kb18279931.exe

The executable kb18279931.exe has been detected as malware by 7 anti-virus scanners.
MD5:
1f59da03fa56376e7098411fae90bfaa

SHA-1:
6dc550272b11693a51b6c3672708787b65795f06

SHA-256:
cafce0d674ec7956553b62b62b161e771d22d3a446e1a11e502f384b17efff8a

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/26/2024 4:58:30 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.MDA
2015.11.27

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

ESET NOD32
Win32/Kryptik.EGHE trojan
7.0.302.0

F-Prot
W32/Agent.XL.gen
v6.4.7.1.166

Qihoo 360 Security
QVM10.1.Malware.Gen
1.0.0.1077

Reason Heuristics
Threat.Win.Reputation.IMP
15.11.27.23

Sophos
Mal/Wonton-BB
4.98

File size:
250 KB (256,000 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\kb18279931.exe

File PE Metadata
Compilation timestamp:
11/26/2015 3:12:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:DEWey+b9gQcT0RasmFF5P7nnjcoBNDe6R+NRM7croTh71Q:rey+bhg07i5fcQE6wRacah7m

Entry address:
0xEDF2

Entry point:
E8, 4A, 93, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 48, 60, 42, 00, E8, 78, 2B, 00, 00, 33, FF, 89, 7D, E4, 33, C0, 8B, 75, 0C, 3B, F7, 0F, 95, C0, 3B, C7, 75, 20, E8, 38, 0C, 00, 00, C7, 00, 16, 00, 00, 00, 57, 57, 57, 57, 57, E8, B6, 1E, 00, 00, 83, C4, 14, 83, C8, FF, E9, BC, 00, 00, 00, 56, E8, 9E, 01, 00, 00, 59, 89, 7D, FC, F6, 46, 0C, 40, 75, 77, 56, E8, 86, 93, 00, 00, 59, 83, F8, FF, 74, 1B, 83, F8, FE, 74, 16, 8B, D0, C1, FA, 05, 8B, C8, 83, E1, 1F, C1, E1, 06, 03, 0C, 95, A0, E9, 43, 00, EB, 05...
 
[+]

Code size:
126.5 KB (129,536 bytes)

Remove kb18279931.exe - Powered by Reason Core Security