gtms.exe

Version:
0.0.0.0

MD5:
4f0c0c02c88f0aa37fe46c0d4c36a79d

SHA-1:
fb50e50d6574bd7cb06eca8d677e410245e65cc1

SHA-256:
e8bfce90b3e37c3b83242c916cde0820b34de9f510145b8ba891361567f89f4f

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/26/2024 12:34:01 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/TrojanDropper.Agent.CLM trojan
8.0.319.0

File size:
28.5 KB (29,184 bytes)

Product version:
0.0.0.0

Original file name:
gtm.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\gtms.exe

File PE Metadata
Compilation timestamp:
7/4/2016 5:33:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:LrRy2e+bELTGQ4/v7JL/xd6x+hcaG0kjkS8Mgc1xo2Jz7SWXCfgM:7e+zJLNh00kj0Mgcdz7eY

Entry address:
0x874E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.6719

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
26 KB (26,624 bytes)

The file gtms.exe has been seen being distributed by the following URL.

Scan gtms.exe - Powered by Reason Core Security