install.exe

The executable install.exe has been detected as malware by 31 anti-virus scanners.
MD5:
8eadfe4cb6960d5a1783a30dab974c74

SHA-1:
e030f5b7178cc6bf40ca690c3c7e97ffac4fc3c5

SHA-256:
b4bac33b6dd84064af9ea04b295ca98f419f968f8eb377b9d34c13297f109066

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
4/1/2025 8:18:50 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Backdoor.SecretService
7.1.1

AhnLab V3 Security
Win-Trojan/SecretSrv.64000
2013.08.25

Avira AntiVirus
TR/BackDoor.CV.3
7.11.98.18

avast!
Win32:SecretService-B [Trj]
2014.9-170315

AVG
BackDoor.SecretService
2018.0.2438

Bitdefender
Backdoor.SecretService.B
1.0.20.370

Comodo Security
Backdoor.Win32.SecretService.10
16818

Dr.Web
BackDoor.SService.10
9.0.1.074

Emsisoft Anti-Malware
Backdoor.SecretService
8.17.03.15.04

ESET NOD32
Win32/SecretService.10
11.8724

Fortinet FortiGate
W32/BackDoor.SecretService.10
3/15/2017

F-Prot
W32/Malware!78a8
v6.4.7.1.166

G Data
Backdoor.SecretService
17.3.22

IKARUS anti.virus
Backdoor.Win32.SecretService.10
t3scan.2.0.127

K7 AntiVirus
Riskware
13.170.9377

Kaspersky
Backdoor.Win32.SecretService
14.0.0.-1313

McAfee
BackDoor-CV
5600.6094

Microsoft Security Essentials
Backdoor:Win32/SecretService.B
1.163.1557.0

MicroWorld eScan
Backdoor.SecretService.B
18.0.0.222

NANO AntiVirus
Trojan.Win32.SecretService.gils
0.26.0.53954

Norman
SecretService.1_0
11.20170315

nProtect
Backdoor/W32.SecretService.64000
13.08.23.03

Panda Antivirus
BK/SecretService.10
17.03.15.04

Quick Heal
Backdoor.SecretService.10
3.17.12.00

Rising Antivirus
Trojan.Win32.Generic.122B282E
23.00.65.17313

Sophos
Troj/Bdoor-CV
4.91

Trend Micro House Call
BKDR_SCRTSERV.10
7.2.74

Trend Micro
BKDR_SCRTSERV.10
10.465.15

Vba32 AntiVirus
Backdoor.SecretService
3.12.22.3

VIPRE Antivirus
Trojan.Win32.Generic
20850

ViRobot
Backdoor.Win32.SecretS.64000
2011.4.7.4223

File size:
62.5 KB (64,000 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ceh\cehv8 module 06 trojans and backdoors\miscellaneous trojans\dhcsecretservice\install.exe

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xC1E4

Entry point:
55, 8B, EC, 83, C4, E8, 53, 56, 57, 33, C0, 89, 45, EC, 89, 45, E8, B8, 74, C1, 40, 00, E8, 25, 90, FF, FF, 33, C0, 55, 68, DE, C7, 40, 00, 64, FF, 30, 64, 89, 20, B8, 30, E6, 40, 00, 68, 04, 01, 00, 00, 50, E8, 3B, 91, FF, FF, 8D, 55, EC, B8, 30, E6, 40, 00, E8, 2E, A3, FF, FF, 8B, 55, EC, B8, 98, E6, 40, 00, E8, B9, 6F, FF, FF, B8, 9C, E6, 40, 00, 68, 04, 01, 00, 00, 50, E8, F9, 90, FF, FF, 8D, 55, EC, B8, 9C, E6, 40, 00, E8, 04, A3, FF, FF, 8B, 55, EC, B8, 04, E7, 40, 00, E8, 8F, 6F, FF, FF, B2, 01, A1...
 
[+]

Entropy:
6.2839

Developed / compiled with:
Microsoft Visual C++

Code size:
47 KB (48,128 bytes)

Remove install.exe - Powered by Reason Core Security