f87ed4e9c45cee8a2e8b0f4d5f16cb2e_2289664.npb

The file f87ed4e9c45cee8a2e8b0f4d5f16cb2e_2289664.npb has been detected as malware by 36 anti-virus scanners.
MD5:
f87ed4e9c45cee8a2e8b0f4d5f16cb2e

SHA-1:
cc8f31c663900cafd9baac119cfc11cd52fbe1b6

SHA-256:
60e9087ae31043a0b6fc1b1a031afebcfcd36e9340d7a8971c867da0fd92a3b6

Scanner detections:
36 / 68

Status:
Malware

Analysis date:
4/27/2024 6:15:52 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Dropper.Agent.VID
-40

AegisLab AV Signature
W32.W.Sohanad.it!c
2.1.4+

AhnLab V3 Security
Worm/Win32.Nuqel.N1024679897
3.7.5.15

Avira AntiVirus
TR/Patched.Ren.Gen
8.3.3.4

Arcabit
Trojan.Dropper.Agent.VID
1.0.0.774

avast!
Win32:Agent-AVDF [Trj]
2014.9-170316

AVG
Patched_c
2018.0.2438

Baidu Antivirus
Win32.Worm.Sohanad
4.0.3.17316

Bitdefender
Trojan.Dropper.Agent.VID
1.0.20.375

Bkav FE
W32.HfsAutoA
1.3.0.8383

Clam AntiVirus
Win.Trojan.Autoit-73
0.98/21511

Comodo Security
Worm.Win32.AutoIt.~N4
25812

Dr.Web
Win32.HLLW.Autoruner.5517
9.0.1.075

Emsisoft Anti-Malware
Trojan.Dropper.Agent.VID
8.17.03.16.12

ESET NOD32
Win32/Sohanad.NCB
11.14167

Fortinet FortiGate
W32/SOHAND.SM!worm
3/16/2017

F-Prot
W32/AutoIt.BR.gen
v6.4.7.1.166

F-Secure
Trojan.Dropper.Agent.VID
11.2017-16-03_5

G Data
Trojan.Dropper.Agent.VID
17.3.25

IKARUS anti.virus
Worm.Win32.AutoIt
t3scan.2.1.6.0

K7 AntiVirus
Trojan
13.2320970

Kaspersky
IM-Worm.Win32.Sohanad
14.0.0.-1315

McAfee
W32/Worm-FTY!F87ED4E9C45C
5600.6094

Microsoft Security Essentials
Worm:Win32/Nuqel.Z
1.1.13103.0

MicroWorld eScan
Trojan.Dropper.Agent.VID
18.0.0.225

NANO AntiVirus
Trojan.Win32.Sohanad.cogfop
1.0.38.11617

Panda Antivirus
Trj/Autoit.gen
17.03.16.12

Qihoo 360 Security
Win32/Trojan.167
1.0.0.1120

Quick Heal
Worm.Autoit.Sohanad.S
3.17.14.00

Rising Antivirus
Malware.Heuristic!ET (rdm+)
23.00.65.17314

Sophos
Troj/Mdrop-GLI
4.98

Trend Micro House Call
TROJ_FAM_0000533.TOMA
7.2.75

Trend Micro
TROJ_FAM_0000533.TOMA
10.465.16

Vba32 AntiVirus
Trojan-Downloader.Autoit.gen
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
52516

Zillya! Antivirus
Worm.Sohanad.Win32.2967
2.0.0.3065

File size:
2.2 MB (2,289,664 bytes)

Common path:
C:\ProgramData\net protector\npbkp\f87ed4e9c45cee8a2e8b0f4d5f16cb2e_2289664.npb

File PE Metadata
Compilation timestamp:
11/24/2007 11:33:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x53E3D

Entry point:
E8, 58, B1, 00, 00, E9, 17, FE, FF, FF, B8, BB, FA, 45, 00, A3, 28, 6D, 47, 00, C7, 05, 2C, 6D, 47, 00, B7, F1, 45, 00, C7, 05, 30, 6D, 47, 00, 75, F1, 45, 00, C7, 05, 34, 6D, 47, 00, A9, F1, 45, 00, C7, 05, 38, 6D, 47, 00, 1F, F1, 45, 00, A3, 3C, 6D, 47, 00, C7, 05, 40, 6D, 47, 00, 35, FA, 45, 00, C7, 05, 44, 6D, 47, 00, 35, F1, 45, 00, C7, 05, 48, 6D, 47, 00, 9F, F0, 45, 00, C7, 05, 4C, 6D, 47, 00, 2E, F0, 45, 00, C3, E8, 9B, FF, FF, FF, E8, 90, BC, 00, 00, 83, 7C, 24, 04, 00, A3, 34, 8A, 47, 00, 74, 05...
 
[+]

Entropy:
6.9558

Code size:
404.5 KB (414,208 bytes)

Remove f87ed4e9c45cee8a2e8b0f4d5f16cb2e_2289664.npb - Powered by Reason Core Security