hela_1.0.5

The file hela_1.0.5 has been detected as a potentially unwanted program by 17 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered by a time event. The file has been seen being downloaded from o24x7.com.
MD5:
47620a18684a911b6a69eeefb4e87e6d

SHA-1:
5e1b7e0596ef7220873640eb6097cae60c7a67c5

SHA-256:
c96bbb12ad19b6ad39f45c9fc873897eed0f40601cf66483c5b58e177c34d857

Scanner detections:
17 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 10:44:22 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2131551
705

Avira AntiVirus
Adware/Gertokr.879104.1
7.11.206.68

avast!
Win32:Malware-gen
2014.9-150302

AVG
Found Win32/DH{gRIeA2KBEyU}
2014.0.4025

Baidu Antivirus
Adware.Win32.Gertokr
4.0.3.1532

Bitdefender
Trojan.GenericKD.2131551
1.0.20.305

Comodo Security
ApplicUnwnt
20920

Emsisoft Anti-Malware
Trojan.GenericKD.2131551
8.15.03.02.12

ESET NOD32
Win32/Adware.Gertokr (variant)
9.11104

F-Secure
Trojan.GenericKD.2131551
11.2015-02-03_2

G Data
Trojan.GenericKD.2131551
15.3.25

IKARUS anti.virus
PUA.Gertokr
t3scan.1.8.6.0

MicroWorld eScan
Trojan.GenericKD.2131551
16.0.0.183

NANO AntiVirus
Trojan.Win32.RYSJ1244.dhgboy
0.30.0.65070

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.2.0

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

Zillya! Antivirus
Adware.Agent.Win32.26757
2.0.0.2050

File size:
858.5 KB (879,104 bytes)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\hela_1.0.5

File PE Metadata
Compilation timestamp:
8/26/2014 4:54:09 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:sh77yi4TPdhp+aKKGshjIlhPjLZOH8EAgcLLGIlP5nXgdwJec:sd74FhsaKKBjIlZLZOHLAgcHjt5Xwc

Entry address:
0x9024A

Entry point:
E8, B1, FB, 00, 00, E9, 7F, FE, FF, FF, E8, 94, 6A, 00, 00, 85, C0, 75, 06, B8, 14, 36, 4C, 00, C3, 83, C0, 0C, C3, 55, 8B, EC, 56, E8, E4, FF, FF, FF, 8B, 4D, 08, 51, 89, 08, E8, 20, 00, 00, 00, 59, 8B, F0, E8, 05, 00, 00, 00, 89, 30, 5E, 5D, C3, E8, 60, 6A, 00, 00, 85, C0, 75, 06, B8, 10, 36, 4C, 00, C3, 83, C0, 08, C3, 55, 8B, EC, 8B, 4D, 08, 33, C0, 3B, 0C, C5, A8, 34, 4C, 00, 74, 27, 40, 83, F8, 2D, 72, F1, 8D, 41, ED, 83, F8, 11, 77, 05, 6A, 0D, 58, 5D, C3, 8D, 81, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8...
 
[+]

Entropy:
6.6350

Code size:
687.5 KB (704,000 bytes)

Scheduled Task
Task name:
Microsoft-Windows-HashDiagnostic

Path:
\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-HashDiagnostic

Trigger:
Time (Next runs on 27/09/2014 at 18:01)


The file hela_1.0.5 has been seen being distributed by the following URL.

Remove hela_1.0.5 - Powered by Reason Core Security