wwe_1.61.101.27.exe

The executable wwe_1.61.101.27.exe has been detected as malware by 11 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from www.pelletiertechnology.com.
MD5:
2abc77970167442d8877d47ab281a3e7

SHA-1:
151c573c26ffca548fe58c605e7d69856047f6a6

SHA-256:
b02bf5ad333779ffd3c74756460133308d085d5827531cc2af8f8399651f44ce

Scanner detections:
11 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
12/27/2024 8:32:06 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160326-0

AVG
Win32/Sality
2015.0.4545

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.217.399.0

Norman
Win32.Sality.3
29.03.2016 06:29:16

File size:
4.2 MB (4,449,184 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\wwe_1.61.101.27.exe

File PE Metadata
Compilation timestamp:
1/28/2016 1:45:22 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:Y0FnGkatdQvDKF22xjoNafRspKegV0RlJApybVIbk0ZdZc1RIorAP:rGk8dAJEoBgVmJG8IbkIZeRbg

Entry address:
0x9EC0

Entry point:
F7, C2, 30, A0, E5, 3F, 89, CF, C6, C2, 89, 74, 05, 33, D1, F3, 87, D7, 78, 05, B5, C1, 0F, AF, F3, C6, C7, 7C, 8B, D8, 8A, F7, 2D, 99, D6, 00, 00, 0F, AF, DB, F7, C5, A4, 77, 56, D8, 69, D3, 73, 35, A1, D9, 05, 4B, 03, 00, 00, 0F, AF, EF, 0C, 70, 2D, 6B, 92, E2, DD, 3C, 2B, 88, E1, B1, AD, 3B, EA, F7, C3, C3, 5A, 4E, D7, 0F, B7, EB, 69, DE, 56, 9B, 57, 50, E8, 00, 00, 00, 00, F7, C5, BB, A9, 44, 5E, F2, 2D, 1A, FD, 98, 17, 8D, 2D, 77, F3, 2E, 20, 38, DC, 0F, B7, F7, 81, C2, F3, D5, 00, 00, F7, C0, 82, 6B...
 
[+]

Entropy:
7.9959  (probably packed)

Code size:
58 KB (59,392 bytes)

The file wwe_1.61.101.27.exe has been seen being distributed by the following URL.

Remove wwe_1.61.101.27.exe - Powered by Reason Core Security