6bf906.exe

The executable 6bf906.exe has been detected as malware by 7 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘6BF906’.
MD5:
7d79e4af736907e153101332dfae7d7a

SHA-1:
77c36c6d36561c78db26af1a4624d09187350bf3

SHA-256:
1a713fb6575d9bc0aefd709f42a865d1175aeb60dc50b73391aaeabd900d5901

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/1/2025 8:03:10 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:ScramEPL [Cryp]
160917-0

Clam AntiVirus
Win.Worm.FlyStudio-27
0.98/23207

Dr.Web
Win32.HLLW.Autoruner.6675
9.0.1.05190

ESET NOD32
Win32/FlyStudio.NPP trojan
6.3.12010.0

F-Prot
W32/Agent.CM.gen
4.6.5.141

Kaspersky
Worm.Win32.FlyStudio
15.0.2.529

Microsoft Security Essentials
Worm:Win32/Autorun.GX
1.237.1169.0

File size:
112 KB (114,688 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Windows\System32\533971\6bf906.exe

File PE Metadata
Compilation timestamp:
12/25/1972 1:33:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
4.0

Entry address:
0x1F191

Entry point:
52, 53, 51, 50, 56, F9, 57, 0F, 82, D5, FF, FF, FF, F0, 95, EA, 42, A1, FB, 79, 8E, 18, CA, B0, 3B, 52, 96, 21, AB, FE, DF, 9C, 79, 19, 43, 97, 52, 6C, F1, D3, 06, 56, 61, 3D, DE, CB, 43, 13, 31, 9D, B5, 47, 32, FA, 0F, 85, 99, FE, FF, FF, 0F, 82, 87, 00, 00, 00, 79, 28, 0C, 37, E5, 3F, 31, CB, 5C, 77, EE, 9F, FE, 82, 44, 85, DC, 77, F3, 05, EE, C0, D7, 60, 09, 33, 77, CF, 0B, 7F, DC, 0C, 59, CA, 9F, 13, 8B, 4A, F9, 0F, 82, C7, FF, FF, FF, 46, 2A, 65, EF, D1, 1F, 09, B9, 8F, D1, 6C, 69, 36, F1, 07, E1, 33...
 
[+]

Entropy:
6.9418

Code size:
3 KB (3,072 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
6BF906

Command:
C:\Windows\System32\533971\6bf906.exe


Remove 6bf906.exe - Powered by Reason Core Security