kb00151508.exe

The executable kb00151508.exe has been detected as malware by 30 anti-virus scanners.
MD5:
4a4545b59e2c0138006d33bb29da8195

SHA-1:
268fdd6591482046fa4b3ea63a4ca3a1c934c068

SHA-256:
81f768c40510c88743dfe46f450e6fdc49715848d8f8998231564b465b05f97e

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
4/25/2024 6:44:01 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2026604
777

AhnLab V3 Security
Trojan/Win32.Agent
2014.12.20

Avira AntiVirus
TR/Crypt.Xpack.115859
7.11.196.230

avast!
Win32:Rootkit-gen [Rtk]
2014.9-141220

AVG
Inject2
2015.0.3255

Baidu Antivirus
Trojan.Win32.Yakes
4.0.3.141221

Bitdefender
Trojan.GenericKD.2026604
1.0.20.1770

Dr.Web
Trojan.Asterope.4
9.0.1.0354

Emsisoft Anti-Malware
Trojan.GenericKD.2026604
8.14.12.20.11

ESET NOD32
Win32/Injector.BRGA (variant)
8.10906

Fortinet FortiGate
W32/Yakes.HUXO!tr
12/20/2014

F-Secure
Trojan.GenericKD.2026598
11.2014-21-12_1

G Data
Trojan.GenericKD.2026604
14.12.24

IKARUS anti.virus
Trojan.Win32.Yakes
t3scan.1.8.5.0

K7 AntiVirus
Trojan
13.188.14395

Kaspersky
Trojan.Win32.Yakes
14.0.0.2768

Malwarebytes
Trojan.Agent.ED
v2014.12.20.11

McAfee
RDN/Generic.dx!dhm
5600.6911

Microsoft Security Essentials
VirTool:Win32/Injector.EY
1.11302

MicroWorld eScan
Trojan.GenericKD.2026604
15.0.0.1062

NANO AntiVirus
Trojan.Win32.Yakes.dkkwvq
0.28.6.64267

Norman
Trojan.GenericKD.2026598
11.20141221

nProtect
Trojan.GenericKD.2026604
14.12.19.01

Panda Antivirus
Trj/Genetic.gen
14.12.20.11

Qihoo 360 Security
Win32/Trojan.990
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.21.23

Sophos
Mal/Wonton-T
4.98

Trend Micro House Call
Suspicious_GEN.F47V1213
7.2.354

Vba32 AntiVirus
Heur.Malware-Cryptor.Ngrbot
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
35904

File size:
185 KB (189,440 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\kb00151508.exe

File PE Metadata
Compilation timestamp:
12/13/2014 10:37:57 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
1536:A8neIOfsYrw/KWBj6Fh+cnWc2qndKiS+ktV5lOZcYLfCRxslc/:A4mw/In+cnWcJgxhvOD1lm

Entry address:
0x21BD

Entry point:
E8, F8, 1B, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, FF, 35, 54, 30, 42, 00, 8B, 35, 0C, 91, 40, 00, FF, D6, 85, C0, 74, 21, A1, 50, 30, 42, 00, 83, F8, FF, 74, 17, 50, FF, 35, 54, 30, 42, 00, FF, D6, FF, D0, 85, C0, 74, 08, 8B, 80, F8, 01, 00, 00, EB, 27, BE, 60, 92, 40, 00, 56, FF, 15, F4, 90, 40, 00, 85, C0, 75, 0B, 56, E8, C8, FA, FF, FF, 59, 85, C0, 74, 18, 68, 50, 92, 40, 00, 50, FF, 15, FC, 90, 40, 00, 85, C0, 74, 08, FF, 75, 08, FF, D0, 89, 45, 08, 8B, 45, 08, 5E, 5D, C3, 6A, 00, E8, 87...
 
[+]

Entropy:
5.1369

Code size:
28.5 KB (29,184 bytes)

Remove kb00151508.exe - Powered by Reason Core Security