gazoz hacks.exe

VMware Tools

Inergen

The application gazoz hacks.exe, “VMware HGFS Client” by Inergen has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from mediadisk.net.
Publisher:
VMware, Inc.  (signed by Inergen)

Product:
VMware Tools

Description:
VMware HGFS Client

Version:
9.6.2.31837

MD5:
dfe61fa1516c98bb3bff793bab83cd68

SHA-1:
c1012f0dca621b432c4c2199e921fc81a4c79d58

SHA-256:
b8152a2f329442af2881da3555b092796f2fc36d939b30d5666a9332e4b8a479

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/10/2025 3:04:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Inergen (M)
16.6.20.5

File size:
560 KB (573,480 bytes)

Product version:
9.6.2 build-1688356

Copyright:
Copyright © 1998-2014 VMware, Inc.

Original file name:
hgfsclient.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\gazoz hacks.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/25/2016 3:00:00 AM

Valid to:
5/26/2017 2:59:59 AM

Subject:
CN=Inergen, O=Inergen, STREET="AVENUE VOLGOGRAD, House 93, Building 2, ROOM II ROOM 12,", L=Moscow, S=Moscow, PostalCode=109117, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C9BE03B759B3C958ED3BBFB001506309

File PE Metadata
Compilation timestamp:
6/19/2016 11:00:53 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:43sSVaLKtMP6X0LCZkCy3KUmvVel0eMxxf5IYkbHIAtWAWM7zFr7TXE0WKRsEt6j:VvWCMZ1SKUIIsxBN+HIoJ3d9WTKfB0

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, B8, 03, 00, 00, 68, 51, 06, 00, 00, 6A, 00, FF, 15, E0, A0, 48, 00, 50, FF, 15, E4, A0, 48, 00, 68, 4C, B0, 48, 00, 8B, 45, EC, 50, FF, 15, F4, A0, 48, 00, 68, 9D, 15, 00, 00, 8B, 0D, 14, B9, 48, 00, 51, FF, 15, F8, A0, 48, 00, 85, C0, 74, 07, 33, C0, E9, F6, 01, 00, 00, 8B, 55, F4, 81, EA, D3, 6B, AA, 04, 89, 55, EC, 8B, 45, F0, 8B, 4D, EC, D3, E0, 89, 45, F0, 8B, 4D, F4, 81, C1, 31, 1E, 83, 10, 89, 4D, F8, 68, 51, 06, 00, 00, 6A, 00, FF, 15, E0, A0, 48, 00, 50, FF, 15, E4, A0, 48, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
547.5 KB (560,640 bytes)

The file gazoz hacks.exe has been seen being distributed by the following URL.

Remove gazoz hacks.exe - Powered by Reason Core Security