keygen.exe

The application keygen.exe has been detected as a potentially unwanted program by 15 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www95.zippyshare.com.
MD5:
50bd056e609cb8fd3425c57b1ecee799

SHA-1:
1198163e84216760b77257a5cf207d77a629f598

SHA-256:
abdf43510c51ee0ff6a4e7570d57e5c608d9e0ff648672e2830158358f313407

Scanner detections:
15 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 10:32:12 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.14550130
552

Arcabit
Trojan.Generic.DDE0472
1.0.0.425

avast!
Win32:Malware-gen
2014.9-150801

AVG
Crack
2016.0.3030

Baidu Antivirus
Hacktool.Win32.Keygen
4.0.3.1581

Bitdefender
Trojan.Generic.14550130
1.0.20.1065

Emsisoft Anti-Malware
Trojan.Generic.14550130
8.15.08.01.02

ESET NOD32
Win32/Keygen.HY potentially unsafe (variant)
9.11926

F-Secure
Trojan.Generic.14550130
11.2015-01-08_7

G Data
Trojan.Generic.14550130
15.8.25

K7 AntiVirus
Unwanted-Program
13.205.16534

MicroWorld eScan
Trojan.Generic.14550130
16.0.0.639

nProtect
Trojan.Generic.14550130
15.07.10.01

Trend Micro
TROJ_GEN.R047C0OET15
10.465.01

VIPRE Antivirus
Trojan.Win32.Generic
41934

File size:
32 KB (32,768 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\compressed\7data.recovery.suite.enterprise.v3.3_asandl.com\install\keygen\keygen.exe

File PE Metadata
Compilation timestamp:
9/2/2013 4:38:58 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
768:FggmnipP2knjZpriaJxG7oXXRuQCAaosLK7C:0ipuojZJiaTgoXcm7C

Entry address:
0x1A25

Entry point:
B8, 48, C2, 42, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 7B, 79, AC, A3, 6B, FB, D5, 20, 7F, AB, 3A, 38, 9C, 84, 45, B9, 90, 34, 26, 9C, 23, F8, AB, FD, 10, AB, DE, 5A, E8, 6C, 78, 24, C6, 4E, 61, 5F, 19, 0A, D2, A8, AF, 2B, 73, EA, 2E, 70, 07, 15, 2B, B0, 66, AB, B5, FE, C9, 3B, 4F, E0, B8, 87, 89, 64, 6B, DE, DD, 3B, 5A, 47, 0E, 6A, 73, B1, AB, 8A, E8, 4C, 9A, D8, 97, 71, CF, EA, D2, C4, DE, 7E, C0, 77, 3C, 58, 3F, 5F, CF...
 
[+]

Entropy:
7.7369

Packer / compiler:
PECompact v2

Code size:
11 KB (11,264 bytes)

The file keygen.exe has been seen being distributed by the following URL.

Remove keygen.exe - Powered by Reason Core Security