dat6d24.tmp.exe

j3d.java.com

The executable dat6d24.tmp.exe has been detected as malware by 4 anti-virus scanners. It runs as a separate (within the context of its own process) windows Service named “mkrmgyti”.
Publisher:
j3d.java.com  (signed and verified)

MD5:
254bb7020570274c7fd2c048cf276155

SHA-1:
a60463d73a7889375a4b9c17fe482ec15ebfe8ed

SHA-256:
4d126643c8326b5e5f704b6ced5de8b7adf9369d716e74dfdaefaaf88649bc2d

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
5/1/2024 10:20:24 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Kryptik.ABFD trojan
6.3.12010.0

F-Prot
W32/Jorik.E.gen
4.6.5.141

F-Secure
Variant.Kazy.45866
5.15.154

Microsoft Security Essentials
TrojanDownloader:Win32/Phdet.E
1.231.782.0

File size:
103.1 KB (105,552 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\temp\dat6d24.tmp.exe

Digital Signature
Signed by:

Authority:
Root Agency

Valid from:
2/29/2012 10:56:19 PM

Valid to:
1/1/2040 4:59:59 AM

Subject:
CN=j3d.java.com

Issuer:
CN=Root Agency

Serial number:
1F9291F2EAA620BD4902433D9C5F5D79

File PE Metadata
Compilation timestamp:
3/5/2012 11:11:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
3072:wSDJknluFfbdYCNqmSNCa7EdJayVFxq4xm:RDtBmc/a2FxPg

Entry address:
0x7FE0

Entry point:
55, 8B, EC, 81, EC, 54, 01, 00, 00, 57, C7, 45, F8, FB, 00, 00, 00, C7, 45, F4, DA, 00, 00, 00, 8B, 45, F4, 0F, AF, 45, F8, 89, 45, F8, C7, 45, FC, 00, 00, 00, 00, C7, 45, E4, 01, 00, 00, 00, C7, 45, E0, E3, 00, 00, 00, 81, 7D, E0, BF, 00, 00, 00, 7F, 1D, 83, 7D, E0, 06, 75, 17, 8B, 4D, F8, 03, 4D, F4, 89, 4D, F8, 8B, 55, E0, 2B, 55, F4, 89, 55, F8, E9, 70, 02, 00, 00, 8B, 45, F4, 0D, 9A, 00, 00, 00, 0F, 84, FE, 00, 00, 00, 33, C9, 74, 16, 8B, 55, F4, 3B, 55, E0, 7C, 0E, 8B, 45, F4, 03, 45, E0, 89, 45, F8...
 
[+]

Entropy:
5.9936

Developed / compiled with:
Microsoft Visual C++

Code size:
36 KB (36,864 bytes)

Service
Display name:
mkrmgyti

Type:
Win32OwnProcess


Remove dat6d24.tmp.exe - Powered by Reason Core Security