wf1.dll

The library wf1.dll has been detected as malware by 13 anti-virus scanners. The file has been seen being downloaded from engenhariatm.com.
MD5:
9c9d8b5fe5cd66c00d711619baa2f226

SHA-1:
59d452f544be37e488e80e56b62f8fde7f004eb7

SHA-256:
62036a3c65d9dc0cacf7dd0f1de15a6e739c411123b95b28df58a4919cb5d172

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
12/26/2024 5:28:09 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2839940
361

Avira AntiVirus
TR/Rogue.139264.117
8.3.2.2

Arcabit
Trojan.Generic.D2B5584
1.0.0.585

AVG
Win32/Blacked
2017.0.2839

Bitdefender
Trojan.GenericKD.2839940
1.0.20.200

Bkav FE
HW32.Packed
1.3.0.7383

Emsisoft Anti-Malware
Trojan.GenericKD.2839940
8.16.02.09.08

F-Secure
Trojan.GenericKD.2839940
11.2016-09-02_3

G Data
Trojan.GenericKD.2839940
16.2.25

McAfee
Artemis!9C9D8B5FE5CD
5600.6495

MicroWorld eScan
Trojan.GenericKD.2839940
17.0.0.120

nProtect
Trojan.GenericKD.2839940
15.11.02.01

Panda Antivirus
Trj/Genetic.gen
16.02.09.08

File size:
136 KB (139,264 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\wf1.dll

File PE Metadata
Compilation timestamp:
10/31/2015 11:18:31 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:TAabINladi7JH+Tj1wu6vZLNxFVZr/IQDuwaYtABtT8:8akrJH+TJwtvxNvVZcQJamAX

Entry address:
0x1EC4F

Entry point:
60, 68, 96, 86, 9E, 1E, C7, 04, 24, 9C, 03, 50, 04, C7, 44, 24, 20, 01, 55, C4, D8, E9, 70, 3B, 01, 00, 66, 0F, C8, 89, 5C, 24, 24, E8, 6D, F3, 00, 00, 09, C9, 9C, 68, DF, 21, B9, 2F, 66, 89, 64, 24, 0C, 8D, 64, 24, 10, 0F, 84, CA, 35, 00, 00, 0F, B6, D2, 8D, 53, 04, 66, 0F, BE, FB, 66, BE, 37, 63, 0F, B7, 72, 1A, 66, F7, D7, BF, 3A, D4, E0, C1, 0F, 89, 8C, 78, FF, FF, 8D, 74, 16, 1C, 60, 68, 04, 0F, D8, E3, 8B, 7D, 08, 60, E9, CE, 34, 00, 00, 8D, 64, 24, 3C, 0F, 85, A2, 78, FF, FF, 9C, 89, 3C, 24, 60, 66...
 
[+]

Code size:
19.5 KB (19,968 bytes)

The file wf1.dll has been seen being distributed by the following URL.

Remove wf1.dll - Powered by Reason Core Security