Ketabeavval.exe

Ketabe Avval Electronic Book

Ketabe Avval

Publisher:
Ketabe Avval

Product:
Ketabe Avval Electronic Book

Version:
1.0.0.0

MD5:
a7dd45696f26a1fc4e05bcc6f70a5319

SHA-1:
271d88516b3909425c1a851268cfa04ff3733a00

Scanner detections:
5 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 12:24:44 PM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft A-Squared
Backdoor.Rbot!IK
4.0.0.101

Comodo Security
Heur.Suspicious
14354

F-Secure
Suspicious:W32/Malware!Gemini
11.2014-02-02_1

IKARUS anti.virus
Backdoor.Rbot
t3scan.1.2.09.0

Trend Micro House Call
TROJ_GEN.F47V1114
7.2.96

File size:
1.8 MB (1,855,488 bytes)

Product version:
1.0.0.0

Original file name:
Ketabeavval.exe

File type:
Executable application (Win32 EXE)

Language:
Farsi

Common path:
C:\Program Files\ketabeavval\ketabeavval electronic book v1.1\ketabeavval.exe

File PE Metadata
Compilation timestamp:
6/20/1992 2:52:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:yGCUcP2pxbypCBDQdonv0r/5WNtqNMAkPZ64t1JM0uDGqVK84UYAuKriNKJyKJye:yp+bypKQdEtq4VG041o8Afz9bop

Entry address:
0x296B33

Entry point:
E8, 00, 00, 00, 00, 60, E8, 4F, 00, 00, 00, 61, E2, 1A, 37, 55, F9, 92, 4E, 1A, 27, 9A, 7B, 03, 9C, E2, 80, AF, FE, 6E, 63, 12, A5, 5A, FF, 57, 21, BF, 03, C0, 27, 25, 43, 4F, E6, FC, 6B, A5, 6E, 9C, E5, FC, 76, 08, 23, FE, B7, 67, 89, 37, 37, 13, A5, DB, 28, CF, 3A, 37, 37, 13, A5, DB, 28, CF, 3A, E9, 1A, 6D, 00, 00, E9, 2E, 6D, 00, 00, E9, 29, 6D, 00, 00, E8, 6E, FB, FF, FF, 6E, 00, 01, 00, E5, 98, 00, 00, E4, E8, D4, F9, 98, 2A, D1, 96, AF, 17, 74, 16, F5, 58, 91, EF, C4, D9, D0, FD, 44, BC, 69, A5, FF...
 
[+]

Entropy:
6.1975

Packer / compiler:
MoleBox v2.0

Windows Firewall Allowed Program
Name:
C:\Program Files\Ketabeavval\Ketabeavval Electronic Book v1.1\Ketabeavval.exe


Scan Ketabeavval.exe - Powered by Reason Core Security