kdlink32.exe

KDLink

QuestPRO Software

The executable kdlink32.exe, “KD-Link PPPoE Client” has been detected as malware by 3 anti-virus scanners. While running, it connects to the Internet address static.130.1.76.144.clients.your-server.de on port 80 using the HTTP protocol.
Publisher:
QuestPRO Software

Product:
KDLink

Description:
KD-Link PPPoE Client

Version:
1.0.25.539

MD5:
9e1b115a137ac44bcbf776b708fdc1f6

SHA-1:
ff3c07afa2a92a905dd6a4f438e1360923d2132a

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
12/24/2024 5:24:20 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Drop.Agent.966144
7.11.100.228

avast!
Win32:Dropper-gen [Drp]
2014.9-160202

IKARUS anti.virus
Virus.Win32.Dropper
t3scan.2.0.127

File size:
943.5 KB (966,144 bytes)

Product version:
1.0.0.0

Copyright:
Copyright©QuestPRO-Software. All rights reserved.

Trademarks:
QuestPRO Software

Original file name:
KDLink

File type:
Executable application (Win32 EXE)

Language:
Polish

Common path:
C:\Program Files\kd-linkblue\kdlink32.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:qK1KPdqW/ToTyOAgRxCHR3J2BzTZpWCsyTe:jQXroT+uTDWCsy

Entry address:
0xB1CF4

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, AC, EC, 4A, 00, E8, 77, 53, F5, FF, 8B, 1D, 04, CF, 4B, 00, 8B, 03, E8, 42, 24, FB, FF, 8B, 0D, F0, CA, 4B, 00, 8B, 03, 8B, 15, 10, 8C, 4A, 00, E8, 47, 24, FB, FF, 8B, 0D, 1C, D1, 4B, 00, 8B, 03, 8B, 15, D4, E7, 4A, 00, E8, 34, 24, FB, FF, 8B, 0D, 04, D4, 4B, 00, 8B, 03, 8B, 15, EC, EA, 4A, 00, E8, 21, 24, FB, FF, 8B, 0D, EC, D1, 4B, 00, 8B, 03, 8B, 15, 60, 6E, 4A, 00, E8, 0E, 24, FB, FF, 8B, 03, E8, 87, 24, FB, FF, 5B, E8, 69, 30, F5, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
704.5 KB (721,408 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to static.130.1.76.144.clients.your-server.de  (144.76.1.130:80)

Remove kdlink32.exe - Powered by Reason Core Security