netstream.exe

The executable netstream.exe has been detected as malware by 29 anti-virus scanners.
Description:
BugReport

Version:
1, 5, 0, 1022

MD5:
66b0778df4ed182ea86a19ebe15fec81

SHA-1:
c8c21a59c480207ab296e30132552f8c7ed0890f

SHA-256:
708b9c96a06e91d5755ecbd9121387e0f03e18458a6a2dbd720962f6d27d85ae

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
4/20/2024 2:42:09 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Agent.CEOQ
-40

AhnLab V3 Security
Malware/Win32.Generic.C1842790
3.8.3.16

Avira AntiVirus
TR/Crypt.ZPACK.ketvh
8.3.3.4

Arcabit
Trojan.Agent.CEOQ
1.0.0.798

avast!
Win32:Rootkit-gen [Rtk]
2014.9-170316

AVG
Proxy
2018.0.2438

Baidu Antivirus
Win32.Trojan.Kryptik
4.0.3.17316

Bitdefender
Trojan.Agent.CEOQ
1.0.20.375

Bkav FE
W32.eHeur.Malware12
1.3.0.8876

Comodo Security
TrojWare.Win32.Ransom.Cerber.BF
26739

Emsisoft Anti-Malware
Trojan.Agent.CEOQ
8.17.03.16.04

ESET NOD32
Win32/TrojanProxy.Agent.OAE
11.15072

Fortinet FortiGate
W32/Agent.CEOQ!tr
3/16/2017

F-Prot
W32/Cerber.AJ.gen
v6.4.7.1.166

F-Secure
Trojan.Agent.CEOQ
11.2017-16-03_5

G Data
Trojan.Agent.CEOQ
17.3.A:25.11137B:25.9061

IKARUS anti.virus
Trojan-Proxy.Agent
0.2.1.2

Kaspersky
Trojan.Win32.Yakes
14.0.0.-1316

McAfee
GenericRXBB-SZ!66B0778DF4ED
5600.6094

Microsoft Security Essentials
TrojanProxy:Win32/Bunitu.Q!bit
1.1.13504.0

MicroWorld eScan
Trojan.Agent.CEOQ
18.0.0.225

NANO AntiVirus
Trojan.Win32.Yakes.emgplj
1.0.70.15657

Panda Antivirus
Trj/GdSda.A
17.03.16.04

Qihoo 360 Security
HEUR/QVM20.1.0000.Malware.Gen
1.0.0.1120

Reason Heuristics
Trojan.Proxy.ET (M)
17.3.16.4

Rising Antivirus
Trojan.Kryptik!1.A877 (cloud:Wa7uZ3d2FmL)
23.00.65.17314

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R021C0DCA17
10.465.16

VIPRE Antivirus
Trojan.Win32.Generic
56574

File size:
633.5 KB (648,704 bytes)

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\netstream.exe

File PE Metadata
Compilation timestamp:
3/8/2017 1:34:25 PM

OS version:
3.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x5ECF0

Entry point:
55, 8B, EC, 83, EC, 0C, E8, 95, FF, FF, FF, A1, D4, 60, 49, 00, 50, FF, 15, 10, 03, 46, 00, 8B, 0D, D4, 60, 49, 00, 51, FF, 15, 0C, 03, 46, 00, 8B, 15, D4, 60, 49, 00, 52, FF, 15, 10, 04, 46, 00, FF, 15, 08, 03, 46, 00, 68, 5C, 60, 49, 00, FF, 15, 04, 03, 46, 00, FF, 15, 00, 03, 46, 00, A1, D4, 60, 49, 00, 50, FF, 15, FC, 02, 46, 00, FF, 15, F8, 02, 46, 00, 8B, 0D, D4, 60, 49, 00, 51, FF, 15, F4, 02, 46, 00, 8B, 15, D4, 60, 49, 00, 52, FF, 15, F0, 02, 46, 00, A1, D4, 60, 49, 00, 50, FF, 15, C8, 03, 46, 00...
 
[+]

Entropy:
4.4006

Developed / compiled with:
Microsoft Visual C++

Code size:
377 KB (386,048 bytes)

Remove netstream.exe - Powered by Reason Core Security