kb00148232.exe

The executable kb00148232.exe has been detected as malware by 28 anti-virus scanners.
MD5:
f89e646c0e2282f5ba373f7a6dedddf0

SHA-1:
cc690f6dfc4f9536130f9109bfc2d3eff5f1e325

SHA-256:
a0bc46148dd7cf045cdcac7485f8f288582aa1a2fb92346f94c4d1351c8043ef

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/25/2024 10:08:59 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2026602
6204532

AhnLab V3 Security
Trojan/Win32.Agent
2014.12.20

Avira AntiVirus
TR/Crypt.Xpack.115793
7.11.196.234

avast!
Win32:Rootkit-gen [Rtk]
141214-1

AVG
Inject2
2015.0.3255

Baidu Antivirus
Trojan.Win32.Yakes
4.0.3.141220

Bitdefender
Trojan.GenericKD.2026602
1.0.20.1770

Dr.Web
Trojan.Asterope.4
9.0.1.05190

Emsisoft Anti-Malware
Trojan.GenericKD.2026602
9.0.0.4668

ESET NOD32
Win32/Injector.BRGA trojan
7.0.302.0

Fortinet FortiGate
W32/Injector.BRGA!tr
12/20/2014

F-Secure
Trojan.GenericKD.2026602
5.13.68

G Data
Trojan.GenericKD.2026602
14.12.24

K7 AntiVirus
Trojan
13.188.14395

Kaspersky
Trojan.Win32.Yakes
15.0.0.543

Malwarebytes
Trojan.Agent.ED
v2014.12.20.10

McAfee
Trojan.Trojan-FFLJ!F89E646C0E22
16.8.708.2

Microsoft Security Essentials
Threat.Undefined
1.191.419.0

MicroWorld eScan
Trojan.GenericKD.2026602
15.0.0.1062

NANO AntiVirus
Trojan.Win32.Yakes.dkkwvq
0.28.6.64267

Norman
Trojan.GenericKD.2026602
04.12.2014 14:30:06

nProtect
Trojan.GenericKD.2026602
14.12.19.01

Panda Antivirus
Trj/Genetic.gen
14.12.20.10

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.21.23

Sophos
Virus 'Mal/Wonton-T'
5.09

Trend Micro House Call
TROJ_GEN.R0C1H07LE14
7.2.355

Vba32 AntiVirus
Heur.Malware-Cryptor.Ngrbot
3.12.26.3

File size:
201 KB (205,824 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\kb00148232.exe

File PE Metadata
Compilation timestamp:
12/13/2014 10:42:03 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:W8neIOfsYrw/KWBj6Fh+cnWc67HwsoZK5kK7M6/4ihF1344iX8OK8h0cW:W4mw/In+cnWciq2MaF13sX5K8y7

Entry address:
0x21BD

Entry point:
E8, F8, 1B, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, FF, 35, 54, 30, 42, 00, 8B, 35, 0C, 91, 40, 00, FF, D6, 85, C0, 74, 21, A1, 50, 30, 42, 00, 83, F8, FF, 74, 17, 50, FF, 35, 54, 30, 42, 00, FF, D6, FF, D0, 85, C0, 74, 08, 8B, 80, F8, 01, 00, 00, EB, 27, BE, 60, 92, 40, 00, 56, FF, 15, F4, 90, 40, 00, 85, C0, 75, 0B, 56, E8, C8, FA, FF, FF, 59, 85, C0, 74, 18, 68, 50, 92, 40, 00, 50, FF, 15, FC, 90, 40, 00, 85, C0, 74, 08, FF, 75, 08, FF, D0, 89, 45, 08, 8B, 45, 08, 5E, 5D, C3, 6A, 00, E8, 87...
 
[+]

Entropy:
5.4539

Code size:
28.5 KB (29,184 bytes)

Remove kb00148232.exe - Powered by Reason Core Security