8, E0, 27, 00, 00, 00, 00, 43, 72, 65, 61, 74, 65, 55, 52, 4C, 4D, 6F, 6E, 69, 6B, 65, 72, 45, 78, 00, 60...
 
[+]

Entropy:
7.8857  (probably packed)

Code size:
1.5 MB (1,586,176 bytes)

The file waxdy+zl4kn.exe has been seen being distributed by the following URL.

Remove waxdy+zl4kn.exe - Powered by Reason Core Security