48af.tmp

The file 48af.tmp has been detected as malware by 31 anti-virus scanners.
MD5:
261597cec7ad59acb05b3dd7fc8c5659

SHA-1:
dea62050baad5fb6bbaa2e4f61c8636e3da53c58

SHA-256:
da7ce43e713bdab1b2afe76441aea9e75c3465f2cafbd68ad3a8e64774e9aece

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
4/25/2024 10:58:43 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Agent.BKKS
577

Agnitum Outpost
Trojan.Injector
7.1.1

AhnLab V3 Security
Malware/Win32.Generic
2015.06.16

Avira AntiVirus
TR/Crypt.Xpack.24767
8.3.1.6

Arcabit
Trojan.Agent.BKKS
1.0.0.425

avast!
Win32:Malware-gen
2014.9-150707

AVG
Inject2
2016.0.3055

Bitdefender
Trojan.Agent.BKKS
1.0.20.940

Dr.Web
Trojan.DownLoader13.34589
9.0.1.0188

Emsisoft Anti-Malware
Trojan.Agent.BKKS
8.15.07.07.03

ESET NOD32
Win32/Injector.CCTP (variant)
9.11792

Fortinet FortiGate
W32/Injector.CCOH!tr
7/7/2015

F-Secure
Trojan.Agent.BKKS
11.2015-07-07_3

G Data
Trojan.Agent.BKKS
15.7.25

K7 AntiVirus
Trojan
13.205.16251

Kaspersky
Trojan.Win32.Agent
14.0.0.1772

Malwarebytes
Spyware.Password
v2015.07.07.03

McAfee
Packed-EM!261597CEC7AD
5600.6711

MicroWorld eScan
Trojan.Agent.BKKS
16.0.0.564

NANO AntiVirus
Trojan.Win32.Injector.dsqrof
0.30.24.2086

nProtect
Trojan.Agent.BKKS
15.06.15.01

Panda Antivirus
Trj/Genetic.gen
15.07.07.03

Qihoo 360 Security
HEUR/QVM07.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.7.7.15

Rising Antivirus
PE:Malware.Obscure/Heur!1.9E03
23.00.65.15705

Sophos
Mal/Zbot-TW
4.98

Trend Micro House Call
TROJ_GEN.R00JC0RFD15
7.2.188

Trend Micro
TROJ_GEN.R00JC0RFD15
10.465.07

Vba32 AntiVirus
OScope.Malware-Cryptor.Hlux
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
41174

Zillya! Antivirus
Trojan.Injector.Win32.266340
2.0.0.2226

File size:
97.2 KB (99,534 bytes)

Common path:
C:\users\{user}\appdata\local\temp\48af.tmp

File PE Metadata
Compilation timestamp:
6/9/2015 7:09:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:18KgGCCaetTN3VkDNAP2MT0kkA2nI198/uZp1iNOUX7BarHIR3:WVCxpN3Qa6Mew1izKg

Entry address:
0x5182

Entry point:
55, 8B, EC, 6A, FF, 68, C8, 75, 40, 00, 68, 56, 53, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 38, 65, 40, 00, 59, 83, 0D, B0, 9E, 40, 00, FF, 83, 0D, B4, 9E, 40, 00, FF, FF, 15, 34, 65, 40, 00, 8B, 0D, A4, 9E, 40, 00, 89, 08, FF, 15, 30, 65, 40, 00, 8B, 0D, A0, 9E, 40, 00, 89, 08, A1, 2C, 65, 40, 00, 8B, 00, A3, AC, 9E, 40, 00, E8, 64, 01, 00, 00, 39, 1D, A0, 9D, 40, 00, 75, 0C, 68, 52, 53, 40, 00, FF, 15, 28, 65...
 
[+]

Entropy:
6.8816

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
20 KB (20,480 bytes)

Remove 48af.tmp - Powered by Reason Core Security