keygen.exe

The application keygen.exe has been detected as a potentially unwanted program by 25 anti-malware scanners. This is a setup program which is used to install the application.
MD5:
a305a0f6fbae00cfa4a9a999b8342bda

SHA-1:
6e05ba6070d6306cecd58c06b5ca0b7f880fdf2f

SHA-256:
17b9e0de848436dfc56029fcbccb75e0047d373f1b3bc56350b7f27eae4fe4a9

Scanner detections:
25 / 68

Status:
Potentially unwanted

Analysis date:
5/22/2024 1:11:06 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.9907343
1080

Agnitum Outpost
Riskware.Keygen
7.1.1

AhnLab V3 Security
Backdoor/Win32.Graybird
2014.02.19

Avira AntiVirus
TR/Crypt.XDR.Gen
7.11.132.90

avast!
Win32:Malware-gen
2014.9-140219

AVG
Crack
2015.0.3558

Bitdefender
Trojan.Generic.9907343
1.0.20.250

Bkav FE
W32.Clode88.Trojan
1.3.0.4924

Comodo Security
UnclassifiedMalware
17807

Emsisoft Anti-Malware
Trojan.Generic.9907343
8.14.02.19.06

ESET NOD32
Win32/Keygen.AU (variant)
8.9439

F-Secure
Trojan.Generic.9907343
11.2014-19-02_4

G Data
Trojan.Generic.9907343
14.2.24

IKARUS anti.virus
Keygen
t3scan.2.2.29

K7 AntiVirus
Trojan
13.176.11205

McAfee
RDN/Generic PUP.x!bmn
5600.7214

MicroWorld eScan
Trojan.Generic.9907343
15.0.0.150

Norman
Suspicious_Gen4.FGWUD
11.20140219

nProtect
Trojan.Generic.9907343
14.02.18.03

Panda Antivirus
Trj/CI.A
14.02.19.06

Sophos
Mal/KeyGen-M
4.97

Trend Micro House Call
TROJ_SPNR.08KD13
7.2.50

Trend Micro
TROJ_SPNR.08KD13
10.465.19

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
26594

ViRobot
Backdoor.Win32.S.Graybird.196096
2011.4.7.4223

File size:
191.5 KB (196,096 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\nitro\pro 9\keygen.exe

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:YYaBHEfomt3HhTvxnFElTUdb9dIwSNbAQcatwM/XItMj+cWYLfy+rle2oXk7PlqP:zCHsom1RvJFITU1tScM/4ij6YLfZrCk6

Entry address:
0x18DD8

Entry point:
B8, 2C, 87, 46, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 04, 10, F7, 7D, FC, 77, EF, 4A, DB, DF, 24, 94, DC, FF, BD, 99, 49, 03, 8B, 5C, AC, 26, 6C, 2B, C5, 91, 80, 72, 2E, AC, CE, FA, 44, 12, 01, 9B, 1B, E6, A0, E2, 4A, D6, DC, 43, 53, 25, 4E, BD, F2, D9, 96, F6, 49, 9F, 07, 6A, F1, C7, 9B, 88, 08, ED, 1E, 4A, 90, 3E, 93, 37, FC, EA, 2D, D8, 83, AD, 68, B5, 48, 4F, 8D, 0E, 86, 61, BB, 81, 9C, 67, 8D, A5, 69, 56, 9F, 42, 5F...
 
[+]

Entropy:
7.9528  (probably packed)

Code size:
96 KB (98,304 bytes)

The file keygen.exe has been seen being distributed by the following 5 URLs.

about:internet

temp:Keygen.exe

https://mega.nz/temporary/.../FA4wVQiL

Remove keygen.exe - Powered by Reason Core Security