ek-sgnd.exe

Trusted Security

The executable ek-sgnd.exe has been detected as malware by 4 anti-virus scanners.
Publisher:
Trusted Security  (signed and verified)

MD5:
c8abfb51a80e775f6f53779309bc96ca

SHA-1:
55b192e811ef458593bc26a3b847b1d4843e5846

SHA-256:
5d4c9a3450698ec03c0e95f484c5de247d0dd42d945d195f7a01d80eb9aa523c

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
7/20/2025 11:57:47 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Avira AntiVirus
SPR/EliteKeyLog.A
8.3.2.2

ESET NOD32
Win32/KeyLogger.EliteKeylogger.NAE
9.12228

IKARUS anti.virus
Trojan-GameThief.Win32.Tibia
t3scan.1.9.5.0

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
43610

File size:
2.1 MB (2,244,064 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ek-sgnd.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/5/2015 6:00:00 PM

Valid to:
5/7/2017 6:59:59 PM

Subject:
CN=Trusted Security, O=Trusted Security, L=Zaporizhzhya, S=Zaporizhzhya, C=UA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
6B441486B3DB6CBCB829F7433EA5CCC4

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:6nMihZ85NJ+jafjRhZdekRyqP3LC5N7onmf8sQtdt:cZ8PUIjRhKqP3m7omf8sQtH

Entry address:
0x12ED4

Entry point:
55, 8B, EC, 83, C4, E4, 33, C0, 89, 45, E4, 89, 45, E8, 89, 45, EC, B8, 4C, 2E, 41, 00, E8, C1, 2C, FF, FF, 33, C0, 55, 68, 2E, 30, 41, 00, 64, FF, 30, 64, 89, 20, E8, 42, 58, FF, FF, 83, C4, F8, DD, 1C, 24, 9B, 8D, 55, EC, B8, 44, 30, 41, 00, E8, 7A, 64, FF, FF, 8B, 55, EC, B8, 84, 58, 41, 00, E8, 01, 11, FF, FF, 8D, 45, E8, E8, C1, FD, FF, FF, FF, 75, E8, 68, 58, 30, 41, 00, FF, 35, 84, 58, 41, 00, 68, 68, 30, 41, 00, B8, 84, 58, 41, 00, BA, 04, 00, 00, 00, E8, DF, 13, FF, FF, 68, 78, 30, 41, 00, 6A, 0A...
 
[+]

Entropy:
7.9812

Developed / compiled with:
Microsoft Visual C++

Code size:
72.5 KB (74,240 bytes)

Remove ek-sgnd.exe - Powered by Reason Core Security