disable activation.exe

MD5:
39aca21e578ae33b4009c0a8619e7a26

SHA-1:
4dde113e58e005fb86600d0e2f40ae9d7ded3fdd

SHA-256:
36260a8fab647c0af4c76dce84d25b2c71680eff5bf519e4ce0e9574adac42d1

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/26/2024 3:28:06 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
17716

Dr.Web
Trojan.Hosts.23855
9.0.1.033

Norman
Suspicious_Gen7.EWE
11.20140202

File size:
322 KB (329,728 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\zpenlcxnuwwytjpd\crack\disable activation.exe

File PE Metadata
Compilation timestamp:
4/5/2011 5:44:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.25

CTPH (ssdeep):
6144:9dJBbn4LiLLDIHhyUEl/hrudNc7GJxAyNS+VbiEcG0:9J4LUIHhnEllWNmhL+VXJ0

Entry address:
0x913C

Entry point:
55, 8B, EC, B9, 06, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, A1, A0, AA, 40, 00, C6, 00, 01, B8, A0, 8F, 40, 00, E8, F3, BD, FF, FF, 33, C0, 55, 68, B7, 96, 40, 00, 64, FF, 30, 64, 89, 20, A1, 8C, A9, 40, 00, 33, D2, 89, 10, 8D, 45, EC, E8, C0, C1, FF, FF, 8B, 55, EC, B8, D4, F9, 40, 00, E8, F7, AE, FF, FF, 8D, 55, E8, A1, D4, F9, 40, 00, E8, BA, C0, FF, FF, 8B, 55, E8, B8, D4, F9, 40, 00, E8, DD, AE, FF, FF, C6, 05, D0, F9, 40, 00, 01, 6A, 0A, 68, C8, 96, 40, 00, A1, F0, D7, 40, 00, 50, E8...
 
[+]

Entropy:
6.0548

Developed / compiled with:
Microsoft Visual C++

Code size:
34 KB (34,816 bytes)

The file disable activation.exe has been seen being distributed by the following URL.

Scan disable activation.exe - Powered by Reason Core Security