ramvbokue.exe

Beijing Kate Zhanhong Technology Co.,Ltd.

The executable ramvbokue.exe has been detected as malware by 4 anti-virus scanners.
Publisher:

Version:
1, 0, 0, 1

MD5:
eb032ed96210a2c5e692c82472fe61ec

SHA-1:
66dbba4df4ee42d986d82936f481f2e125933217

SHA-256:
a402d4ecf333736f65c34589ba2285c7ba43d384a9311f92ced9b861b8a27989

Scanner detections:
4 / 68

Status:
Malware

Analysis date:
4/24/2024 2:15:00 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-161001

F-Prot
W32/SelfStarterInternetTrojan!M
v6.4.7.1.166

NANO AntiVirus
Trojan.Win32.SelfStarterInternetTrojan.dzhpgy
1.0.14.5380

Qihoo 360 Security
Trojan.Generic
1.0.0.1077

File size:
102.6 KB (105,080 bytes)

Product version:
1, 0, 0, 1

Copyright:
版权 (C) 2015

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\appdata\roaming\miokxekco\ramvbokue.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/28/2013 8:00:00 AM

Valid to:
11/29/2014 7:59:59 AM

Subject:
CN="Beijing Kate Zhanhong Technology Co.,Ltd.", O="Beijing Kate Zhanhong Technology Co.,Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3C5883BD1DBCD582AD41C8778E4F56D9

File PE Metadata
Compilation timestamp:
12/18/2015 2:35:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:fkA4wkcbc2BUhBgvm3u5CaTBfpC3PM+4T32tDnX:fkz7cbQ+YaTBAk+4T32tD

Entry address:
0x31D2

Entry point:
55, 8B, EC, 6A, FF, 68, F0, C8, 40, 00, 68, 5E, 33, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 18, C3, 40, 00, 59, 83, 0D, 68, 28, 41, 00, FF, 83, 0D, 6C, 28, 41, 00, FF, FF, 15, 1C, C3, 40, 00, 8B, 0D, 3C, 28, 41, 00, 89, 08, FF, 15, 20, C3, 40, 00, 8B, 0D, 38, 28, 41, 00, 89, 08, A1, 24, C3, 40, 00, 8B, 00, A3, 64, 28, 41, 00, E8, 1C, 01, 00, 00, 39, 1D, C8, 22, 41, 00, 75, 0C, 68, 5A, 33, 40, 00, FF, 15, 28, C3...
 
[+]

Entropy:
6.2470

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
44 KB (45,056 bytes)

Remove ramvbokue.exe - Powered by Reason Core Security