kb148945609.exe

The executable kb148945609.exe has been detected as malware by 28 anti-virus scanners.
MD5:
825a60a23ed04477f0b46461f880bfda

SHA-1:
e92fd48da72272b13bbcf041b35e5e289c0c2b7b

SHA-256:
0b116fe2137c998cb4695b40c90a5abc2acb7d4e507d44f1960dd1136deab4d9

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/26/2024 7:21:32 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.58510
435

Agnitum Outpost
Trojan.Droma
7.1.1

AhnLab V3 Security
Malware/Win32.Generic
2015.11.25

Avira AntiVirus
TR/Crypt.ZPACK.215596
8.3.2.4

Arcabit
Trojan.Symmi.DE48E
1.0.0.624

avast!
Win32:Agent-BBLQ [Trj]
2014.9-151126

AVG
Crypt5
2016.0.2913

Baidu Antivirus
Trojan.Win32.Droma
4.0.3.151126

Bitdefender
Gen:Variant.Symmi.58510
1.0.20.1650

Bkav FE
W32.GiascovaLTV
1.3.0.7383

Dr.Web
Trojan.PWS.Siggen1.44199
9.0.1.0330

Emsisoft Anti-Malware
Gen:Variant.Symmi.58510
8.15.11.26.08

ESET NOD32
Win32/Kryptik.EFSZ (variant)
9.12619

Fortinet FortiGate
W32/Droma.EFSZ!tr
11/26/2015

F-Prot
W32/Agent.XL.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Symmi.58510
11.2015-26-11_5

G Data
Gen:Variant.Symmi.58510
15.11.25

IKARUS anti.virus
Trojan.Win32.Crypt
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.212.17959

Kaspersky
Trojan.Win32.Droma
14.0.0.1061

Malwarebytes
Trojan.Dropper
v2015.11.26.08

McAfee
Artemis!825A60A23ED0
5600.6569

Microsoft Security Essentials
Trojan:Win32/Bagsu!rfn
1.1.12300.0

MicroWorld eScan
Gen:Variant.Symmi.58510
16.0.0.990

Panda Antivirus
Trj/GdSda.A
15.11.26.08

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1077

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic
45404

File size:
536 KB (548,864 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\kb148945609.exe

File PE Metadata
Compilation timestamp:
11/21/2015 1:34:02 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:zjcC25WsdFbaWcR0daWko9rxPBzZgK6w2vgVcDz4eeMVXHouV:zjcC+/zbqM1/5liVgu4eeMNIuV

Entry address:
0xAA92

Entry point:
E8, 65, 82, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, D8, 17, 42, 00, E8, EC, 17, 00, 00, 33, FF, 89, 7D, E4, 33, C0, 8B, 75, 0C, 3B, F7, 0F, 95, C0, 3B, C7, 75, 20, E8, 0A, E9, FF, FF, C7, 00, 16, 00, 00, 00, 57, 57, 57, 57, 57, E8, 70, 3B, 00, 00, 83, C4, 14, 83, C8, FF, E9, BC, 00, 00, 00, 56, E8, 24, F8, FF, FF, 59, 89, 7D, FC, F6, 46, 0C, 40, 75, 77, 56, E8, B8, 60, 00, 00, 59, 83, F8, FF, 74, 1B, 83, F8, FE, 74, 16, 8B, D0, C1, FA, 05, 8B, C8, 83, E1, 1F, C1, E1, 06, 03, 0C, 95, 80, DB, 45, 00, EB, 05...
 
[+]

Entropy:
6.2836

Code size:
109 KB (111,616 bytes)

Remove kb148945609.exe - Powered by Reason Core Security