zone4.exe

GPLYRA - Setup

Open Source

The application zone4.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from zone4.izabelcoin.com.
Publisher:
Open Source

Product:
GPLYRA - Setup

Version:
5.2

MD5:
634c5b4426d8a1711e5a3f567bce9a91

SHA-1:
27a48e802a19d3b423195b341195b3483d848be9

SHA-256:
00361434927618c5349db279bc77e514f86671211fb95ae8ddf0a32091bfe84f

Scanner detections:
11 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 11:04:30 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160209-2

AVG
Win32/Sality
2015.0.4489

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

McAfee
Program.Artemis!FC01AC55A333
18.0.204.0

Norman
Win32.Sality.3
03.02.2016 10:30:35

Sophos
PUA 'Bitcoin Miner'
5.23

VIPRE Antivirus
Threat.4721115
47186

File size:
2.1 MB (2,233,367 bytes)

Product version:
5.2

Copyright:
2015 - Open Source

Original file name:
-

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\zone4.exe

File PE Metadata
Compilation timestamp:
8/5/2015 8:47:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:yHpyoXTPFFiKYV6yjoA2KUqrxd6l6asVFeg5iXEorx2aRLsXF/lUh1QltYf/MLsc:apL/iV6yjoGWO4RyXF/ldjm/W

Entry address:
0x3239

Entry point:
EB, 0A, 8B, C0, F7, C0, 0B, 53, EA, 47, FF, C5, 56, 28, C2, B3, 9C, 84, E6, B0, 76, 77, 07, 1C, 9C, BA, 17, C6, B2, 8D, B1, E4, 0F, BF, CE, 88, E5, 81, FB, 77, 4F, 00, 00, 0F, AF, EA, 56, 81, D9, D7, D7, 53, B6, 3A, D4, BD, 00, 00, 00, 00, C7, C2, E1, 7B, EA, DB, FF, CB, 32, FE, F2, 0F, BE, C6, F2, 69, F6, 9B, BF, 3F, 71, 69, DF, 3A, 7D, 5D, 47, 81, C5, 01, 00, 00, 00, 4E, 89, D1, 2D, C2, 17, A3, DE, F2, 81, FD, 47, 08, 00, 00, 0F, 8C, CA, FF, FF, FF, 0F, AF, CA, 69, F8, 2A, 7C, E5, 33, F2, 69, CA, 7D, 9E...
 
[+]

Entropy:
7.9924  (probably packed)

Code size:
24 KB (24,576 bytes)

The file zone4.exe has been seen being distributed by the following URL.

Remove zone4.exe - Powered by Reason Core Security