abc.exe

The executable abc.exe has been detected as malware by 15 anti-virus scanners.
MD5:
3d90b8e5a7260b808b4832ceb901de00

SHA-1:
21496f655ce8a9b862dee1a2419de883de8a4643

SHA-256:
91fb6057956e33ea2c61008a4f7bca93f15d4dc88c6645e238120f164c610af0

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
4/29/2024 4:59:46 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
BDS/Backdoor.Gen
7.9.1.44

Bitdefender
Gen:Trojan.Heur.WSW@rXK3Qeebi
1.0.20.345

ESET NOD32
Win32/KillAV.NDA (variant)
11.4546

F-Secure
Gen:Trojan.Heur.WSW@rXK3Qeebi
11.2017-10-03_6

G Data
Gen:Trojan.Heur.WSW@rXK3Qeebi
17.3.19

McAfee
Artemis!3D90B8E5A726
5600.6100

Microsoft Security Essentials
Worm:Win32/Autorun.PP
1.163.1557.0

Norman
W32/Obfuscated.O!genr
11.20170310

Panda Antivirus
Trj/CI.A
17.03.10.09

Prevx
Medium Risk Malware
3.0

Quick Heal
(Suspicious) - DNAScan
3.17.10.00

Rising Antivirus
Backdoor.Win32.ShangXing.beq
23.00.65.17308

Sophos
Sus/UnkPacker
4.46

Trend Micro
Cryp_Opet-3
10.465.10

Vba32 AntiVirus
MalwareScope.Trojan-PSW.Game.16
3.12.10.11

File size:
777 KB (795,648 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\abc.exe

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x1DD394

Entry point:
68, 04, 40, 9E, 30, E8, 9B, 4C, 00, 00, 68, 04, 30, 6C, DE, E8, 87, 5F, 00, 00, F9, 77, 5E, 70, CC, 2C, 28, 4C, E8, 9C, A6, CA, AA, BE, 02, 72, C2, 3A, A6, FE, 4E, 96, FE, 72, F2, CE, C2, E3, FA, EE, 12, C0, B4, 35, A1, B8, AC, EA, 03, 4E, 49, 5F, F8, EA, 40, 0D, 50, 28, 42, 32, C0, 3A, 7B, 80, D7, A8, 83, EC, 5C, 48, 89, 89, AA, 8F, 5C, 16, 40, 3D, 7E, 7E, F8, 19, 0A, F1, 4F, BC, B0, D1, 25, F9, 12, 2C, F1, 0E, 82, 3E, 52, 4E, 81, 90, 92, 8C, A5, B9, 19, C7, BB, F9, AF, 70, AB, 47, 00, EE, 02, 23, 6A, FB...
 
[+]

Entropy:
7.9503  (probably packed)

Code size:
1.9 MB (1,979,392 bytes)

Remove abc.exe - Powered by Reason Core Security