bastion v1.0r21 update setup.exe

The executable bastion v1.0r21 update setup.exe has been detected as malware by 37 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source.
MD5:
96a3365ebaa18fbef0131e49feeac636

SHA-1:
9f34409b6132bb75d3fb98cf6bc273f3fd041a8b

SHA-256:
ef715cf8f00190ad69b6699c4d8efcd95749e9592ea3f0fa42b59237038ff5ed

Scanner detections:
37 / 68

Status:
Malware

Analysis date:
4/26/2024 2:42:18 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.Crifi.@pJfamh6RnpO
1016

Agnitum Outpost
Trojan.Chifrax
7.1.1

AhnLab V3 Security
Trojan/Win32.Chifrax
2014.02.08

Avira AntiVirus
TR/Chifrax.a.353
7.11.130.16

Bitdefender
Gen:Trojan.Heur.Crifi.@pJfamh6RnpO
1.0.20.570

Comodo Security
UnclassifiedMalware
17749

Emsisoft Anti-Malware
Gen:Trojan.Heur.Crifi.@pJfamh6RnpO
8.14.04.24.12

ESET NOD32
Win32/HackTool.Crack
8.9397

Fortinet FortiGate
W32/Chifrax.A!tr
4/24/2014

F-Secure
Gen:Trojan.Heur.Crifi.@pJfamh6RnpO
11.2014-24-04_5

G Data
Gen:Trojan.Heur.Crifi.@pJfamh6RnpO
14.4.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.2.2.29

K7 AntiVirus
Hacktool
13.175.11103

Kaspersky
Trojan.Win32.Chifrax
14.0.0.3967

Microsoft Security Essentials
1.165.247.01

MicroWorld eScan
Gen:Trojan.Heur.Crifi.@pJfamh6RnpO
15.0.0.342

NANO AntiVirus
Trojan.Win32.Chifrax.bmnygj
0.28.0.57630

Norman
Suspicious_Gen2.JUDXR.dropper
11.20140424

Panda Antivirus
Trj/CI.A
14.04.24.12

Quick Heal
Trojan.Chifrax.a
4.14.12.00

Rising Antivirus
PE:Trojan.Win32.Generic.12E161EF!316760559
23.00.65.14422

Sophos
Mal/Chifrax-A
4.97

Vba32 AntiVirus
Trojan.Chifrax
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
26250

ViRobot
Trojan.Win32.A.Chifrax.31764344
2011.4.7.4223

File size:
30.3 MB (31,764,344 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
786432:9fdY/tjAKW9AhapQKBhVdD1ipT0sjQv9RAGFRNIF6mn36:tdmtsKs7fBFD1iZ+9VqFU

Entry address:
0x717C0

Entry point:
60, BE, 00, D0, 44, 00, 8D, BE, 00, 40, FB, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 67, FC, 06, 00, 57, 83, C3, 04, 53, 68, AF, 47, 02, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 00, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
152 KB (155,648 bytes)

Remove bastion v1.0r21 update setup.exe - Powered by Reason Core Security