thc stealer builder.exe

THC Stealer

The executable thc stealer builder.exe has been detected as malware by 31 anti-virus scanners.
Product:
THC Stealer

Version:
1.0.0.0

MD5:
3752b5f2f2e407f1adf627256f30bf94

SHA-1:
0f32ec8c1ab0c0e26eef916b732a2cea36e72dd3

SHA-256:
98b558e94e3eeb8329288b14034c9f270d47253e378b68ae72bf2ed76a3ef415

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
4/25/2024 5:53:25 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKDV.1124389
896

Agnitum Outpost
Trojan.Genome
7.1.1

Avira AntiVirus
TR/Kazy.84607.1
7.11.164.42

avast!
Win32:Malware-gen
2014.9-140822

AVG
Dropper.Generic7
2015.0.3374

Baidu Antivirus
Trojan.Win32.Genome
4.0.3.14822

Bitdefender
Trojan.GenericKDV.1124389
1.0.20.1170

Bkav FE
W32.Clodf13.Trojan
1.3.0.4959

Comodo Security
UnclassifiedMalware
18991

Emsisoft Anti-Malware
Trojan.GenericKDV.1124389
8.14.08.22.05

ESET NOD32
MSIL/PSW.Agent.NHM
8.10160

F-Secure
Trojan.GenericKDV.1124389
11.2014-22-08_6

G Data
Trojan.GenericKDV.1124389
14.8.24

IKARUS anti.virus
Trojan.Msil
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.181.12846

Kaspersky
Trojan.Win32.Genome
14.0.0.3366

McAfee
Artemis!3752B5F2F2E4
5600.7030

MicroWorld eScan
Trojan.GenericKDV.1124389
15.0.0.702

NANO AntiVirus
Trojan.Win32.Genome.cqkwdl
0.28.2.60990

Norman
Troj_Generic.GJKWN
11.20140822

nProtect
Trojan/W32.Genome.741376.AP
14.07.27.01

Panda Antivirus
Generic Malware
14.08.22.05

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Quick Heal
Trojan.Genome.r3
8.14.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.13EE1C75!334371957
23.00.65.14820

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
HKTL_BUILDSTEAL
7.2.234

Trend Micro
HKTL_BUILDSTEAL
10.465.22

Vba32 AntiVirus
Trojan.Genome.alzof
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
31654

ViRobot
Trojan.Win32.A.Genome.741376.AG
2011.4.7.4223

File size:
724 KB (741,376 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Ganja & Nirsoft 2012

Original file name:
THC Stealer v1.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
12/23/2012 8:52:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:evPZ9Cn5UGwuuCouKTMHK4RJ/13zQ5HlPLnoDXbt20WBdpdOGUHA:oPZpGICone/1jwFDabM0OdpdYHA

Entry address:
0xB3ECE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.3974

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
712 KB (729,088 bytes)

Remove thc stealer builder.exe - Powered by Reason Core Security