80e2.tmp

Agnitum Ltd.

The file 80e2.tmp has been detected as malware by 1 anti-virus scanner.
Publisher:
Agnitum Ltd.  (signed and verified)

MD5:
72c662308ec1b78fe7e61ff8e3e1344f

SHA-1:
858da99062128c0a438ad3117a7204534c72d298

SHA-256:
561d03b3d5f282e48157ba2ba7d23216f3a33fdbb74e20079280d654d67983a6

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/27/2024 6:46:19 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Trojan.Kryptic
17.2.7.22

File size:
740.3 KB (758,088 bytes)

Common path:
C:\users\{user}\appdata\local\temp\80e2.tmp

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/21/2006 2:00:00 AM

Valid to:
12/19/2009 12:59:59 AM

Subject:
CN=Agnitum Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Agnitum Ltd., L=Nicosia, S=Nicosia, C=CY

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4F538F2425657E9505193A68065FEDF6

File PE Metadata
Compilation timestamp:
12/26/2013 11:13:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
3.216

Entry address:
0x1000

Entry point:
50, 6A, 01, 6A, 00, FF, 15, 24, 92, 41, 00, B8, 68, 0D, 00, 00, 50, 33, C9, B8, B0, 7E, 00, 00, 50, 68, 8F, 06, 4C, 00, 6A, 16, 6A, 20, 6A, 00, FF, 15, 00, 92, 41, 00, A3, 8B, 06, 4C, 00, 68, EA, 00, 00, 00, FF, 35, 8B, 06, 4C, 00, FF, 15, 8C, 91, 41, 00, 83, C0, 01, 74, 06, BF, B0, 7E, 00, 00, C3, 8B, EC, 81, EC, 18, 07, 00, 00, 68, 00, A9, 52, 14, FF, 15, 24, 92, 41, 00, 66, 85, C0, 0F, 84, 2E, 1E, 00, 00, BF, 69, 00, 00, 00, 89, BD, F4, FE, FF, FF, B9, 7D, B3, 00, 00, C1, E9, 05, 89, 0D, 80, 02, 4C, 00...
 
[+]

Code size:
93 KB (95,232 bytes)

Remove 80e2.tmp - Powered by Reason Core Security