key-generator.exe

The application key-generator.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. The file has been seen being downloaded from download2023.mediafire.com and multiple other hosts.
MD5:
f3bbe2e283956727757a6b59334adb66

SHA-1:
388e688d027ac6d427fe20e3d6f2598fd47c1a91

SHA-256:
f6b183feac94829294115c4c20610b8e6fc07190bf39ef7545636419e1221e25

Scanner detections:
10 / 68

Status:
Potentially unwanted

Analysis date:
11/30/2024 9:22:02 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Keygen.98304
14.03.27

Avira AntiVirus
SPR/Tool.Keygen.773
7.11.138.118

AVG
Crack
2015.0.3522

Bkav FE
W32.HfsAutoB
1.3.0.4959

F-Prot
W32/Heuristic-210
v6.4.7.1.166

IKARUS anti.virus
not-a-virus.Keygen.CoD
t3scan.2.2.29

Microsoft Security Essentials
1.10401

Norman
Troj_Generic.NUSM
11.20140327

Rising Antivirus
PE:Trojan.Win32.Generic.12CA95AA!315266474
23.00.65.14325

VIPRE Antivirus
HackTool.Win32.Keygen
27660

File size:
96 KB (98,304 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\key-generator.exe

File PE Metadata
Compilation timestamp:
11/8/2008 5:03:10 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
768:PzAuZxY2KS+J+VUwFM0N1lTZzlE1Zn7Aue85sG5K3hSgTtG4z7XPCpxO/huLMpug:XxHYcO0NnTZzlcZ7peThSiCqELMMpR

Entry address:
0x1000

Entry point:
6A, 00, E8, 23, 02, 00, 00, A3, BC, 32, 40, 00, E8, 1F, 02, 00, 00, 50, E8, E3, 02, 00, 00, 33, C0, 66, B8, 65, 00, 6A, 00, 68, 39, 10, 40, 00, 6A, 00, 50, FF, 35, BC, 32, 40, 00, E8, 0A, 02, 00, 00, 6A, 00, E8, EB, 01, 00, 00, 55, 8B, EC, 81, C4, 68, FF, FF, FF, 53, 56, 57, 55, 33, C0, 66, 8B, 45, 0C, 66, 83, F8, 02, 75, 04, EB, 28, EB, 1C, 66, 83, F8, 10, 75, 04, EB, 1E, EB, 12, 66, 3D, 11, 01, 75, 04, EB, 38, EB, 08, 66, 3D, 10, 01, 75, 02, EB, 4F, 33, C0, 5D, 5F, 5E, 5B, C9, C2, 10, 00, FF, 35, C8, 32...
 
[+]

Entropy:
5.6060

Packer / compiler:
MASM / TASM

Code size:
4 KB (4,096 bytes)

The file key-generator.exe has been seen being distributed by the following 19 URLs.

http://download2023.mediafire.com/x1d7c4wa2afg/.../key-generator.exe

http://download2023.mediafire.com/0de2oc63o0sg/.../key-generator.exe

http://download2023.mediafire.com/58syd8q29ugg/.../key-generator.exe

http://download2023.mediafire.com/n9vhzesv66dg/.../key-generator.exe

http://download2023.mediafire.com/t9cb5h3hj7sg/.../key-generator.exe

Remove key-generator.exe - Powered by Reason Core Security