login.exe

WindowsApplication2

The executable login.exe has been detected as malware by 28 anti-virus scanners.
Product:
WindowsApplication2

Version:
1.0.0.0

MD5:
a0f962a22e5307f64dfa3a08d70f39d2

SHA-1:
5be92c7e2e30d0ee3a6e60be4d73f31c36d0f24c

SHA-256:
3175572176a1794fdc53be1b789f3a58c7f4342f370f144e0c91738cacc4a998

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/19/2024 5:37:12 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.264589
680

Agnitum Outpost
Trojan.DR.Agent
7.1.1

AhnLab V3 Security
Trojan/Win32.agent
2015.03.24

Avira AntiVirus
TR/Dropper.Gen
3.6.1.96

avast!
MSIL:GenMalicious-YZ [Trj]
2014.9-150327

AVG
MSIL
2016.0.3158

Baidu Antivirus
Trojan.MSIL.Agent
4.0.3.15327

Bitdefender
Gen:Variant.Kazy.264589
1.0.20.430

Clam AntiVirus
Win.Trojan.Agent-799309
0.98/21511

Emsisoft Anti-Malware
Gen:Variant.Kazy.264589
8.15.03.27.06

ESET NOD32
MSIL/TrojanDropper.Agent.AHC (variant)
9.11364

Fortinet FortiGate
MSIL/Dropper.POO!tr
3/27/2015

F-Secure
Gen:Variant.Kazy.264589
11.2015-27-03_6

G Data
Gen:Variant.Kazy.264589
15.3.25

IKARUS anti.virus
Trojan-Dropper.MSIL.Agent
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.202.15354

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.2284

McAfee
RDN/Generic Dropper!vx
5600.6814

MicroWorld eScan
Gen:Variant.Kazy.264589
16.0.0.258

NANO AntiVirus
Trojan.Win32.Jorik.dkmpej
0.30.8.659

Norman
Agent.ATTAS
11.20150327

Panda Antivirus
Trj/CI.A
15.03.27.06

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Quick Heal
Trojan.Generic.r4
3.15.14.00

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R047C0EAD15
7.2.86

Trend Micro
TROJ_GEN.R047C0EAD15
10.465.27

VIPRE Antivirus
Trojan.Win32.Generic
38698

File size:
948.1 KB (970,868 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2013

Original file name:
WindowsApplication2.exe

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

Common path:
C:\users\{user}\downloads\ratpro\ratpro\login.exe

File PE Metadata
Compilation timestamp:
11/20/2013 2:19:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:ZYP6FO7mTqnJzaC2h0UVv/Xy1NwlABgyda2hgR+XymGoHvXEpExTQ8EtY+o8W/jt:ZYyF+uKJz1K0kQc2ymlX9oWKM/

Entry address:
0x5F0E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16 KB (16,384 bytes)

Remove login.exe - Powered by Reason Core Security