hgo-fr7p.exe

The executable hgo-fr7p.exe has been detected as malware by 26 anti-virus scanners. The file has been seen being downloaded from mckamikaz3.free.fr.
MD5:
1c4317e1da0da0b2a6b1ae0297a0d4c2

SHA-1:
4f821957be584ecba0f277f3076df2406cc77f78

SHA-256:
fddd0e881396c69c4662f68b2216c35f0ddf909a691a2a658f62269643edbd25

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
4/25/2024 9:18:24 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.2606854
1150

Agnitum Outpost
Suspicious
7.1.1

AVG
Generic5
2014.0.3543

Baidu Antivirus
HackTool.Win32.Keygen
4.0.3.131127

Bitdefender
Trojan.Generic.2606854
1.0.20.1205

Comodo Security
UnclassifiedMalware
17503

Emsisoft Anti-Malware
Trojan.Generic.2606854
8.13.08.29.06

Fortinet FortiGate
Keygen.AP!tr
8/29/2013

F-Prot
W32/Heuristic-210
v6.4.7.1.166

F-Secure
Trojan.Generic.2606854
11.2013-29-08_5

G Data
Trojan.Generic.2606854
13.8.22

IKARUS anti.virus
Virus.Win32.Trojan
t3scan.2.2.29

K7 AntiVirus
Trojan
13.174.10644

Malwarebytes
Malware.Packer.Gen
v2013.08.29.06

Microsoft Security Essentials
1.165.247.01

MicroWorld eScan
Trojan.Generic.2606854
14.0.0.723

NANO AntiVirus
Trojan.Win32.Bifrost.bbswkj
0.28.0.57029

Norman
Suspicious_F.A
11.20130829

Quick Heal
HackTool.Keygen (Not a Virus)
8.13.12.00

Reason Heuristics
Unnamed.Threat.38
14.3.1.0

Rising Antivirus
PE:Trojan.Win32.Generic.1242D70D!306370317
23.00.65.13827

Sophos
Mal/Packer
4.96

SUPERAntiSpyware
Trojan.Agent/Gen-FSG
10708

Trend Micro House Call
TROJ_SPNR.08JU11
7.2.241

Trend Micro
TROJ_SPNR.08JU11
10.465.29

VIPRE Antivirus
Trojan.Win32.Generic
24780

File size:
5.1 KB (5,264 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\hgo-fr7p.exe

File PE Metadata
Compilation timestamp:
9/10/1987 6:35:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

CTPH (ssdeep):
96:hLkVRYJ53bzYbgmdIcKyXZyiH1dTrgLgOQVis:hcqX3bkzIoQAe7sis

Entry address:
0x8197

Entry point:
BE, A4, 01, 40, 00, AD, 93, AD, 97, AD, 56, 96, B2, 80, A4, B6, 80, FF, 13, 73, F9, 33, C9, FF, 13, 73, 16, 33, C0, FF, 13, 73, 1F, B6, 80, 41, B0, 10, FF, 13, 12, C0, 73, FA, 75, 3C, AA, EB, E0, FF, 53, 08, 02, F6, 83, D9, 01, 75, 0E, FF, 53, 04, EB, 26, AC, D1, E8, 74, 2F, 13, C9, EB, 1A, 91, 48, C1, E0, 08, AC, FF, 53, 04, 3D, 00, 7D, 00, 00, 73, 0A, 80, FC, 05, 73, 06, 83, F8, 7F, 77, 02, 41, 41, 95, 8B, C5, B6, 00, 56, 8B, F7, 2B, F0, F3, A4, 5E, EB, 9D, 8B, D6, 5E, AD, 48, 74, 0A, 79, 02, AD, 50, 56...
 
[+]

Entropy:
6.8121

Packer / compiler:
FSG v1.33

Code size:
2.5 KB (2,560 bytes)

The file hgo-fr7p.exe has been seen being distributed by the following URL.

Remove hgo-fr7p.exe - Powered by Reason Core Security