6.exe

The executable 6.exe has been detected as malware by 27 anti-virus scanners.
Version:
1.2.2.5

MD5:
ed3409917d7d350f4fdf6961c4656ee3

SHA-1:
dee10043e78006e3565e42c14709d0704d0a9c4f

SHA-256:
dc3b701bbcbc5ea1e578e4555c408f8b085d78dc741d90468a31e7e20a8b9762

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
4/26/2024 11:52:22 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKDZ.31258
368

AegisLab AV Signature
Backdoor.W32.Gen
2.1.4+

Avira AntiVirus
TR/AD.Nanocore.Y.921
8.3.2.4

Arcabit
Trojan.Generic.D7A1A
1.0.0.646

avast!
MSIL:NanoCore-D [Trj]
2014.9-160201

AVG
Atros2
2017.0.2846

Bitdefender
Trojan.GenericKDZ.31258
1.0.20.160

Clam AntiVirus
Win.Trojan.Nanocore
0.98/21511

Dr.Web
Trojan.DownLoader17.41485
9.0.1.032

Emsisoft Anti-Malware
Trojan.GenericKDZ.31258
8.16.02.01.05

ESET NOD32
MSIL/NanoCore (variant)
10.12948

Fortinet FortiGate
MSIL/NanoCore.B!tr
2/1/2016

F-Secure
Trojan.GenericKDZ.31258
11.2016-01-02_2

G Data
Trojan.GenericKDZ.31258
16.2.25

IKARUS anti.virus
Trojan.MSIL.NanoCore
t3scan.2.0.4.0

K7 AntiVirus
Trojan
13.213.18582

Kaspersky
HEUR:Backdoor.Win32.Generic
14.0.0.726

Malwarebytes
Backdoor.NanoCore
v2016.02.01.05

McAfee
NanoRat!ED3409917D7D
5600.6502

Microsoft Security Essentials
Backdoor:MSIL/Noancooe.C
1.1.12400.0

MicroWorld eScan
Trojan.GenericKDZ.31258
17.0.0.96

NANO AntiVirus
Trojan.Win32.NanoCore.dzwwoe
1.0.14.5798

nProtect
Trojan.GenericKDZ.31258
16.01.29.01

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1077

Rising Antivirus
MSIL:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.16130

Sophos
Mal/NanoCore-A
4.98

Trend Micro House Call
HT_NOANCOOE_EK16029F.UVPM
7.2.32

File size:
130 KB (133,120 bytes)

Product version:
1.2.2.5

Original file name:
NanoCore Client.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
1/29/2016 9:09:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:yYGpA7imQbLoNOZ6MV1xb1VU2vaE02f01SjT7bQJp337NBccoPEEUU:yppA+mQbLK21t1iIbqhcPEbU

Entry address:
0x1E7CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 78, 00, 00, 80, 10, 00, 00, 00, 90, 00, 00, 80, 18, 00, 00, 00, A8, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 07, 00, 02, 00, 00, 00, C0, 00, 00, 80, 03, 00, 00, 00, D8, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
114 KB (116,736 bytes)

Remove 6.exe - Powered by Reason Core Security