xf-a2012-64bits.exe

The application xf-a2012-64bits.exe has been detected as a potentially unwanted program by 14 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download1749.mediafire.com and multiple other hosts.
MD5:
829350e2591c8629d3095c6eda2b4a63

SHA-1:
7ab679be3d6ebcd677e0d9cf964fa6ac06e2c8aa

SHA-256:
02e47619310564db7ce7298139e4b7345a7112b191bbb3cf1ea2a6aa2e5841ad

Scanner detections:
14 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 6:33:46 PM UTC  (today)

Scan engine
Detection
Engine version

Bitdefender
Trojan.Generic.7298403
1.0.20.1790

Bkav FE
W32.Clod8e8.Trojan
1.3.0.4613

Comodo Security
UnclassifiedMalware
17486

Emsisoft Anti-Malware
Trojan.Generic.7298403
8.13.12.24.07

F-Prot
W32/MalwareF.WVOU
v6.4.7.1.166

F-Secure
Trojan.Generic.7298403
11.2013-24-12_3

G Data
Trojan.Generic.7298403
13.12.22

IKARUS anti.virus
PossibleThreat.Patch.AutoDesk
t3scan.2.2.29

Malwarebytes
RiskWare.Tool.CK
v2013.12.24.07

MicroWorld eScan
Trojan.Generic.7298403
14.0.0.1074

NANO AntiVirus
Trojan.Win32.KeygenEW.lfoan
0.28.0.57029

Panda Antivirus
Generic Malware
13.12.24.07

Sophos
Troj/Keygen-EW
4.96

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
24660

File size:
80.5 KB (82,432 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
3/14/2010 4:02:48 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:IGKYe96QRN8jbX4elrUJm+hCCf53DlrxvltwK1JQinouy8jl:InpWbX4eldMlDhxLwEJdoutj

Entry address:
0x48750

Entry point:
60, BE, 00, 70, 43, 00, 8D, BE, 00, A0, FC, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 9C, 68, 04, 00, 57, 83, C3, 04, 53, 68, 49, 17, 01, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 00, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Entropy:
7.8801  (probably packed)

Code size:
76 KB (77,824 bytes)

The file xf-a2012-64bits.exe has been seen being distributed by the following 2 URLs.

http://download1749.mediafire.com/bceazk15wnpg/.../xf-a2011-64bits.exe

Remove xf-a2012-64bits.exe - Powered by Reason Core Security