cerberus.exe

The executable cerberus.exe has been detected as malware by 30 anti-virus scanners. Accoriding to the detections, this has been classified as a kyelogger which is capable of recoring a user's keystrokes.
MD5:
64a1f0f84e78b73110b70b52e75ce683

SHA-1:
2de10ee07aff2a5f0ebdd7e921db9f08dd886371

SHA-256:
88b73237342fd413715e4fcf0e49f2032b91fbb53e96945921bc7324c26bb6d7

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
4/28/2024 7:00:37 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win32/MalPackedB.suspicious
2011.09.24

Avira AntiVirus
BDS/Backdoor.Gen
7.11.15.30

avast!
Win32:Delf-GIY [Drp]
2014.9-170313

AVG
Win32/Cryptor
2018.0.2440

Bitdefender
Trojan.Generic.2345133
1.0.20.360

Comodo Security
TrojWare.Win32.Spy.KeyLogger.~P
10244

Dr.Web
Trojan.PWS.Multi.origin
9.0.1.072

Emsisoft Anti-Malware
Virus.Klone!IK
8.17.03.13.09

ESET NOD32
Win32/Spy.Delf.NYS (variant)
11.6493

Fortinet FortiGate
W32/Buzus.BVDP!tr
3/13/2017

F-Prot
W32/Fujack.U
v6.4.6.2.117

F-Secure
Trojan.Generic.2345133
11.2017-13-03_2

G Data
Trojan.Generic.2345133
17.3.22

IKARUS anti.virus
Virus.Klone
t3scan.1.1.107.0

K7 AntiVirus
Virus
13.113.5184

Kaspersky
Trojan.Win32.Buzus
14.0.0.-1304

McAfee
Artemis!64A1F0F84E78
5600.6096

Microsoft Security Essentials
VirTool:Win32/DelfInject.gen!AC
1.163.1557.0

Norman
Fujack.T
11.20170313

nProtect
Trojan/W32.Buzus.1759779
11.09.25.01

Panda Antivirus
Trj/CI.A
17.03.13.09

Prevx
High Risk Cloaked Malware
3.0

Quick Heal
Trojan.Agent.ATV
3.17.11.00

Rising Antivirus
Trojan.Win32.Generic.1231170B
23.00.65.17311

Sophos
Mal/Generic-L
4.69

Trend Micro House Call
TROJ_GEN.RC1C3H3
7.2.72

Trend Micro
TROJ_GEN.RC1C3H3
10.465.13

Vba32 AntiVirus
Trojan.Win32.Buzus.bvdp
3.12.16.4

VIPRE Antivirus
Trojan.Crypt.AntiSig.b
10582

ViRobot
Backdoor.Win32.IRCBot.35288
2011.9.24.4687

File size:
1.7 MB (1,759,779 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\cerberus rat 1.02 beta\cerberus.exe

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

Entry address:
0x1000

Entry point:
57, C7, C7, 72, AF, B4, DF, 8D, 3D, 5F, BA, 58, 1A, FF, CF, 0F, AC, F7, F2, 0F, BD, FE, F7, C7, 5C, DC, 30, 27, 0F, BA, F7, 33, 0F, BB, F7, 0F, CF, BF, 64, A9, 09, DB, 85, F6, 81, DF, AC, 19, 46, 48, F7, DF, 0F, A3, F7, C7, C7, 41, BC, 79, A0, 85, F7, D1, CF, 0F, B3, F7, 0F, AF, FE, C7, C7, 10, 6E, 5F, 55, 81, C7, B1, C9, 4B, 85, 85, F7, F3, 0F, BA, F7, 92, C7, C7, 58, 57, 03, 7B, 8B, FE, 64, 0F, BB, F7, F3, F7, C6, D9, 4C, D2, 3E, D1, FF, 09, F7, FF, C7, 87, FF, 0F, AC, F7, 1A, F2, 87, FF, 0F, AF, FE, 8D...
 
[+]

Entropy:
7.9965  (probably packed)

Windows Firewall Allowed Program
Name:
cerberus.exe


Remove cerberus.exe - Powered by Reason Core Security