keygen التفعيل.exe

The application keygen التفعيل.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. The file has been seen being downloaded from dc95.gulfup.com.
MD5:
892eb2457edfabd3f3cbddc1050e1eba

SHA-1:
f80d66615b1c8bd3dd9dec6a40649fe744195ab1

SHA-256:
f0398b2ee9cf74edf2a93ddb08ecd1410f5370bc709007f3687ad210aecf1dda

Scanner detections:
21 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 9:09:38 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.9736169
1019

Avira AntiVirus
TR/Rogue.9736169
7.11.144.160

AVG
Crack
2015.0.3497

Bitdefender
Trojan.Generic.9736169
1.0.20.560

Comodo Security
UnclassifiedMalware
18142

Emsisoft Anti-Malware
Trojan.Generic.9736169
8.14.04.22.09

Fortinet FortiGate
W32/KeyGen.A!tr
4/22/2014

F-Secure
Trojan.Generic.9736169
11.2014-22-04_3

G Data
Trojan.Generic.9736169
14.4.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.6.1.0

K7 AntiVirus
Riskware
13.176.11833

McAfee
RDN/Generic.dx!c2i
5600.7153

MicroWorld eScan
Trojan.Generic.9736169
15.0.0.336

Norman
Troj_Generic.QXOQE
11.20140422

nProtect
Trojan.Generic.9736169
14.04.21.01

Panda Antivirus
Trj/CI.A
14.04.22.09

Qihoo 360 Security
Win32/Trojan.f9f
1.0.0.1015

Sophos
Mal/KeyGen-A
4.98

Trend Micro House Call
TROJ_SPNR.08J813
7.2.112

Trend Micro
TROJ_SPNR.08J813
10.465.22

VIPRE Antivirus
Trojan.Win32.Generic
28462

File size:
803.5 KB (822,784 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\keygen ???????.exe

File PE Metadata
Compilation timestamp:
3/7/2013 2:41:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:OrIWnTPlhMLPeCP4DlQdhAOaQBp6Seshy9Ib:+xNj6vYSM9

Entry address:
0x7C7F4

Entry point:
55, 8B, EC, 83, C4, F0, B8, 7C, AF, 47, 00, E8, FC, 9F, F8, FF, A1, 30, 0B, 48, 00, 8B, 00, E8, A0, 14, FE, FF, A1, 30, 0B, 48, 00, 8B, 00, B2, 01, E8, 6A, 33, FE, FF, A1, 30, 0B, 48, 00, 8B, 00, BA, 60, C8, 47, 00, E8, 51, 0F, FE, FF, 8B, 0D, 24, 0C, 48, 00, A1, 30, 0B, 48, 00, 8B, 00, 8B, 15, AC, A2, 47, 00, E8, 81, 14, FE, FF, A1, 30, 0B, 48, 00, 8B, 00, E8, AD, 15, FE, FF, E8, 58, 7F, F8, FF, FF, FF, FF, FF, 06, 00, 00, 00, 4B, 65, 79, 67, 65, 6E, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.8500

Developed / compiled with:
Microsoft Visual C++

Code size:
491 KB (502,784 bytes)

The file keygen التفعيل.exe has been seen being distributed by the following URL.

Remove keygen التفعيل.exe - Powered by Reason Core Security