نجرات.exe

The executable نجرات.exe has been detected as malware by 34 anti-virus scanners.
MD5:
179b363ad0ead169a1afdfaf5dad4454

SHA-1:
24677040770ace9ec82b70019e21c6a8dbfb23b5

SHA-256:
e4bbc2e458b9ac192cd429357d0b23f1c81b8f5434b0286b4726a568097fa6c1

Scanner detections:
34 / 68

Status:
Malware

Analysis date:
4/18/2024 10:19:34 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Agent2
7.1.1

AhnLab V3 Security
Win-Trojan/Agent.100616.B
2012.10.20

Avira AntiVirus
Worm/Agent.100616
7.11.46.240

avast!
Win32:Agent-ALZJ [Trj]
2014.9-151201

AVG
Generic22
2016.0.2909

Bitdefender
Trojan.Agent.AQNV
1.0.20.1675

Clam AntiVirus
Trojan.Agent-142577
0.98/18155

Comodo Security
Worm.Win32.Agent.NEC1
13919

Dr.Web
Trojan.MulDrop3.8203
9.0.1.0335

Emsisoft Anti-Malware
Trojan.Agent.AQNV
8.15.12.01.06

ESET NOD32
Win32/Agent.NEC
9.7607

Fortinet FortiGate
W32/Rotinom.SME!tr
12/1/2015

F-Prot
W32/Trojan2.MGVM
v6.4.6.5.141

F-Secure
Trojan.Agent.AQNV
11.2015-01-12_3

G Data
Trojan.Agent.AQNV
15.12.22

IKARUS anti.virus
Trojan.Win32.Agent2
t3scan.1.1.122.0

K7 AntiVirus
Trojan
13.153.7745

Kaspersky
Trojan.Win32.Agent2
14.0.0.1039

McAfee
W32/Rotinom
5600.6565

Microsoft Security Essentials
Worm:Win32/Folstart.A
1.163.1557.0

MicroWorld eScan
Trojan.Agent.AQNV
16.0.0.1005

Norman
W32/Obfuscated.H!genr
11.20151201

nProtect
Trojan/W32.Agent2.95232.B
12.10.19.02

Panda Antivirus
W32/FakeFolder.Q.worm
15.12.01.06

Quick Heal
Worm.Folstart.A2
12.15.12.00

Rising Antivirus
Worm.Win32.Autorun.tic
23.00.65.151129

Sophos
Mal/Autorun-T
4.81

SUPERAntiSpyware
Trojan.Agent/Gen-Folstart
9474

Total Defense
Win32/Folstart.A
37.0.10127

Trend Micro House Call
TROJ_GEN.F47V0907
7.2.335

Trend Micro
WORM_AUTORUN.SMI
10.465.01

Vba32 AntiVirus
Worm.Palevo.eewd
3.12.18.2

VIPRE Antivirus
Trojan.Win32.Rotinom.b
13598

ViRobot
Trojan.Win32.Agent.178440
2011.4.7.4223

File size:
93 KB (95,232 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\s-1-5-31-1286970278978-5713669491-166975984-320\rotinom\?????\?????.exe

File PE Metadata
Compilation timestamp:
6/3/2009 3:09:17 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:YreR9ieUOc+/RAhDcaPLXbbsAyQIrZBQlgSJ0:GeR8Y6hDaAyQIrZBbSJ

Entry address:
0x4189

Entry point:
E8, 58, 35, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, F8, 0F, 41, 00, 89, 0D, F4, 0F, 41, 00, 89, 15, F0, 0F, 41, 00, 89, 1D, EC, 0F, 41, 00, 89, 35, E8, 0F, 41, 00, 89, 3D, E4, 0F, 41, 00, 66, 8C, 15, 10, 10, 41, 00, 66, 8C, 0D, 04, 10, 41, 00, 66, 8C, 1D, E0, 0F, 41, 00, 66, 8C, 05, DC, 0F, 41, 00, 66, 8C, 25, D8, 0F, 41, 00, 66, 8C, 2D, D4, 0F, 41, 00, 9C, 8F, 05, 08, 10, 41, 00, 8B, 45, 00, A3, FC, 0F, 41, 00, 8B, 45, 04, A3, 00, 10, 41, 00, 8D, 45, 08, A3, 0C, 10, 41...
 
[+]

Entropy:
5.6953

Code size:
46.5 KB (47,616 bytes)

Remove نجرات.exe - Powered by Reason Core Security