HawtMaple.exe

The application HawtMaple.exe has been detected as a potentially unwanted program by 22 anti-malware scanners. This file is typically installed with the program MapleStory by Wizet. The file has been seen being downloaded from hostr.co and multiple other hosts.
Version:
0.0.0.0

MD5:
d875e7bcf3b593bd732e2331831aa897

SHA-1:
de2f04a6f8d24d5be641d98d7c9ce4629de59d28

SHA-256:
62813bef5da72a621e600bfb016934e7b96ee4ce1b97220b4b0494ffcabf6886

Scanner detections:
22 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 1:16:40 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1687915
950

Agnitum Outpost
Riskware.Confuser
7.1.1

Avira AntiVirus
TR/Dropper.MSIL.Gen2
7.11.157.134

Baidu Antivirus
Trojan.MSIL.Confuser
4.0.3.14630

Bitdefender
Trojan.GenericKD.1687915
1.0.20.905

Comodo Security
UnclassifiedMalware
18707

Emsisoft Anti-Malware
Trojan.GenericKD.1687915
8.14.06.30.11

ESET NOD32
MSIL/Packed.Confuser (variant)
8.10015

Fortinet FortiGate
Riskware/Fam.NB
6/30/2014

F-Secure
Trojan.GenericKD.1687915
11.2014-30-06_2

G Data
Trojan.GenericKD.1687915
14.6.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.6.1.0

McAfee
Artemis!D875E7BCF3B5
5600.7084

MicroWorld eScan
Trojan.GenericKD.1687915
15.0.0.543

NANO AntiVirus
Trojan.Win32.DomaIQ.dboqao
0.28.0.60475

Norman
Obfuscated.gen!r
11.20140630

nProtect
Trojan.GenericKD.1687915
14.06.27.01

Panda Antivirus
Trj/CI.A
14.06.30.11

Sophos
Generic PUA NO
4.98

Trend Micro House Call
TROJ_GEN.R02KC0OET14
7.2.181

Trend Micro
TROJ_GEN.R02KC0OET14
10.465.30

VIPRE Antivirus
Trojan.Win32.Generic
30766

File size:
2.7 MB (2,791,424 bytes)

Product version:
0.0.0.0

Original file name:
HawtMaple.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\hawtmaple.exe

File PE Metadata
Compilation timestamp:
5/3/2014 6:48:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:HVvO2pniYCy36L4z0FPmxtVrK4UPzsB7iY+qGJ9GvU/Z9worBKAu/qgIZsEhSRYL:HVvO2ZiYn3poFPmxtVrKDPzsB7iY+qGT

Entry address:
0x26E07E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7736

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.4 MB (2,540,032 bytes)

The file HawtMaple.exe has been discovered within the following program.

MapleStory  by Wizet
MapleStory is a free-to-play, 2D, side-scrolling massively multiplayer online role-playing game, developed by the South Korean company Wizet.
maplestory.nexon.net
About 6% of users remove it
 
Powered by Should I Remove It?

The file HawtMaple.exe has been seen being distributed by the following 2 URLs.

Remove HawtMaple.exe - Powered by Reason Core Security