[www.oldschoolhack.me]_break the injector v2.1.exe

WindowsApplication1

The executable [www.oldschoolhack.me]_break the injector v2.1.exe has been detected as malware by 14 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.oldschoolhack.me.
Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
0d00796315ec71e8641540e3480d7463

SHA-1:
b1c20faff83ea5b0b4ad9a5480fbb1b015357e09

SHA-256:
e51da73f72ddfc17727afb1914d80a15d70e6f26d4324a2a29c8aad84f105517

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
11/27/2024 8:41:28 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
ILCrypt
2016.0.2922

Baidu Antivirus
Hacktool.MSIL.DllInject
4.0.3.151117

ESET NOD32
MSIL/DllInject.BK potentially unsafe (variant)
9.12454

Fortinet FortiGate
Riskware/Injector
11/17/2015

G Data
Win32.Application.Agent.01D4Q1
15.11.25

IKARUS anti.virus
Trojan-Dropper
t3scan.1.9.5.0

Kaspersky
not-a-virus:HEUR:RiskTool.MSIL.Injecter
14.0.0.1106

McAfee
Artemis!0D00796315EC
5600.6578

Panda Antivirus
Generic Suspicious
15.11.17.04

Qihoo 360 Security
Win32/Virus.RiskTool.c98
1.0.0.1015

Rising Antivirus
PE:Trojan.MSIL.Injector!1.9E1B[F1]
23.00.65.151115

Sophos
Mal/MsilInj-G
4.98

Vba32 AntiVirus
Trojan.MSIL.gen.b.5
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
44760

File size:
345.5 KB (353,792 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
Break the Injector V2.1.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\[www.oldschoolhack.me]_break the injector v2.1.exe

File PE Metadata
Compilation timestamp:
10/22/2015 10:53:15 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:5Tznae+idzJQXZnzlsEqnByD1cvWrhXednCU9ZVSh0lKKRfD9IF:lzCidzexBuypn9OdCIV40lKKd9

Entry address:
0x535AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, AB, 3E, 29, 56, 00, 00, 00, 00, 02, 00, 00, 00, 9E, 00, 00, 00, 1C, 40, 05, 00, 1C, 1A, 05, 00, 52, 53, 44, 53, 40, A7, C4, 41, A5, 4E, 83, 4F, B3, FC, 99, F9, CB, 7D...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
325.5 KB (333,312 bytes)

The file [www.oldschoolhack.me]_break the injector v2.1.exe has been seen being distributed by the following URL.