patch-x64.exe

The application patch-x64.exe has been detected as a potentially unwanted program by 30 anti-malware scanners. The file has been seen being downloaded from cloudbox.ku.ac.th.
MD5:
de53396766c5147250292f37439b6f21

SHA-1:
84e8c03bff5659b47f0dbeb9b646b96d0dbf1963

SHA-256:
ca6883d485b73dd4acf6dd49d216c341530f7efcf10b1eb7a598c7ae5cac4ae1

Scanner detections:
30 / 68

Status:
Potentially unwanted

Analysis date:
5/16/2024 4:58:05 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.6040687
717

Agnitum Outpost
Trojan.PWS.LdPinch
7.1.1

AhnLab V3 Security
Trojan/Win32.LdPinch
2015.02.11

AVG
PSW.Ldpinch
2016.0.3195

Baidu Antivirus
Hacktool.Win32.Patcher
4.0.3.15217

Bitdefender
Trojan.Generic.6040687
1.0.20.240

Comodo Security
UnclassifiedMalware
21032

Dr.Web
Tool.Patcher.110
9.0.1.048

Emsisoft Anti-Malware
Trojan.Generic.6040687
8.15.02.17.12

ESET NOD32
Win32/HackTool.Patcher.AA potentially unsafe (variant)
9.11155

F-Secure
Trojan.Generic.6040687
11.2015-17-02_3

G Data
Trojan.Generic.6040687
15.2.25

IKARUS anti.virus
Trojan-PSW.Ldpinch
t3scan.1.8.6.0

K7 AntiVirus
Hacktool
13.194.14927

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.2472

McAfee
RDN/PWS-LDPinch!p
5600.6851

MicroWorld eScan
Trojan.Generic.6040687
16.0.0.144

NANO AntiVirus
Riskware.Win32.Patcher.ctlndb
0.30.0.65070

Norman
Troj_Generic.XLJUA
11.20150217

nProtect
Trojan.Generic.6040687
15.02.10.01

Panda Antivirus
Trj/CI.A
15.02.17.12

Qihoo 360 Security
HEUR/QVM11.1.Malware.Gen
1.0.0.1015

Quick Heal
(Suspicious) - DNAScan
2.15.14.00

Sophos
Generic Patcher
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-LdPinch
10048

Trend Micro House Call
TROJ_LDPINCH_DD3005BA.UVPA
7.2.48

Trend Micro
TROJ_LDPINCH_DD3005BA.UVPA
10.465.17

Vba32 AntiVirus
TrojanPSW.Pinch
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
37426

Zillya! Antivirus
Trojan.LdPinch.Win32.16080
2.0.0.2061

File size:
16.1 KB (16,468 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
12/15/2010 7:22:54 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
192:dcTjplHq5vpIlGhdX4H5l2Q6B9blvhdtwDkOpt58Tbo/lxf:d6pKIlGhd+b29blvXWDkORMbo/bf

Entry address:
0xC850

Entry point:
60, BE, 00, B0, 40, 00, 8D, BE, 00, 60, FF, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB...
 
[+]

Entropy:
6.3656

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
8 KB (8,192 bytes)

The file patch-x64.exe has been seen being distributed by the following URL.

Remove patch-x64.exe - Powered by Reason Core Security