z3x 24.3 loader.exe

The executable z3x 24.3 loader.exe has been detected as malware by 20 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dc435.4shared.com and multiple other hosts.
MD5:
f20ef033547809a625d43a859a015d40

SHA-1:
336a56d0aeb6dbb2141b364ba9c63056e75c28b2

SHA-256:
969c5cf7f7e26ebcde7875038ca116597ff6204fcd65b53aca2f6a5f8757d018

Scanner detections:
20 / 68

Status:
Malware

Analysis date:
11/30/2024 8:59:06 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Packer.Enigma.1
346

AegisLab AV Signature
Troj.W32.Generic!c
2.1.4+

Avira AntiVirus
TR/Agent.1753088.122
8.3.3.2

Arcabit
Packer.Enigma.1
1.0.0.656

Baidu Antivirus
Hacktool.Win32.EnigmaProtector
4.0.3.16223

Bitdefender
Packer.Enigma.1
1.0.20.270

Bkav FE
HW32.Packed
1.3.0.7400

Emsisoft Anti-Malware
Packer.Enigma
8.16.02.23.08

ESET NOD32
Win32/Packed.EnigmaProtector.J suspicious application
6.3.12010.0

F-Prot
W32/Heuristic-210
v6.4.7.1.166

F-Secure
Packer.Enigma.1
5.15.21

G Data
Packer.Enigma
16.2.25

IKARUS anti.virus
Packer.Enigma
t3scan.2.0.7.0

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.616

McAfee
Artemis!F20EF0335478
5600.6480

MicroWorld eScan
Packer.Enigma.1
17.0.0.162

Norman
Packer.Enigma.1
17.02.2016 05:18:35

nProtect
Packer.Enigma.1
16.02.22.01

Qihoo 360 Security
HEUR/QVM18.1.Malware.Gen
1.0.0.1120

Vba32 AntiVirus
TrojanBanker.ChePro
3.12.26.4

File size:
1.7 MB (1,753,088 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\z3x 24.3 loader.exe

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:B5lXiDpHKx5SsW5sGisTNk9Ljes9Ltg5EeEtRK7:/lXM1rGMMjes30Is

Entry address:
0x58536

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, 10, 40, 00, E8, 01, 00, 00, 00, 9A, 83, C4, 10, 8B, E5, 5D, E9, 3E, 67, 47, 00, 65, 70, AF, 5E, C0, B5, C3, C1, 2C, B3, 3E, B5, E7, 6A, 16, BF, 7C, A0, D9, 2D, 64, C2, 74, 0A, 3E, 12, 50, 5C, A1, F8, 12, 1B, 84, 7B, BA, 08, E6, A1, 31, 34, 5B, 33, 26, 37, DA, A9, 16, 22, E8, D2, B5, 21, 24, E0, 4D, 7D, D6, F2, 68, 87, 09, 8E, BF, 55, 48, B4, E6, AF, 14, C8, 39, 31, C9, 74, DC, 3E, A5, 96, 16, DE, 26, BC, A9, 66, E1, 42, FB, 5C, 1D, 8D, A1, CC, A7, 3F, 11, BB, E3, FE, 4C, AE...
 
[+]

Entropy:
7.9831

Developed / compiled with:
Microsoft Visual C++

Code size:
1.2 MB (1,263,616 bytes)

The file z3x 24.3 loader.exe has been seen being distributed by the following 2 URLs.

http://dc435.4shared.com/download/.../Z3X_243_Loader.exe

Remove z3x 24.3 loader.exe - Powered by Reason Core Security