netstream.exe

The executable netstream.exe has been detected as malware by 25 anti-virus scanners.
Description:
BugReport

Version:
1, 5, 0, 1022

MD5:
07fd03a185d7648e8579db9930dbdd4d

SHA-1:
6031eeac3c49680886871cc54a1aaea102d34c13

SHA-256:
d90cb176a078ac16c66e945ad08a9ae34f4f8064033cb20ddda504a548e060d1

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
4/20/2024 1:53:16 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Agent.CEOQ
-40

AhnLab V3 Security
Malware/Win32.Generic.C1842790
3.8.3.16

Avira AntiVirus
TR/Crypt.ZPACK.ketvh
8.3.3.4

Arcabit
Trojan.Agent.CEOQ
1.0.0.798

avast!
Win32:Rootkit-gen [Rtk]
2014.9-170316

AVG
Proxy
2018.0.2438

Baidu Antivirus
Win32.Trojan.Kryptik
4.0.3.17316

Bitdefender
Trojan.Agent.CEOQ
1.0.20.375

Comodo Security
TrojWare.Win32.Ransom.Cerber.BF
26729

Emsisoft Anti-Malware
Trojan.Agent.CEOQ
8.17.03.16.04

ESET NOD32
Win32/TrojanProxy.Agent.OAE
11.15063

Fortinet FortiGate
W32/Agent.OAE!tr
3/16/2017

F-Prot
W32/Cerber.AJ.gen
v6.4.7.1.166

F-Secure
Trojan.Agent.CEOQ
11.2017-16-03_5

G Data
Trojan.Agent.CEOQ
17.3.A:25.11099B:25.9046

Kaspersky
Trojan.Win32.Yakes
14.0.0.-1316

McAfee
Artemis!07FD03A185D7
5600.6094

Microsoft Security Essentials
TrojanProxy:Win32/Bunitu.Q!bit
1.1.13504.0

MicroWorld eScan
Trojan.Agent.CEOQ
18.0.0.225

Panda Antivirus
Trj/GdSda.A
17.03.16.04

Qihoo 360 Security
HEUR/QVM20.1.AA9A.Malware.Gen
1.0.0.1120

Reason Heuristics
Trojan.Proxy.ET (M)
17.3.16.4

Rising Antivirus
Trojan.Kryptik!1.A877 (cloud:9lBx11d2FmL)
23.00.65.17314

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic
56532

File size:
633.5 KB (648,704 bytes)

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\netstream.exe

File PE Metadata
Compilation timestamp:
3/8/2017 10:06:46 AM

OS version:
3.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x5ECF0

Entry point:
55, 8B, EC, 83, EC, 0C, E8, 95, FF, FF, FF, A1, D4, 60, 49, 00, 50, FF, 15, 10, 03, 46, 00, 8B, 0D, D4, 60, 49, 00, 51, FF, 15, 0C, 03, 46, 00, 8B, 15, D4, 60, 49, 00, 52, FF, 15, 10, 04, 46, 00, FF, 15, 08, 03, 46, 00, 68, 5C, 60, 49, 00, FF, 15, 04, 03, 46, 00, FF, 15, 00, 03, 46, 00, A1, D4, 60, 49, 00, 50, FF, 15, FC, 02, 46, 00, FF, 15, F8, 02, 46, 00, 8B, 0D, D4, 60, 49, 00, 51, FF, 15, F4, 02, 46, 00, 8B, 15, D4, 60, 49, 00, 52, FF, 15, F0, 02, 46, 00, A1, D4, 60, 49, 00, 50, FF, 15, C8, 03, 46, 00...
 
[+]

Entropy:
4.4006

Developed / compiled with:
Microsoft Visual C++

Code size:
377 KB (386,048 bytes)

Remove netstream.exe - Powered by Reason Core Security