Kaspersky Keygen.exe

WindowsApplication2

Microsoft

This is a setup program which is used to install the application. The file has been seen being downloaded from s8005.abelhas.pt and multiple other hosts.
Publisher:
Microsoft

Product:
WindowsApplication2

Description:
Kaspersky Keygen

Version:
1.0.0.0

MD5:
79a60ee55973739825353055e23f1e3f

SHA-1:
1faf92cd2040ad55e1fb0b66286fb926ae8f5b9c

SHA-256:
38d2f036a2be8309a3eaf6c8b1fedc223e226ea3da20e3b0610373254e3d1bb9

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/24/2024 10:07:27 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.Dropper.W32.Injector
2.1.4+

Bkav FE
W32.HfsAutoA
1.3.0.4923

File size:
850.5 KB (870,912 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Microsoft 2013

Original file name:
Kaspersky Keygen.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\kaspersky keygen.exe

File PE Metadata
Compilation timestamp:
11/17/2013 8:25:33 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:RAzFzGwDBQIv9SOFDgs5n4BeWR9Jei9qQmE1nJ1HAiAzFzGUDBQIi:6JtQIv9SOFDnOZRWlJE1JoJDQIi

Entry address:
0x9CFDE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 6D, 6F, 88, 52, 00, 00, 00, 00, 02, 00, 00, 00, 1C, 01, 00, 00, 1C, E0, 09, 00, 1C, B4, 09, 00, 52, 53, 44, 53, 22, 9C, 51, F7, 53, A4, 91, 4F, B0, 7E, 74, 27, 6D, B2, E4, C1, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 55, 73, 65, 72, 5C, 64, 6F, 63, 75, 6D, 65, 6E, 74, 73, 5C, 76, 69, 73, 75, 61, 6C, 20, 73, 74, 75, 64, 69, 6F, 20, 32, 30, 31, 32...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
620 KB (634,880 bytes)

The file Kaspersky Keygen.exe has been seen being distributed by the following 3 URLs.

http://s8005.abelhas.pt/File.aspx?e=Iup_KvKLh5nLvZFWmxeCHYrD6nMV49UOiVk3ifFvxNg_uczzdqniX3Un4ZV4demnpzEhPWhI2kR7JFpmsTjPURnrbjTo4EKBDqhh3bLMaS5fgx-RYVgwZgxDRQvQ6IcwXCvRgjo5PYqowGZ85prHlg&pv=2

Scan Kaspersky Keygen.exe - Powered by Reason Core Security