x64.exe

The executable x64.exe has been detected as malware by 23 anti-virus scanners.
MD5:
1f61cf413a6230ec21d7a9c30701cfa1

SHA-1:
8e2871b994ac5051b52ccc864a4d79dc877cbb49

SHA-256:
55fae9ed0545e1ac80ea04ffd4d6f659eeb608b202a4f00a9c5060dc8fd96f5c

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
4/26/2024 1:22:22 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11623764
701

Agnitum Outpost
Trojan.Agent
7.1.1

AVG
Agent4
2016.0.3179

Baidu Antivirus
Trojan.Win64.Agent
4.0.3.1535

Bitdefender
Trojan.Generic.11623764
1.0.20.320

Comodo Security
UnclassifiedMalware
21062

Dr.Web
Trojan.DownLoader11.37123
9.0.1.064

Emsisoft Anti-Malware
Trojan.Generic.11623764
8.15.03.05.10

ESET NOD32
Win64/Agent.CH
9.11169

Fortinet FortiGate
W64/Agent.CH!tr
3/5/2015

F-Secure
Trojan.Generic.11623764
11.2015-05-03_5

G Data
Trojan.Generic.11623764
15.3.25

IKARUS anti.virus
Trojan-Proxy.Win32.Wonknod
t3scan.1.8.6.0

McAfee
RDN/Generic Proxy!j
5600.6835

Microsoft Security Essentials
TrojanProxy:Win32/Wonknod.B
1.1.11302.0

MicroWorld eScan
Trojan.Generic.11623764
16.0.0.192

Norman
Troj_Generic.XRKUE
11.20150305

nProtect
Trojan.Generic.11623764
15.02.12.01

Panda Antivirus
Trj/CI.A
15.03.05.10

Quick Heal
TrojanProxy.Wonknod.r6
3.15.14.00

Trend Micro House Call
TROJ_SPNR.38I114
7.2.64

Trend Micro
TROJ_SPNR.38I114
10.465.05

VIPRE Antivirus
Trojan.Win32.Generic
37508

File size:
60.5 KB (61,952 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\x64.exe

File PE Metadata
Compilation timestamp:
7/4/2014 6:09:38 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:6nGicrT/Zev8TBs7yMIVaPgvETWvm8zahz6:GGi1v8TW7nGaPgMTYaJ6

Entry address:
0x3288

Entry point:
48, 83, EC, 28, E8, 8F, 33, 00, 00, 48, 83, C4, 28, E9, 76, FE, FF, FF, CC, CC, 48, 89, 5C, 24, 08, 48, 89, 6C, 24, 10, 48, 89, 74, 24, 18, 57, 48, 83, EC, 20, 48, 8D, 59, 1C, 48, 8B, E9, BE, 01, 01, 00, 00, 48, 8B, CB, 44, 8B, C6, 33, D2, E8, 27, FA, FF, FF, 45, 33, DB, 48, 8D, 7D, 10, 41, 8D, 4B, 06, 41, 0F, B7, C3, 44, 89, 5D, 0C, 4C, 89, 5D, 04, 66, F3, AB, 48, 8D, 3D, 26, BD, 00, 00, 48, 2B, FD, 8A, 04, 1F, 88, 03, 48, FF, C3, 48, FF, CE, 75, F3, 48, 8D, 8D, 1D, 01, 00, 00, BA, 00, 01, 00, 00, 8A, 04...
 
[+]

Entropy:
5.7049

Code size:
37.5 KB (38,400 bytes)

Remove x64.exe - Powered by Reason Core Security