trojan.exe

The executable trojan.exe has been detected as malware by 30 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘8515eb34d8f9de5af815466e9715b3e5’.
MD5:
740b9f3cae70cb96414b11398d2aaba0

SHA-1:
9eaac316ec5085e532ac91a07c9c9ff084141207

SHA-256:
2645955529bd9b79cc87e483e800fd329eca1d71aecfb73592e4bc51027db2db

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
4/25/2024 1:12:00 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Barys.12841
918

AhnLab V3 Security
Trojan/Win32.Bladabindi
2014.08.01

Avira AntiVirus
BDS/Bladabindi.cikr
7.11.164.206

avast!
Win32:Agent-ARSZ [Trj]
140617-1

AVG
Trojan horse MSIL.AL
2014.0.3986

Bitdefender
Gen:Variant.Barys.12841
1.0.20.1060

Comodo Security
TrojWare.MSIL.Bladabindi.O
19039

Dr.Web
BackDoor.Bladabindi.1393
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Barys.12841
8.14.07.31.03

ESET NOD32
MSIL/Bladabindi.O trojan
7.0.302.0

Fortinet FortiGate
MSIL/Agent.PPW!tr
7/31/2014

F-Prot
W32/MSIL_Troj.AP.gen
4.6.5.141

F-Secure
Gen:Variant.Barys.12841
11.2014-31-07_5

G Data
Gen:Variant.Barys.12841
14.7.24

IKARUS anti.virus
Trojan.Agent
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.182.12911

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3477

Malwarebytes
Backdoor.Agent.TRJ
v2014.07.31.03

McAfee
Trojan-FAUE!740B9F3CAE70
5600.7052

Microsoft Security Essentials
Threat.Undefined
1.179.1619.0

MicroWorld eScan
Gen:Variant.Barys.12841
15.0.0.636

NANO AntiVirus
Trojan.Win32.Autoruner.dcktlz
0.28.2.61148

Norman
Bladabindi.HY
11.20140731

Qihoo 360 Security
Malware.QVM03.Gen
1.0.0.1015

Quick Heal
Trojan.Bladabindi.B3
7.14.14.00

Sophos
Troj/MSIL-HX
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-MSIL
10450

Trend Micro House Call
BKDR_BLADABI.SMC
7.2.212

Trend Micro
BKDR_BLADABI.SMC
10.465.31

VIPRE Antivirus
Threat.4785344
31208

File size:
43.5 KB (44,544 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\trojan.exe

File PE Metadata
Compilation timestamp:
7/31/2014 6:54:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:ZnAlrUPMNBGdLB3QEyK6yVOpl6FUzn1u8KVTrdJCYv4b/oc07Y+/WURFl+:ClrUPMmdLB3QEyK6Saz1utFCYv4b/oJr

Entry address:
0xC44E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.5777

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
41.5 KB (42,496 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
8515eb34d8f9de5af815466e9715b3e5

Command:
"C:\users\{user}\appdata\roaming\trojan.exe"..


Remove trojan.exe - Powered by Reason Core Security