krt_2.1.exe

KRT

Коллективный разум forum.ru-board

The application krt_2.1.exe has been detected as a potentially unwanted program by 22 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from f.cl.ly and multiple other hosts.
Publisher:
Коллективный разум forum.ru-board

Product:
KRT

Version:
2.1.0.19

MD5:
fd97948196d18c87f46d52ba612ed743

SHA-1:
78e9a61eefa503534c6c915bee54a9df0f2d95dd

SHA-256:
5b4e02f139bb6bd3ac188a18f877d28757719695e895be9ca55331286332cf39

Scanner detections:
22 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 2:26:48 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
HackTool.Kiser
7.1.1

AVG
HackTool
2015.0.3583

Baidu Antivirus
HackTool.Win32.Kiser
4.0.3.14126

Bkav FE
W32.Clod12e.Trojan
1.3.0.4923

Clam AntiVirus
Win.Trojan.Zusy-89
0.98/18155

Comodo Security
ApplicUnwnt.Win32.HackTool.Kiser.A
17671

ESET NOD32
Win32/RiskWare.HackAV.NR application
8.0.319.0

IKARUS anti.virus
HackTool.Win32.Kiser
t3scan.2.2.29

K7 AntiVirus
Riskware
13.175.10963

Kaspersky
HackTool.Win32.Kiser
14.0.0.4409

Malwarebytes
Hacktool.Kiser
v2014.01.26.02

McAfee
Artemis!FD97948196D1
5600.7239

NANO AntiVirus
Trojan.Win32.Kiser.crocae
0.28.0.57380

Norman
Suspicious_Gen4.EXVFL
11.20140126

nProtect
Trojan/W32.HackTool.1385984.B
14.01.25.01

Quick Heal
HackTool.Kiser.bse (Not a Virus)
2.14.12.00

Rising Antivirus
PE:Trojan.Win32.Generic.15A975D8!363427288
23.00.65.14124

Sophos
Generic PUA HI
4.97

Trend Micro House Call
HKTL_KISER
7.2.26

Trend Micro
HKTL_KISER
10.465.26

VIPRE Antivirus
Trojan.Win32.Generic
25786

XVirus List
Win.Detected
2.3.31

File size:
1.3 MB (1,385,984 bytes)

Product version:
2.1

Copyright:
(C) Коллективный разум forum.ru-board

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\kasper14act\krt_2.1.exe

File PE Metadata
Compilation timestamp:
7/6/2013 10:51:55 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:51YLn+aCSQsB9M1CziT3rq1I9BkSVArzxy5MV8as3S:5CcLpGYKI9OSVio5MZ

Entry address:
0x12616C

Entry point:
55, 8B, EC, 83, C4, F0, B8, 80, EF, 51, 00, E8, 0C, 46, EE, FF, A1, C0, B9, 52, 00, 8B, 00, E8, 44, 63, FE, FF, A1, C0, B9, 52, 00, 8B, 00, B2, 01, E8, 56, 80, FE, FF, 8B, 0D, 2C, B7, 52, 00, A1, C0, B9, 52, 00, 8B, 00, 8B, 15, EC, E0, 51, 00, E8, 36, 63, FE, FF, 8B, 0D, E0, BB, 52, 00, A1, C0, B9, 52, 00, 8B, 00, 8B, 15, 70, DD, 51, 00, E8, 1E, 63, FE, FF, A1, C0, B9, 52, 00, 8B, 00, E8, 76, 64, FE, FF, E8, C1, 06, EE, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.1 MB (1,200,640 bytes)

The file krt_2.1.exe has been seen being distributed by the following 4 URLs.

Remove krt_2.1.exe - Powered by Reason Core Security