1870

Kemeda

The file 1870 has been detected as malware by 27 anti-virus scanners.
Publisher:
Kemeda  (signed and verified)

Version:
12.3.0.78

MD5:
865cd67856e87ca6d8c5d29f8ac3ecae

SHA-1:
3ede13bb70e57d68926425a9fd2f18221a379ce8

SHA-256:
bf9baa5749d1f30b3e8265ddd35f745440720733ecc6f5daf3b27d06eff2a338

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
5/11/2025 1:15:42 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Inject
7.1.1

Avira AntiVirus
TR/Dropper.MSIL.222369
8.3.2.2

Arcabit
Trojan.Generic.D2B9903
1.0.0.593

avast!
Win32:Malware-gen
2014.9-160209

AVG
MSIL9
2017.0.2839

Baidu Antivirus
Trojan.MSIL.Injector
4.0.3.1629

Bitdefender
Trojan.GenericKD.2857219
1.0.20.200

Dr.Web
BackDoor.Wirenet.9
9.0.1.040

Emsisoft Anti-Malware
Trojan.GenericKD.2857219
8.16.02.09.01

ESET NOD32
MSIL/Injector.MIX (variant)
10.12553

Fortinet FortiGate
MSIL/MIX!tr
2/9/2016

F-Secure
Trojan.GenericKD.2857219
11.2016-09-02_3

G Data
Trojan.GenericKD.2857219
16.2.25

IKARUS anti.virus
Trojan.MSIL.Injector
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.212.17825

Kaspersky
Trojan.MSIL.Inject
14.0.0.690

McAfee
Artemis!865CD67856E8
5600.6495

Microsoft Security Essentials
VirTool:MSIL/Injector.HG
1.1.12205.0

MicroWorld eScan
Trojan.GenericKD.2857219
17.0.0.120

NANO AntiVirus
Trojan.Win32.Inject.dyosnd
0.30.26.4437

nProtect
Trojan.GenericKD.2857219
15.11.11.01

Panda Antivirus
Trj/CI.A
16.02.09.01

Qihoo 360 Security
Win32/Trojan.Dropper.fe7
1.0.0.1077

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16207

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic
45168

ViRobot
Trojan.Win32.Z.Injector.431592[h]
2014.3.20.0

File size:
421.5 KB (431,592 bytes)

Product version:
12.3.0.78

Original file name:
zavx.exe

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\1870

Digital Signature
Signed by:

Authority:
Kemeda

Valid from:
10/21/2015 11:07:25 PM

Valid to:
10/21/2016 11:07:25 PM

Subject:
CN=www.kemeda.pt, O=Kemeda, L=Lisboa, S=Lisboa, C=PK

Issuer:
CN=www.kemeda.pt, O=Kemeda, L=Lisboa, S=Lisboa, C=PK

Serial number:
008C6590B70633A028

File PE Metadata
Compilation timestamp:
11/5/2015 8:25:56 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
80.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:7GHYH3CQ2sID/q/xX+zpSSSOChFspRJE9lJR8TzV9W+S0C8TE9Gj7iEcc2Ve4w:7GHY12sCyYxSO4+p3uDgvrEoAc2Ve4w

Entry address:
0x6A5BE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, 50, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 38, 00, 00, 80, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.0089

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
417.5 KB (427,520 bytes)

Remove 1870 - Powered by Reason Core Security