{1c044075-8fe4-47c2-aaa3-e3e22dd8b48d}

Rapid7 LLC

The file {1c044075-8fe4-47c2-aaa3-e3e22dd8b48d} has been detected as malware by 9 anti-virus scanners.
Publisher:
Rapid7 LLC  (signed and verified)

MD5:
049461b1221ee2ecfc887eec3080ce05

SHA-1:
9dac769c293160d61200bb406cafb293c89991aa

SHA-256:
a4a20d485c033d5e10dc44c706f03e1edd2eed10ba483ef09b8f57d53ae4f99b

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
11/25/2024 9:56:21 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Swrort
7.1.1

avast!
Win32:Agent-ARNB [Trj]
2014.9-150509

Comodo Security
UnclassifiedMalware
21573

Dr.Web
Trojan.Click2.45960
9.0.1.0129

F-Prot
W32/A-783cd85d
v6.4.7.1.166

K7 AntiVirus
Trojan
13.202.15414

Panda Antivirus
Trj/Genetic.gen
15.05.09.08

SUPERAntiSpyware
Trojan.Agent/Gen-Swrort
9885

Trend Micro House Call
HV_SWRORT_CA2239BA.TOMC
7.2.129

File size:
21.1 KB (21,656 bytes)

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
12/21/2011 11:07:24 AM

Valid to:
12/21/2012 11:03:50 AM

Subject:
CN=Rapid7 LLC, O=Rapid7 LLC, L=Austin, S=TX, C=US

Issuer:
SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4EF02272FB2A40

File PE Metadata
Compilation timestamp:
12/29/2011 2:13:31 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
192:QXKcyowJL/RkmEPJUuJFuzf77yowJL/RkmEPJUuJFuzf7l:MKcYJLRktRgHYJLRktRgB

Entry address:
0x10D0

Entry point:
55, 8B, EC, 83, EC, 08, 6A, 00, E8, 23, FF, FF, FF, 83, C4, 04, 89, 45, F8, 83, 7D, F8, 00, 75, 04, 33, C0, EB, 0E, 8B, 45, F8, 89, 45, FC, FF, 55, FC, B8, 01, 00, 00, 00, 8B, E5, 5D, C2, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.2571

Developed / compiled with:
Microsoft Visual C++

Code size:
512 Bytes (512 bytes)

Remove {1c044075-8fe4-47c2-aaa3-e3e22dd8b48d} - Powered by Reason Core Security