chrone

The file chrone has been detected as malware by 4 anti-virus scanners. The file has been seen being downloaded from b1.ge.tt.
Version:
0.0.0.0

MD5:
0310c6044b089031e82140cfc4a7604f

SHA-1:
45d0d232d1e766ae238a1774b9cc3fbe15d25163

SHA-256:
496124d2e5915dd01f706943c607e2bd44ed1f87a5d36e32504025649fa4729b

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
5/17/2024 1:34:40 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.MSIL.Gen
8.3.3.4

Baidu Antivirus
Win32.Trojan.WisdomEyes.151026.9950
4.0.3.1664

ESET NOD32
MSIL/Kryptik.CRI (variant)
10.13594

Qihoo 360 Security
HEUR/QVM03.0.0000.Malware.Gen
1.0.0.1120

File size:
384 KB (393,216 bytes)

Product version:
0.0.0.0

Original file name:
thecorm.exe

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\chrone

File PE Metadata
Compilation timestamp:
6/4/2016 2:57:10 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:tAnJ4s8Ptiv7WZlSwMWpx1gSll299990NDkW4/LROlOzNB8XbKYtw:tmJPQAvaZwwV1fTuEw

Entry address:
0x610CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
380.5 KB (389,632 bytes)

2 Windows Firewall Allowed Programs
Name:
C:\Documents and Settings\pc\Local Settings\Temp\h.exe

Name:
C:\Documents and Settings\Administrateur\Local Settings\Temp\h.exe


The file chrone has been seen being distributed by the following URL.

Remove chrone - Powered by Reason Core Security