gobel.exe

The application gobel.exe has been detected as a potentially unwanted program by 32 anti-malware scanners. The file has been seen being downloaded from neocity1.free.fr.
MD5:
7a19cc896f7015d8484e46e672dfa1b9

SHA-1:
b02cc67dd116ba084cb98fc2314e240afcd3d61d

SHA-256:
eb240f1cbf294097879ee71a2ead3daca0116b938a2f553691bbe1c46d5ee16b

Scanner detections:
32 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 1:52:31 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Backdoor.Generic.704849
1133

Agnitum Outpost
Backdoor.Agent
7.1.1

AhnLab V3 Security
Spyware/Win32.Gray_generic
2013.10.20

Avira AntiVirus
JOKE/Cokegift
7.11.121.86

avast!
Win32:PUP-gen [PUP]
2014.9-130829

AVG
Joke.F
2014.0.3543

Baidu Antivirus
Trojan.Win32.Joke
4.0.3.131127

Bitdefender
Backdoor.Generic.704849
1.0.20.1205

Bkav FE
W32.DenmontN.Trojan
1.3.0.4261

Comodo Security
UnclassifiedMalware
17483

Dr.Web
Joke.Geschenk
9.0.1.0331

Emsisoft Anti-Malware
Backdoor.Generic.704849
8.13.08.29.06

Fortinet FortiGate
W32/Geschenk
8/29/2013

F-Prot
W32/Backdoor.BNAG
v6.4.7.1.166

F-Secure
Backdoor.Generic.704849
11.2013-29-08_5

G Data
Backdoor.Generic.704849
13.8.22

IKARUS anti.virus
not-a-virus.BadJoke.Geschenk
t3scan.2.2.29

K7 AntiVirus
Backdoor
13.174.10588

McAfee
Joke-Geschenk
5600.7181

Microsoft Security Essentials
Joke:Win32/Kokegift.A
1.165.247.01

MicroWorld eScan
Backdoor.Generic.704849
14.0.0.723

NANO AntiVirus
Riskware.Win32.Geschenk.bdflz
0.28.0.57029

Norman
Suspicious_Gen2.AALRP
11.20130829

nProtect
Joke/W32.Cokegift.268800
13.12.22.01

Panda Antivirus
Joke/Geschenk
13.08.29.06

Reason Heuristics
Unnamed.Threat.46
14.3.1.0

Sophos
Generic PUA LA
4.96

SUPERAntiSpyware
Trojan.Agent/Gen-Koke
10708

Trend Micro House Call
GRAY_Generic
7.2.241

Trend Micro
GRAY_Generic
10.465.29

VIPRE Antivirus
Joke.Win32.Kokegift.A (not malicious)
24644

ViRobot
Joke.Win32.Cokegift
2011.4.7.4223

File size:
262.5 KB (268,800 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\gobel.exe

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:nFyOrD+0/9dILpiUnK0+pSkEOqraqlmDyW10:FyOfuLoUnypzhqraAmDyW10

Entry address:
0x31FF8

Entry point:
55, 8B, EC, 83, C4, F4, B8, 18, 1F, 43, 00, E8, D0, 30, FD, FF, A1, 8C, 3A, 43, 00, 8B, 00, E8, 4C, 86, FF, FF, 8B, 0D, 08, 3B, 43, 00, A1, 8C, 3A, 43, 00, 8B, 00, 8B, 15, 5C, 1C, 43, 00, E8, 4C, 86, FF, FF, A1, 8C, 3A, 43, 00, 8B, 00, E8, CC, 86, FF, FF, E8, EF, 14, FD, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3767

Developed / compiled with:
Microsoft Visual C++

Code size:
196.5 KB (201,216 bytes)

The file gobel.exe has been seen being distributed by the following URL.

Remove gobel.exe - Powered by Reason Core Security