keygen.exe

The application keygen.exe has been detected as a potentially unwanted program by 30 anti-malware scanners. The file has been seen being downloaded from s10063.chomikuj.pl.
MD5:
888764791d706546ddda46d7439c14c0

SHA-1:
d69344e78fd09ca76096f87a28fc9cb6388d0ec5

SHA-256:
e84cdf03985ae183dca497a8758fe920f1623f6130ff8cce15d881d0284f4df1

Scanner detections:
30 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 12:51:50 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.RP.kGX@am3pKmpi
599

Agnitum Outpost
Trojan.Packed
7.1.1

AhnLab V3 Security
Trojan/Win32.Buzus
2015.06.11

Avira AntiVirus
TR/Black.Gen2
8.3.1.6

Arcabit
Trojan.Heur.RP.ED1349F
1.0.0.425

AVG
Win32/Blacked
2016.0.3077

Baidu Antivirus
PUA.Win32.VMProtect
4.0.3.15615

Bitdefender
Gen:Trojan.Heur.RP.kGX@am3pKmpi
1.0.20.830

Clam AntiVirus
Win.Trojan.Agent-639724
0.98/21511

Comodo Security
TrojWare.Win32.Trojan.XPACK.Gen
22406

Emsisoft Anti-Malware
Gen:Trojan.Heur.RP.kGX@am3pKmpi
8.15.06.15.03

ESET NOD32
Win32/Packed.VMProtect.AAD (variant)
9.11764

Fortinet FortiGate
W32/Packed_VMProtect.AAD
6/15/2015

F-Secure
Gen:Trojan.Heur.RP.kGX@am3pKmpi
11.2015-15-06_2

G Data
Gen:Trojan.Heur.RP.kGX@am3pKmpi
15.6.25

IKARUS anti.virus
Trojan.Win32.Genome
t3scan.1.9.5.0

K7 AntiVirus
Riskware
13.204.16199

Kaspersky
HEUR:VirTool.Win32.Generic
14.0.0.1882

McAfee
RDN/Generic.dx!dpd
5600.6733

Microsoft Security Essentials
Trojan:Win32/Dynamer!dtc
1.1.11701.0

MicroWorld eScan
Gen:Trojan.Heur.RP.kGX@am3pKmpi
16.0.0.498

NANO AntiVirus
Riskware.Win32.Black.dcgtei
0.30.24.2086

Panda Antivirus
Trj/Thed.W
15.06.15.03

Qihoo 360 Security
HEUR/Malware.QVM16.Gen
1.0.0.1015

Quick Heal
Trojan.gen.r8
6.15.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.129CB8E8!312260840
23.00.65.15613

Sophos
Mal/VMProtBad-A
4.98

Vba32 AntiVirus
Trojan.Genome.yp
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
41000

Zillya! Antivirus
Trojan.Packed.Win32.11612
2.0.0.2217

File size:
164 KB (167,936 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
8/14/2020 12:07:50 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
1536:q9eCegIzLcMl7EWMibmEFnyJWs6xOhZycQUBJY6fbaA7CNuesOk:e1egIzLcMl7nCE9g6xO7zQGa6zaNt

Entry address:
0x29946

Entry point:
53, C7, 04, 24, 66, C0, C9, 4D, 9C, 9C, C7, 44, 24, 04, 3F, 1C, A4, BB, 68, 48, EE, 3B, 37, 8D, 64, 24, 08, E9, FC, B1, 00, 00, 3B, 20, EF, 80, 3A, 4A, 26, 91, F0, 77, C2, 0D, 84, D7, 3A, 7D, F0, F7, D6, 25, 1C, 4D, 6D, 60, F4, 05, FC, 91, 04, AC, EE, 96, 01, 70, 55, 48, B5, 49, 38, 8A, 2F, 80, 27, 68, F8, 42, D3, 63, C2, 44, B3, 48, 99, 74, BC, FC, B8, BD, 75, B0, D1, CC, AE, 6E, 8D, AB, 31, 4E, 38, E5, C8, 0D, BB, 61, 5C, C5, 8D, C1, 80, 44, 2A, CD, A8, 77, 07, EA, D5, 6F, F8, D4, FE, D7, F1, B0, E2, DD...
 
[+]

Entropy:
5.6332

Code size:
207.5 KB (212,480 bytes)

The file keygen.exe has been seen being distributed by the following URL.

Remove keygen.exe - Powered by Reason Core Security