khobbit-_nezhdannd_h4__15387817_291.exe

Monkeke Inc.

The application khobbit-_nezhdannd_h4__15387817_291.exe by Monkeke has been detected as a potentially unwanted program by 23 anti-malware scanners.
Publisher:
Monkeke Inc.  (signed and verified)

MD5:
23ec53911fb10fb76fb8de51777d7df9

SHA-1:
37ebc55af79569a535c462c326a542eb75f62789

SHA-256:
660502c79f4102f21661a2c31a9e7818303f31c8498a8c5d9739ca9dfae78298

Scanner detections:
23 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 12:23:16 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Rogue.8855432
8.3.2.2

Arcabit
Adware.Agent.NRB
1.0.0.593

avast!
Win32:PUP-gen [PUP]
2014.9-160305

AVG
AdLoad
2017.0.2813

Baidu Antivirus
Adware.Win32.Webalta
4.0.3.1635

Bitdefender
Adware.Agent.NRB
1.0.20.325

Comodo Security
Application.Win32.Agent.WEFB
23570

Dr.Web
BackDoor.Evit.26
9.0.1.065

Emsisoft Anti-Malware
Adware.Agent.NRB
8.16.03.05.01

ESET NOD32
Win32/Adware.Toolbar.Webalta.BS (variant)
10.12549

Fortinet FortiGate
Riskware/Toolbar_Webalta
3/5/2016

F-Secure
Adware.Agent.NRB
11.2016-05-03_7

G Data
Adware.Agent.NRB
16.3.25

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.9.5.0

Kaspersky
not-a-virus:HEUR:Downloader.Win32.Walta
14.0.0.562

McAfee
PUP-FIT
5600.6469

MicroWorld eScan
Adware.Agent.NRB
17.0.0.195

NANO AntiVirus
Trojan.Win32.Walta.csnuih
0.30.26.4437

nProtect
Adware.Agent.NRB
15.11.11.01

Qihoo 360 Security
Win32/Virus.Downloader.bcc
1.0.0.1077

Sophos
Generic PUA DH (PUA)
4.98

Vba32 AntiVirus
Downware.iDatix.gen
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
45156

File size:
1.5 MB (1,540,400 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\khobbit-_nezhdannd_h4__15387817_291.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
2/1/2012 8:51:32 PM

Valid to:
2/1/2013 8:51:32 PM

Subject:
CN=Monkeke Inc., O=Monkeke Inc., L=Flemington, S=MO, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0453F0B8F59ABD

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:0ikxKT6BKn37z/GAGEVgauotsEj+gB06ce+G1xg6/2kGR7Gy:TOA3A9gBme+YG6+kdy

Entry address:
0x94D44

Entry point:
55, 8B, EC, 83, C4, F0, B8, 6C, 4A, 49, 00, E8, 00, 1B, F7, FF, A1, 1C, 6D, 49, 00, 8B, 00, E8, 90, 63, FC, FF, 8B, 0D, 54, 6E, 49, 00, A1, 1C, 6D, 49, 00, 8B, 00, 8B, 15, 74, 38, 47, 00, E8, 90, 63, FC, FF, 8B, 0D, 90, 6E, 49, 00, A1, 1C, 6D, 49, 00, 8B, 00, 8B, 15, 1C, 36, 47, 00, E8, 78, 63, FC, FF, 8B, 0D, D0, 6C, 49, 00, A1, 1C, 6D, 49, 00, 8B, 00, 8B, 15, 6C, 48, 49, 00, E8, 60, 63, FC, FF, A1, 1C, 6D, 49, 00, 8B, 00, E8, D4, 63, FC, FF, E8, 27, F5, F6, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
591.5 KB (605,696 bytes)

Remove khobbit-_nezhdannd_h4__15387817_291.exe - Powered by Reason Core Security