timer_505_shut.exe

Beijing Kate Zhanhong Technology Co.,Ltd.

The application timer_505_shut.exe by Beijing Kate Zhanhong Technology Co.,Ltd has been detected as a potentially unwanted program by 16 anti-malware scanners.
Publisher:

Version:
1, 0, 0, 1

MD5:
2ed7ac43da1a4a4d2b3aef9b83d97d81

SHA-1:
a1e27cbc87cabc92643021b255e92f720ede8a1d

SHA-256:
3b06a972f9ef4da88543e54c56df277b9bb397681cee3937070f8721094a7445

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 4:19:26 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2936277
244

Agnitum Outpost
Riskware.Agent
7.1.1

avast!
Win32:Malware-gen
2014.9-160604

Baidu Antivirus
PUA.Win32.Kuping
4.0.3.1664

Bitdefender
Trojan.GenericKD.2936277
1.0.20.780

Emsisoft Anti-Malware
Trojan.GenericKD.2936277
8.16.06.04.06

ESET NOD32
Win32/Kuping.K potentially unwanted (variant)
10.12804

Fortinet FortiGate
Riskware/Kuping
6/4/2016

G Data
Trojan.GenericKD.2936277
16.6.25

K7 AntiVirus
Adware
13.212.18285

McAfee
Artemis!2ED7AC43DA1A
5600.6378

MicroWorld eScan
Trojan.GenericKD.2936277
17.0.0.468

NANO AntiVirus
Trojan.Win32.SelfStarterInternetTrojan.dzhpgy
1.0.14.5380

nProtect
Trojan.GenericKD.2936277
15.12.31.01

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.16602

VIPRE Antivirus
Trojan.Win32.Generic
46198

File size:
727.4 KB (744,816 bytes)

Product version:
1, 0, 0, 1

Copyright:
版权 (C) 2015

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\timer_505_shut.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/28/2013 8:00:00 AM

Valid to:
11/29/2014 7:59:59 AM

Subject:
CN="Beijing Kate Zhanhong Technology Co.,Ltd.", O="Beijing Kate Zhanhong Technology Co.,Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3C5883BD1DBCD582AD41C8778E4F56D9

File PE Metadata
Compilation timestamp:
12/18/2015 2:35:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:mg2PAfBtTrw0OnSjF0Mf2tmAjjv0s04ROsziHKSl2kkL2Roj/z+02hgE:m5stTrwrSjF0MftQj8s04EurL2Rof+p

Entry address:
0x3382

Entry point:
55, 8B, EC, 6A, FF, 68, 38, D6, 40, 00, 68, 0E, 35, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, C0, D2, 40, 00, 59, 83, 0D, C4, 39, 41, 00, FF, 83, 0D, C8, 39, 41, 00, FF, FF, 15, BC, D2, 40, 00, 8B, 0D, 54, 35, 41, 00, 89, 08, FF, 15, B8, D2, 40, 00, 8B, 0D, 50, 35, 41, 00, 89, 08, A1, B4, D2, 40, 00, 8B, 00, A3, C0, 39, 41, 00, E8, 1C, 01, 00, 00, 39, 1D, 98, 31, 41, 00, 75, 0C, 68, 0A, 35, 40, 00, FF, 15, B0, D2...
 
[+]

Entropy:
7.8266

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
48 KB (49,152 bytes)

Remove timer_505_shut.exe - Powered by Reason Core Security