get.exe

The application get.exe has been detected as a potentially unwanted program by 30 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.kloster-walkenried.de.
Version:
3, 3, 8, 1

MD5:
226e45beff5a3d494db02f1fa4aa72fc

SHA-1:
ab61773eb1a4dd945838a013fcd1388ec019a736

SHA-256:
90b2d8d9f775815c3a50b8b61b753d41f2ae3e1d0870f93b57d53b964eb6f7e3

Scanner detections:
30 / 68

Status:
Potentially unwanted

Analysis date:
5/19/2024 10:46:20 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.9993272
1134

AhnLab V3 Security
Trojan/Win32.Autoit
2013.12.20

avast!
Win32:Downloader-UGJ [Trj]
2014.9-131227

AVG
Autoit_c
2014.0.3612

Baidu Antivirus
Trojan.Win32.Autoit
4.0.3.131227

Bitdefender
Trojan.Generic.9993272
1.0.20.1805

Bkav FE
W32.Clodebc.Trojan
1.3.0.4613

Comodo Security
Worm.Win32.P2P-Worm.Palevo.fqau
17467

Dr.Web
Trojan.DownLoader10.33280
9.0.1.0361

Emsisoft Anti-Malware
Trojan.Generic.9993272
8.13.12.27.04

ESET NOD32
Win32/TrojanClicker.Autoit.NDA
7.9190

Fortinet FortiGate
W32/Autoit.BNW!tr
12/27/2013

F-Prot
W32/Trojan2.NWGR
v6.4.7.1.166

F-Secure
Trojan.Generic.9993272
11.2013-27-12_6

G Data
Trojan.Generic.9993272
13.12.22

IKARUS anti.virus
Trojan.Win32.Spy
t3scan.2.2.29

K7 AntiVirus
Spyware
13.174.10560

Kaspersky
Trojan.Win32.Autoit
14.0.0.4557

Malwarebytes
Trojan.Agent.AI
v2013.12.27.04

McAfee
RDN/Generic.dx!cqq
5600.7268

MicroWorld eScan
Trojan.Generic.9993272
14.0.0.1083

Norman
Suspicious_Gen4.EYFQK
11.20131227

Panda Antivirus
Trj/CI.A
13.12.27.04

Rising Antivirus
AU3SCRIPT:Dropper.Insrun!1.9E21
23.00.65.131225

Sophos
Mal/Generic-S
4.96

Trend Micro House Call
TROJ_GEN.R01TH07L113
7.2.361

Trend Micro
TROJ_EMBEDDED.LL
10.465.27

Vba32 AntiVirus
Trojan.Autoit
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
24524

ViRobot
Adware.Agent.803580
2011.4.7.4223

File size:
784.7 KB (803,580 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\get.exe

File PE Metadata
Compilation timestamp:
1/29/2012 11:32:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:06Wq4aaE6KwyF5L0Y2D1PqLKsUhrKdk3sOxyqSdiut2cxz+I4on+Io9cgRKf3tYi:ythEVaPqLOQws7GkyIqfRKf9YNq1B

Entry address:
0xB2E60

Entry point:
60, BE, 00, 10, 47, 00, 8D, BE, 00, 00, F9, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.9870

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
268 KB (274,432 bytes)

The file get.exe has been seen being distributed by the following URL.

Remove get.exe - Powered by Reason Core Security