keygen.exe

The application keygen.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from doc-0g-cc-docs.googleusercontent.com and multiple other hosts.
MD5:
19514e0615731fddc85fb79e08ab216a

SHA-1:
b43bd473e2bacde1251a024582061c02d29dfd7c

SHA-256:
52f1fe9c82c4fdd8bc0f4c349fed13b7e27eeadf06bfeda1cd33f3e4a6a2d1fe

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 3:31:49 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Keygen
7.1.1

Bkav FE
W32.Clodbbc.Trojan
1.3.0.4923

ESET NOD32
Win32/Keygen.AI (variant)
8.9326

F-Prot
W32/MalwareF.HUKG
v6.4.7.1.166

IKARUS anti.virus
not-a-virus.Keygen.WinRAR
t3scan.2.2.29

K7 AntiVirus
Riskware
13.175.10926

Malwarebytes
Trojan.Agent.CK
v2014.01.25.08

McAfee
Generic.bfr!dp
5600.7240

Norman
Hacktool.A!genr
11.20140125

nProtect
Backdoor/W32.Hupigon.202240.E
14.01.22.03

Reason Heuristics
Unnamed.Threat.46
14.2.24.5

Rising Antivirus
PE:Trojan.Win32.Generic.129AF192!312144274
23.00.65.14123

Sophos
Mal/KeyGen-M
4.97

Total Defense
Win32/Tnega.AGUP
37.0.10498

VIPRE Antivirus
Trojan.Win32.Generic
25698

ViRobot
Backdoor.Win32.Hupigon.202240.C
2011.4.7.4223

File size:
197.5 KB (202,240 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\winrar\keygen.exe

File PE Metadata
Compilation timestamp:
8/20/2009 4:02:49 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:UD1YoBTG2m5uKyGQaDonABtK2bLjw8zh:UDKo5m5d3DcABtBjwuh

Entry address:
0x94F2

Entry point:
B8, E4, B8, 45, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, FD, E7, AD, 51, 20, 3E, AA, 10, 58, F2, 76, CF, 81, 3F, F5, 42, 99, 12, 61, 62, 55, 9A, 4F, F6, 34, D0, EA, 0A, 8A, AC, 8D, 75, E2, EE, C9, D9, 0C, D1, 2A, 7D, 3A, 48, 28, 90, 88, DB, 5C, 95, 04, 5C, C9, 25, 1D, 4F, CB, 8D, E0, 92, 66, E9, 6B, 28, 69, DA, 68, EA, 7C, 7D, 6A, 1E, 96, 5D, 2F, C4, 14, 89, A7, 4D, B7, 9E, BF, A2, A2, AA, A6, 42, 49, F1, 53, CB, A1, B2, FB...
 
[+]

Entropy:
7.9845

Packer / compiler:
PECompact v2

Code size:
93.5 KB (95,744 bytes)

The file keygen.exe has been seen being distributed by the following 4 URLs.

Remove keygen.exe - Powered by Reason Core Security