keygen.exe

The application keygen.exe has been detected as a potentially unwanted program by 17 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from s10108.chomikuj.pl.
MD5:
10668553b4c32ba809eb288a08a14bef

SHA-1:
3084a728b73c309a7067a8ff7a05d5fad9bcb14e

SHA-256:
200b277c4f73eefef318152819300aecca2dd15147012916fdb086204a169632

Scanner detections:
17 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 7:40:34 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Keygen
7.1.1

AhnLab V3 Security
Packed/Win32.Katusha
2015.11.19

AVG
PSW.Banker5
2017.0.2846

Baidu Antivirus
Hacktool.Win32.Keygen
4.0.3.1621

Clam AntiVirus
Win.Trojan.5484805
0.98/21511

ESET NOD32
Win32/Keygen.AG potentially unsafe (variant)
10.12586

Fortinet FortiGate
PossibleThreat
2/1/2016

IKARUS anti.virus
not-a-virus.Keygen.ACDsee
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.212.17897

Malwarebytes
Trojan.Dropper.PGen
v2016.02.01.06

nProtect
Abuse-Worry/W32.KeyGen.115200
15.11.18.01

Panda Antivirus
Generic Malware
16.02.01.06

Rising Antivirus
PE:Malware.Keygen!6.C50 [F]
23.00.65.16130

Sophos
Keygen (PUA)
4.98

Trend Micro House Call
PAK_Generic.001
7.2.32

Trend Micro
PAK_Generic.001
10.465.01

VIPRE Antivirus
Trojan-Spy.Win32.Banker.ovo
45276

File size:
112.5 KB (115,200 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\acdsee photo manager 10.0.219 rus\keygen.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:XfFHNhrkkXGa3YqK3aP9MQuHGpzjNxTd9Rb5vTlG3:XdxWa3Y3KP9MmJX3ve

Entry address:
0xE45C

Entry point:
B8, 04, A8, 49, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 12, 16, 83, A3, 83, F2, 52, AF, F5, FB, 4F, 54, 2D, 47, 51, 40, 98, 5D, BD, 6F, 2B, E5, B8, 8C, CA, D8, DC, 89, 86, 43, AF, 8F, F1, 14, 6B, 85, DF, E3, 4E, B4, AD, 06, 43, 5E, 03, C4, B9, C7, B3, 7F, 26, DE, 40, DD, 99, D0, 88, 48, D4, 64, 6B, 11, D2, 4B, 01, C6, 74, EB, 50, 7A, BA, 50, E4, 82, 74, 1B, 70, 2A, A3, 83, 48, 73, E5, 09, CA, 3F, D0, 3B, 9E, BD, C7, EB, 0F...
 
[+]

Packer / compiler:
PECompact v2

Code size:
54.5 KB (55,808 bytes)

The file keygen.exe has been seen being distributed by the following URL.

Remove keygen.exe - Powered by Reason Core Security