48d1.tmp

The file 48d1.tmp has been detected as malware by 32 anti-virus scanners.
MD5:
d9a3d5c3c06f3429b65db7b84b50bed4

SHA-1:
ac4bd143e8a7fd8cf65847e3150988e41f9ae05d

SHA-256:
948f5dee6e752a593949c327781bae2d3e8994d4c00074228bed6e1156fe3402

Scanner detections:
32 / 68

Status:
Malware

Analysis date:
4/19/2024 2:30:36 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.169330
738

Agnitum Outpost
Trojan.DownLoader
7.1.1

AhnLab V3 Security
Trojan/Win32.agent
2015.01.28

Avira AntiVirus
TR/ATRAPS.A.3467
7.11.205.126

avast!
Win32:Malware-gen
2014.9-150128

AVG
Agent5
2016.0.3216

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.15128

Bitdefender
Gen:Variant.Graftor.169330
1.0.20.140

Dr.Web
Trojan.DownLoader11.46408
9.0.1.028

Emsisoft Anti-Malware
Gen:Variant.Graftor.169330
8.15.01.28.11

ESET NOD32
Win32/Agent.WSO
9.11081

Fortinet FortiGate
W32/Agent.WSO!tr
1/28/2015

F-Secure
Gen:Variant.Graftor.169330
11.2015-28-01_4

G Data
Gen:Variant.Graftor.169330
15.1.25

IKARUS anti.virus
Trojan.Win32.Agent
t3scan.1.8.6.0

K7 AntiVirus
Riskware
13.192.14775

Malwarebytes
Trojan.Agent.ED
v2015.01.28.11

McAfee
Artemis!D9A3D5C3C06F
5600.6872

MicroWorld eScan
Gen:Variant.Graftor.169330
16.0.0.84

NANO AntiVirus
Trojan.Win32.DownLoader11.dkmxej
0.30.0.65070

Norman
DLoader.MINI
11.20150128

nProtect
Trojan.Generic.12356151
14.12.26.01

Panda Antivirus
Trj/Downloader.IEW
15.01.28.11

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Quick Heal
Trojan.Downloader.r5
1.15.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
15.1.28.11

Rising Antivirus
PE:Trojan.Win32.Generic.17DA5AA0!400186016
23.00.65.15126

Sophos
Mal/Agent-AQM
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Netkit
10088

Trend Micro House Call
TROJ_GOPHE.A
7.2.28

Trend Micro
TROJ_GOPHE.A
10.465.28

VIPRE Antivirus
Win32.Malware!Drop
37018

File size:
441 KB (451,584 bytes)

Common path:
C:\windows\temp\48d1.tmp

File PE Metadata
Compilation timestamp:
11/10/2014 3:53:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:5++NasYJG1xuIj0Q0i2iHXolyGB0ip15Zaf9:E+uO4lhKA5ZK9

Entry address:
0x37052

Entry point:
E8, 3D, BF, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 68, BF, 45, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 6C, BF, 45, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, EE, 6D, 00, 00, 85, C0, 75, 06, B8, D0, C0, 45, 00, C3, 83, C0, 08, C3, E8, DB, 6D, 00, 00, 85, C0, 75, 06, B8, D4, C0, 45, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Entropy:
6.3859

Code size:
311 KB (318,464 bytes)

Remove 48d1.tmp - Powered by Reason Core Security