eScriptionDownloader.exe

eScriptionDownloader

Axiom Technologies

The executable eScriptionDownloader.exe has been detected as malware by 19 anti-virus scanners. The file has been seen being downloaded from sutterhealth.escriptionasp.com and multiple other hosts.
Publisher:
Axiom Technologies

Product:
eScriptionDownloader

Version:
9.120

MD5:
022141bdbeaafa8c543f6218cbb8af1c

SHA-1:
0d4819a278cb1af68823f2d9332a04ff4791dc86

SHA-256:
b47d204a077954e0a55f9161eb0f319c423bea345b1fa64ec791c0ca06180b49

Scanner detections:
19 / 68

Status:
Malware

Analysis date:
7/16/2025 6:35:47 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.44428
538

Agnitum Outpost
Trojan.Kazy
7.1.1

Avira AntiVirus
TR/Kazy.266313.1
8.3.1.6

Arcabit
Trojan.Kazy.DAD8C
1.0.0.425

avast!
Win32:Malware-gen
2014.9-150815

Bitdefender
Gen:Variant.Kazy.44428
1.0.20.1135

Comodo Security
UnclassifiedMalware
22758

Emsisoft Anti-Malware
Gen:Variant.Kazy.44428
8.15.08.15.06

F-Prot
W32/VB-Dialog-Spyer-based!Maxim
v6.4.7.1.166

F-Secure
Gen:Variant.Kazy.44428
11.2015-15-08_7

G Data
Gen:Variant.Kazy.44428
15.8.25

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.9.5.0

McAfee
Artemis!022141BDBEAA
5600.6672

MicroWorld eScan
Gen:Variant.Kazy.44428
16.0.0.681

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.8.15.18

Rising Antivirus
PE:Trojan.Win32.Generic.18760464!410387556
23.00.65.15813

SUPERAntiSpyware
Trojan.Agent/Gen-Kazy
9689

VIPRE Antivirus
Trojan-Spy.Win32.VB.Dialog!cobra
41990

File size:
260.1 KB (266,313 bytes)

Product version:
9.120

Original file name:
eScriptionDownloader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\escription\editscriptv9\escriptiondownloader.exe

File PE Metadata
Compilation timestamp:
5/17/2013 2:29:33 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:0TZ9FUfuqcHz8bHh6FKAcglhsFalow2N96w08B9XcBMp1scViwYmbfzKb9MGRjUZ:GZsGjNY7gV5vK7mk1

Entry address:
0x72DC

Entry point:
68, 1C, 7A, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, 6B, F2, BF, 09, D0, F8, 22, 48, 87, E7, 4C, BB, 31, 78, E6, 60, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 04, 00, 00, 00, 65, 53, 63, 72, 69, 70, 74, 69, 6F, 6E, 44, 6F, 77, 6E, 6C, 6F, 61, 64, 65, 72, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 0B, 55, FE, D2, 4F, 7D, 2F, F8, 48, 8C, 86, 46, F2, 45, 00, CA, 3D, 92, 93, 46, B0, 8E, BA, 76, 4A, B3, 2B, 60, 27, B5, 48, 30, EB, 3A, 4F, AD...
 
[+]

Entropy:
5.5994

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
248 KB (253,952 bytes)

The file eScriptionDownloader.exe has been seen being distributed by the following 2 URLs.

Remove eScriptionDownloader.exe - Powered by Reason Core Security