skachka_knig_15470761_440.exe

Monkeke Inc.

The application skachka_knig_15470761_440.exe by Monkeke has been detected as a potentially unwanted program by 25 anti-malware scanners.
Publisher:
Monkeke Inc.  (signed and verified)

MD5:
485d1216883376d2533e56daee00a0ea

SHA-1:
defbcea37bea0ee77897bcc0d5f81488960b4f79

SHA-256:
0f2d7dc84af42e7d5a285f242fb2f93c9fda123549c26fcae21ed925f50691e4

Scanner detections:
25 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 12:40:40 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.8874763
433

AhnLab V3 Security
Win-AppCare/Walta.K.1546032
2015.03.24

Avira AntiVirus
TR/Rogue.8874763
3.6.1.96

avast!
Win32:PUP-gen [PUP]
2014.9-151129

AVG
AdLoad
2016.0.2911

Baidu Antivirus
Adware.Win32.Webalta
4.0.3.151129

Bitdefender
Trojan.Generic.8874763
1.0.20.1665

Comodo Security
Application.Win32.AgentCV.IAS
21512

Dr.Web
Adware.Downware.881
9.0.1.0333

Emsisoft Anti-Malware
Trojan.Generic.8874763
8.15.11.29.09

ESET NOD32
Win32/Adware.Toolbar.Webalta.AV (variant)
9.11365

F-Secure
Trojan.Generic.8874763
11.2015-29-11_1

G Data
Trojan.Generic.8874763
15.11.25

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.6.0

Kaspersky
not-a-virus:HEUR:Downloader.Win32.Walta
14.0.0.1048

McAfee
PUP-FIT
5600.6567

MicroWorld eScan
Trojan.Generic.8874763
16.0.0.999

NANO AntiVirus
Trojan.Win32.Walta.cudrfl
0.30.8.659

nProtect
Trojan.Generic.8874763
15.03.23.01

Sophos
Generic PUA NO
4.98

Trend Micro House Call
TROJ_GEN.R08NC0EK414
7.2.333

Trend Micro
TROJ_GEN.R08NC0EK414
10.465.29

Vba32 AntiVirus
Downware.iDatix.gen
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
38702

Zillya! Antivirus
Adware.Toolbar.Win32.104
2.0.0.2112

File size:
1.5 MB (1,546,032 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\skachka_knig_15470761_440.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
2/1/2012 7:51:32 PM

Valid to:
2/1/2013 7:51:32 PM

Subject:
CN=Monkeke Inc., O=Monkeke Inc., L=Flemington, S=MO, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0453F0B8F59ABD

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:J7dYjfwon2xHhoccTQ3tSjah0wtQ3Ej+gB06ce+G1xg6/2kGR7QN:JxYdn9cyQ9TtQhgBme+YG6+kPN

Entry address:
0x95484

Entry point:
55, 8B, EC, 83, C4, F0, B8, 94, 51, 49, 00, E8, 70, 11, F7, FF, A1, C8, 7F, 49, 00, 8B, 00, E8, 24, 95, FC, FF, 8B, 0D, 0C, 81, 49, 00, A1, C8, 7F, 49, 00, 8B, 00, 8B, 15, 88, 7B, 47, 00, E8, 24, 95, FC, FF, 8B, 0D, 50, 81, 49, 00, A1, C8, 7F, 49, 00, 8B, 00, 8B, 15, 2C, 79, 47, 00, E8, 0C, 95, FC, FF, 8B, 0D, 68, 7F, 49, 00, A1, C8, 7F, 49, 00, 8B, 00, 8B, 15, 90, 4F, 49, 00, E8, F4, 94, FC, FF, A1, C8, 7F, 49, 00, 8B, 00, E8, 68, 95, FC, FF, E8, 43, ED, F6, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
593.5 KB (607,744 bytes)

Remove skachka_knig_15470761_440.exe - Powered by Reason Core Security