{blocked}.exe

KyLfODfr

Dinosaur

The executable {blocked}.exe has been detected as malware by 5 anti-virus scanners.
Publisher:
Dinosaur  (signed and verified)

Product:
KyLfODfr

Version:
1.2.5.6

MD5:
1474caba483d2de93b9f2eb3bec60c2d

SHA-1:
127b294cd650a8ffdf2a57df6b1caa270664c03e

SHA-256:
af1848f898afeaccd892e8827806747762b2782287411892ec65fd6b96cdd076

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
11/8/2024 12:31:42 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Broban-AR [Trj]
160414-2

Emsisoft Anti-Malware
Trojan.GenericKDZ.27648
9.0.0.4157

ESET NOD32
MSIL/Injector.IXP trojan
8.0.319.0

Microsoft Security Essentials
Threat.Undefined
1.223.1545.0

Norman
Trojan.GenericKDZ.27648
28.05.2016 15:32:18

File size:
537.5 KB (550,416 bytes)

Product version:
1.2.5.6

Copyright:
Copyright KyLfODfr © 2015

Original file name:
KyLfODfr.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\screenshot_1511.scr.exe

Digital Signature
Signed by:

Authority:
getaCert - www.getacert.com

Valid from:
4/2/2015 4:58:13 AM

Valid to:
6/1/2015 4:58:13 AM

Subject:
E=LOL@run.away, CN=Melaldon, OU=Carnivore, O=Dinosaur, L=Cali, S=Pandora, C=NL

Issuer:
O=getaCert - www.getacert.com, L=Seattle, S=Washington, C=US

Serial number:
0DF6

File PE Metadata
Compilation timestamp:
4/3/2015 9:07:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:IoHIauUklFLy/CqPb82UNuk0lrqLeB303rZ92gQN1u:IiQUklxy/fb/UNuplrq6BJ8

Entry address:
0x7643E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
465.5 KB (476,672 bytes)

Remove {blocked}.exe - Powered by Reason Core Security