keygen.exe

The application keygen.exe has been detected as a potentially unwanted program by 33 anti-malware scanners. This is a setup program which is used to install the application.
MD5:
63817fe8815e21e34dacb443ffe1842c

SHA-1:
736901598e7595ad634dd099062ffe9e7a03351b

SHA-256:
4648bf797d68c4474b5bfe672bfffa5acb8bca068fa60963f477b090eaa63b49

Scanner detections:
33 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 10:32:27 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.8174560
924

AegisLab AV Signature
Troj.Crypt.XDR.Gen
2.1.4+

Agnitum Outpost
PUP.Agent
7.1.1

Avira AntiVirus
TR/Crypt.XDR.Gen
7.11.156.190

avast!
Win32:Malware-gen
2014.9-140725

AVG
Crack
2015.0.3402

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.14725

Bitdefender
Trojan.Generic.8174560
1.0.20.1030

Bkav FE
W32.Clod157.Trojan
1.3.0.4959

Comodo Security
UnclassifiedMalware
18662

Dr.Web
Trojan.Click2.47759
9.0.1.0206

Emsisoft Anti-Malware
Trojan.Generic.8174560
8.14.07.25.01

ESET NOD32
Win32/Keygen.AC (variant)
8.9997

Fortinet FortiGate
W32/Keygen.DS!tr
7/25/2014

F-Secure
Trojan.Generic.8174560
11.2014-25-07_6

G Data
Trojan.Generic.8174560
14.7.24

IKARUS anti.virus
Keygen
t3scan.1.6.1.0

K7 AntiVirus
Riskware
13.180.12512

McAfee
Artemis!63817FE8815E
5600.7058

MicroWorld eScan
Trojan.Generic.8174560
15.0.0.618

NANO AntiVirus
Trojan.Win32.XDR.bcjvbc
0.28.0.60475

Norman
Suspicious_Gen4.BOIRB
11.20140725

nProtect
Trojan.Generic.8174560
14.06.25.01

Panda Antivirus
Trj/CI.A
14.07.25.01

Qihoo 360 Security
Win32/Trojan.27f
1.0.0.1015

Rising Antivirus
PE:Trojan.Win32.Generic.1385FC17!327547927
23.00.65.14723

Sophos
Troj/Keygen-DS
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-StartPage
10462

Trend Micro House Call
TROJ_SPNR.08EE14
7.2.206

Trend Micro
TROJ_SPNR.08EE14
10.465.25

Vba32 AntiVirus
Trojan.Genome.ai
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
30636

Zillya! Antivirus
Trojan.Genome.Win32.205813
2.0.0.1837

File size:
69.5 KB (71,168 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
1536:U4k2S6pXt4eVZUEAa0y9BNNQ46fpUDU2zORU8p:UVomjY0yNfAyy

Entry address:
0x1000

Entry point:
B8, 44, DC, 43, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 0F, E8, DF, 1E, 79, 72, 28, 50, 47, B8, 39, 4B, 77, A3, BD, 5D, 03, D3, 18, 8C, DC, 99, 98, 12, 25, 0C, D2, DD, 9B, 87, F3, 69, D0, CE, 32, DC, A5, 40, 17, 97, E9, B2, FF, 27, 0B, 8C, B4, C7, 43, DA, 2F, 25, A3, B1, 1E, 6D, 9E, 46, CB, 11, 7E, 53, 03, F1, 4E, AC, D2, 07, 4E, EB, 6A, E8, AB, B8, 08, 83, 52, 76, A5, 5D, B6, B2, DA, 8C, D5, BC, BB, CC, 1C, 65, 91, 9D, 2C...
 
[+]

Entropy:
7.8631

Packer / compiler:
PECompact v2

Code size:
62.5 KB (64,000 bytes)

The file keygen.exe has been seen being distributed by the following URL.

temp:keygen.exe

Remove keygen.exe - Powered by Reason Core Security