Ketabeavval.exe

Ketabe Avval Electronic Book

Ketabe Avval

Publisher:
Ketabe Avval

Product:
Ketabe Avval Electronic Book

Version:
1.0.0.0

MD5:
475a06b97ae014005a2168a4908e0165

SHA-1:
5204b2ecfa169f89aac331d4e4362cc9d5d3ce3f

SHA-256:
0c2a7e781f7a74ff497281eaf2a64463b8caea7e57498da8ca3608c9c55e0efa

Scanner detections:
5 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/11/2025 4:40:25 PM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft A-Squared
Backdoor.Rbot!IK
4.0.0.101

Comodo Security
Heur.Suspicious
14354

F-Secure
Suspicious:W32/Malware!Gemini
11.2014-05-04_7

IKARUS anti.virus
Backdoor.Rbot
t3scan.1.2.09.0

Trend Micro House Call
TROJ_GEN.F47V1114
7.2.32

File size:
1.8 MB (1,855,488 bytes)

Product version:
1.0.0.0

Original file name:
Ketabeavval.exe

File type:
Executable application (Win32 EXE)

Language:
Persian

Common path:
C:\Program Files\ketabeavval\ketabeavval electronic book v1.1\ketabeavval.exe

File PE Metadata
Compilation timestamp:
6/20/1992 2:52:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:yGCUcP2pxbypCBDQdonv0r/5WNtqNMAkPZ64t1JM0uDGqVK84UYAuKriNKJyKJyu:yp+bypKQdEtq4VG041o8Afz9Lop

Entry address:
0x296B33

Entry point:
E8, 00, 00, 00, 00, 60, E8, 4F, 00, 00, 00, 96, 64, 96, B6, C8, BB, E9, 34, 4E, B1, A5, 49, 64, 93, 7D, 0D, 7F, E7, 03, A6, 20, F1, C4, 2F, 88, 89, 8A, D6, AF, AE, 36, 9C, 4F, 27, 57, DD, 9B, CF, C3, 27, 2B, 26, E7, 10, 6B, 47, 5C, DB, 6A, ED, 84, BC, C9, E1, AE, 15, 6A, ED, 84, BC, C9, E1, AE, 15, E9, 1A, 6D, 00, 00, E9, 2E, 6D, 00, 00, E9, 29, 6D, 00, 00, E8, 6E, FB, FF, FF, 6E, 00, 01, 00, E5, 98, 00, 00, 6B, E6, 5C, 19, 98, 2A, D1, 96, AF, 17, 74, 16, F5, 58, 91, EF, C4, D9, D0, FD, 44, BC, 69, A5, FF...
 
[+]

Entropy:
6.1975

Packer / compiler:
MoleBox v2.0

Windows Firewall Allowed Program
Name:
C:\Program Files\Ketabeavval\Ketabeavval Electronic Book v1.1\Ketabeavval.exe


Scan Ketabeavval.exe - Powered by Reason Core Security