fahrschul-keybinder.exe

The executable fahrschul-keybinder.exe has been detected as malware by 17 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from fs.netplayzone.net.
MD5:
ec3dc4bc26258868d7fe7bc5129d06c4

SHA-1:
b00cbb24a787ba9e836f62d09499d2e95c7b3f3c

SHA-256:
c914ddf17d2fb9b8e9848ca95f219eba780d831fad7ca6c44a7df0c25ffa0855

Scanner detections:
17 / 68

Status:
Malware

Analysis date:
4/26/2024 2:13:49 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.9918404
1125

avast!
Win32:Malware-gen
2014.9-140106

Bitdefender
Trojan.Generic.9918404
1.0.20.30

Bkav FE
HW32.CDB
1.3.0.4613

Emsisoft Anti-Malware
Trojan.Generic.9918404
8.14.01.06.09

F-Prot
W32/Downloader.N.gen
v6.4.7.1.166

G Data
Trojan.Generic.9918404
14.1.22

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.2.2.29

Malwarebytes
Malware.Packer.YPGen
v2014.01.06.09

MicroWorld eScan
Trojan.Generic.9918404
15.0.0.18

Norman
Suspicious_Y.gen
11.20140106

nProtect
Trojan.Generic.9918404
14.01.06.03

Panda Antivirus
Suspicious file
14.01.06.09

Quick Heal
(Suspicious) - DNAScan
1.14.12.00

Trend Micro House Call
Cryp_Yodap
7.2.6

Trend Micro
Cryp_Yodap
10.465.06

VIPRE Antivirus
Trojan.Win32.Generic
25146

File size:
389 KB (398,336 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
8/27/2013 12:11:34 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:oBuem++rUNVJ707B5rSQ/G8/H1Ay/0XgdlE:murrUN87B5rF/G8tNbdl

Entry address:
0xDB6ED

Entry point:
E8, 03, 00, 00, 00, EB, 01, E8, BB, 55, 00, 00, 00, E8, 03, 00, 00, 00, EB, 01, E9, E8, 8E, 00, 00, 00, E8, 03, 00, 00, 00, EB, 01, C2, E8, 81, 00, 00, 00, E8, 03, 00, 00, 00, EB, 01, C2, E8, B7, 00, 00, 00, E8, 03, 00, 00, 00, EB, 01, E8, E8, AA, 00, 00, 00, E8, 03, 00, 00, 00, EB, 01, C2, 83, FB, 55, E8, 03, 00, 00, 00, EB, 01, E8, 75, 2D, E8, 03, 00, 00, 00, EB, 01, E8, 60, E8, 00, 00, 00, 00, 5D, 81, ED, 07, E2, 40, 00, 8B, D5, 81, C2, 56, E2, 40, 00, 52, E8, 01, 00, 00, 00, C3, C3, E8, 03, 00, 00, 00...
 
[+]

Packer / compiler:
yoda's Protector v1.03.3)

Code size:
579 KB (592,896 bytes)

The file fahrschul-keybinder.exe has been seen being distributed by the following URL.

Remove fahrschul-keybinder.exe - Powered by Reason Core Security