ck_mcvt.exe

北京天瑞地安网络科技有限公司

The executable ck_mcvt.exe has been detected as malware by 9 anti-virus scanners.
Publisher:

MD5:
a1addd0fee32df0212419efad99aaac3

SHA-1:
5ac6806461da50868f2515e2eb4a2fbab48f053f

SHA-256:
f300c5a9c1acb31e68014599af72509e8d974359717e5a304672d7b45aa83b52

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
11/24/2024 6:03:43 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Win32/DH{I05X?}
2017.0.2691

ESET NOD32
probably unknown NewHeur_PE
10.13744

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
14.0.0.-48

McAfee
Artemis!A1ADDD0FEE32
5600.6347

Sophos
Mal/DownLdr-AC
4.98

Trend Micro House Call
Mal_DLDER
7.2.187

Trend Micro
Mal_DLDER
10.465.05

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
50570

File size:
41.2 KB (42,200 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\ck_mcvt.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/7/2015 5:30:00 AM

Valid to:
5/7/2016 5:29:59 AM

Subject:
CN=北京天瑞地安网络科技有限公司, O=北京天瑞地安网络科技有限公司, L=北京市, S=北京市, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6CAC2D28C3F0828B2EF49B40AA2B1287

File PE Metadata
Compilation timestamp:
7/2/2016 1:22:38 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
384:4wGSxJQDeyde4aXa9lVHkON/V6OzxzDKglljYq2CMhhhhLILtbfniIWle5us8dei:bGneNbX23EONt6OtrpR8Mfi5CgeaEE3

Entry address:
0x1958

Entry point:
E8, 3C, 05, 00, 00, E9, 63, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 98, 31, 40, 00, 89, 0D, 94, 31, 40, 00, 89, 15, 90, 31, 40, 00, 89, 1D, 8C, 31, 40, 00, 89, 35, 88, 31, 40, 00, 89, 3D, 84, 31, 40, 00, 66, 8C, 15, B0, 31, 40, 00, 66, 8C, 0D, A4, 31, 40, 00, 66, 8C, 1D, 80, 31, 40, 00, 66, 8C, 05, 7C, 31, 40, 00, 66, 8C, 25, 78, 31, 40, 00, 66, 8C, 2D, 74, 31, 40, 00, 9C, 8F, 05, A8, 31, 40, 00, 8B, 45, 00, A3, 9C, 31, 40, 00, 8B, 45, 04, A3, A0, 31, 40, 00, 8D, 45, 08, A3, AC, 31, 40...
 
[+]

Entropy:
5.9304

Code size:
4 KB (4,096 bytes)

Remove ck_mcvt.exe - Powered by Reason Core Security