res_0711.exe

The executable res_0711.exe has been detected as malware by 27 anti-virus scanners.
MD5:
6a54e16283c23ba1b4c159c1e34f4624

SHA-1:
c4ff3e1b26e92cc20006c4d271f80a63d3b6ae77

SHA-256:
ccd0d1d99c98466206352f1fae17beded1d0245a61d4fa598275123f993b063e

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
12/21/2025 6:26:04 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.149309
698

Agnitum Outpost
Trojan.Farfli
7.1.1

Avira AntiVirus
TR/Rogue.11567569
7.11.211.234

avast!
Win32:Malware-gen
2014.9-150309

AVG
BackDoor.Generic_r
2016.0.3176

Baidu Antivirus
Trojan.Win32.Farfli
4.0.3.1539

Bitdefender
Gen:Variant.Graftor.149309
1.0.20.340

Comodo Security
UnclassifiedMalware
21158

Emsisoft Anti-Malware
Gen:Variant.Graftor.149309
8.15.03.09.04

ESET NOD32
Win32/Farfli.AYO
9.11211

Fortinet FortiGate
JS/Agent.NMK!tr
7/19/2014

F-Secure
Gen:Variant.Graftor.149309
11.2015-09-03_2

G Data
Gen:Variant.Graftor.149309
15.3.25

IKARUS anti.virus
Trojan-Proxy.Win32.Bedri
t3scan.1.8.6.0

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.2374

McAfee
Artemis!6A54E16283C2
5600.6832

Microsoft Security Essentials
TrojanProxy:Win32/Bedri.F
1.1.11400.0

MicroWorld eScan
Gen:Variant.Graftor.149309
16.0.0.204

NANO AntiVirus
Trojan.Win32.Rogue.deuems
0.30.0.296

Norman
Suspicious_Gen2.VXUPP
11.20150309

Panda Antivirus
Trj/CI.A
15.03.09.04

Qihoo 360 Security
Win32/Trojan.Multi.daf
1.0.0.1015

Rising Antivirus
PE:Backdoor.Farfli!1.6531
23.00.65.14717

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GE.5D9342E6
7.2.68

Trend Micro
TROJ_GE.5D9342E6
10.465.09

VIPRE Antivirus
Trojan.Win32.Generic
37754

File size:
173.6 KB (177,727 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\res_0711\res_0711.exe

File PE Metadata
Compilation timestamp:
6/9/2012 6:19:49 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:Bz+92mhTMMJ/cPiq5bVin8/etO+dhjOl9OOH84Q3QGLGrNm:Bz+92mhAMJ/cPl3i8/wOh84O9

Entry address:
0xAC87

Entry point:
E8, E3, FE, FF, FF, 33, C0, 50, 50, 50, 50, E8, 9F, 30, 00, 00, C3, 56, 57, 8B, 7C, 24, 0C, 8B, F1, 8B, CF, 89, 3E, E8, 8F, AB, FF, FF, 89, 46, 08, 89, 56, 0C, 8B, 87, 24, 0C, 00, 00, 89, 46, 10, 5F, 8B, C6, 5E, C2, 04, 00, 8B, C1, 8B, 08, 8B, 50, 10, 3B, 91, 24, 0C, 00, 00, 75, 0D, 6A, 00, FF, 70, 0C, FF, 70, 08, E8, 0E, B1, FF, FF, C3, 56, 8B, F1, 8B, 06, 85, C0, 74, 07, 50, FF, 15, C4, 40, 41, 00, 83, 26, 00, 83, 66, 08, 00, 83, 66, 0C, 00, 5E, C3, 56, 8B, F1, 80, 7E, 04, 00, 75, 34, 68, F4, 44, 41, 00...
 
[+]

Entropy:
7.3214

Code size:
73 KB (74,752 bytes)

Remove res_0711.exe - Powered by Reason Core Security