prhack.exe

WindowsApplication1

The application prhack.exe has been detected as a potentially unwanted program by 23 anti-malware scanners. The file has been seen being downloaded from download2156.mediafire.com.
Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
d177be195f0d2b3af1243859ec9c8ad1

SHA-1:
d2512531b9867193c76578e6e84de0b5e5bf111d

SHA-256:
01e94f80c7b0850817b231a2c226a4676e113161494935f092d2b7d5f7cff646

Scanner detections:
23 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 7:45:24 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.450872
403

Baidu Antivirus
Backdoor.Win32.DarkKomet
4.0.3.151228

Bitdefender
Gen:Variant.Kazy.450872
1.0.20.1810

Comodo Security
UnclassifiedMalware
21749

Emsisoft Anti-Malware
Gen:Variant.Kazy.450872
8.15.12.28.04

ESET NOD32
MSIL/Hoax.FakeHack.JY
9.11465

Fortinet FortiGate
W32/DarkKomet.DNKO!tr.bdr
12/28/2015

F-Secure
Gen:Variant.Kazy.450872
11.2015-28-12_2

G Data
Gen:Variant.Kazy.450872
15.12.25

IKARUS anti.virus
Virus.ILCrypt
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.202.15572

Kaspersky
Backdoor.Win32.DarkKomet
14.0.0.902

McAfee
RDN/Generic BackDoor!bc3
5600.6537

MicroWorld eScan
Gen:Variant.Kazy.450872
16.0.0.1086

NANO AntiVirus
Trojan.Win32.Bladabindi.dkmxyh
0.30.10.952

Panda Antivirus
Trj/CI.A
15.12.28.04

Qihoo 360 Security
Win32/Backdoor.7af
1.0.0.1015

Quick Heal
Backdoor.DarkKomet.r4
12.15.14.00

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R00UC0EJF14
7.2.362

Trend Micro
TROJ_GEN.R00UC0EJF14
10.465.28

VIPRE Antivirus
MSIL.Hoax.FakeHack (not malicious)
39300

Zillya! Antivirus
Backdoor.DarkKomet.Win32.23488
2.0.0.2136

File size:
86.5 KB (88,576 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
PRHack.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\prhack.exe

File PE Metadata
Compilation timestamp:
8/6/2014 2:51:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:XIYoqlNYOwpEBeu8KpcZX/k3DAvfXJIE:XhoQxwpEBppcZPk30vh1

Entry address:
0x1650E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.9490

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
81.5 KB (83,456 bytes)

The file prhack.exe has been seen being distributed by the following URL.

Remove prhack.exe - Powered by Reason Core Security