prology latitude i-601_14714601_218.exe

Monkeke Inc.

The application prology latitude i-601_14714601_218.exe by Monkeke has been detected as a potentially unwanted program by 5 anti-malware scanners.
Publisher:
Monkeke Inc.  (signed and verified)

MD5:
e822980319976f866647c58cfbabb88a

SHA-1:
bce1ac9a5bc86fbba4d36aeef75a4c2be53324ef

SHA-256:
1b567fb7cf112d7b8f1990075e73aae7a31ee876a37892ab11a3020796ccf9dc

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 12:16:43 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
BackDoor.Evit.20
9.0.1.0140

ESET NOD32
Win32/Adware.Toolbar.Webalta.BI
8.7910

Fortinet FortiGate
Riskware/Toolbar_Webalta
5/20/2014

Kaspersky
not-a-virus:HEUR:Downloader.Win32.Walta
14.0.0.3837

Trend Micro House Call
TROJ_GEN.F47V0114
7.2.140

File size:
1.4 MB (1,519,408 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
2/1/2012 9:51:32 PM

Valid to:
2/1/2013 9:51:32 PM

Subject:
CN=Monkeke Inc., O=Monkeke Inc., L=Flemington, S=MO, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0453F0B8F59ABD

File PE Metadata
Compilation timestamp:
6/20/1992 2:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:UW+jmHtmO2Ic/+wU/3s8XqaGk1sWGxPBGq/uEbDtsTPza7GuAIuvVnP5L0DypztQ:UmcNE1kldPGqmE/tsTba7GMuvvowyQq9

Entry address:
0x90418

Entry point:
55, 8B, EC, 83, C4, F0, B8, 40, 01, 49, 00, E8, F8, 63, F7, FF, A1, A0, 2C, 49, 00, 8B, 00, E8, 40, 94, FC, FF, 8B, 0D, D0, 2D, 49, 00, A1, A0, 2C, 49, 00, 8B, 00, 8B, 15, 0C, EF, 46, 00, E8, 40, 94, FC, FF, 8B, 0D, 0C, 2E, 49, 00, A1, A0, 2C, 49, 00, 8B, 00, 8B, 15, B4, EC, 46, 00, E8, 28, 94, FC, FF, 8B, 0D, 54, 2C, 49, 00, A1, A0, 2C, 49, 00, 8B, 00, 8B, 15, 60, FF, 48, 00, E8, 10, 94, FC, FF, A1, A0, 2C, 49, 00, 8B, 00, E8, 84, 94, FC, FF, E8, 53, 3E, F7, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
573.5 KB (587,264 bytes)

Remove prology latitude i-601_14714601_218.exe - Powered by Reason Core Security