krt_5.0.0.111.exe

KRT

Collective Intelligence forum.ru-board

The application krt_5.0.0.111.exe has been detected as a potentially unwanted program by 20 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from doc-0k-3c-docs.googleusercontent.com and multiple other hosts.
Publisher:
Collective Intelligence forum.ru-board

Product:
KRT

Version:
5.0.0.111

MD5:
66d8d83e4ee4e3cad8b2a1b8c75aadeb

SHA-1:
e77a5a794490bd7c62643209a0f282f71aa1f002

SHA-256:
5328587008e827ec1444e2fc2be7cbdd95974b3dad0d7e1c90a7d5f7d69ac024

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
11/17/2024 3:53:48 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.1273941
631

Agnitum Outpost
RiskWare.HackAV
7.1.1

AhnLab V3 Security
HackTool/Win32.HackAV
2015.05.15

avast!
Win32:Malware-gen
2014.9-150515

Baidu Antivirus
Trojan.Win32.HackAV
4.0.3.15515

Bitdefender
Application.Generic.1273941
1.0.20.675

Comodo Security
UnclassifiedMalware
22118

Dr.Web
Trojan.KillFiles.27475
9.0.1.0135

ESET NOD32
Win32/RiskWare.HackAV.OM (variant)
9.11628

Fortinet FortiGate
RiskWare/HackAV
5/15/2015

F-Secure
Application.Generic.1273941
11.2015-15-05_6

G Data
Application.Generic.1273941
15.5.25

herdProtect (fuzzy)
2015.8.12.0

IKARUS anti.virus
PUA.RiskWare.HackAV
t3scan.1.8.9.0

McAfee
Artemis!66D8D83E4EE4
5600.6765

MicroWorld eScan
Application.Generic.1273941
16.0.0.405

NANO AntiVirus
Trojan.Win32.KRT.doctel
0.30.24.1357

Norman
Suspicious_Gen4.IIUVQ
11.20150515

Qihoo 360 Security
HEUR/QVM05.1.Malware.Gen
1.0.0.1015

Trend Micro House Call
Suspicious_GEN.F47V0508
7.2.135

File size:
1.8 MB (1,936,896 bytes)

Product version:
5.0.0.111

Copyright:
Copyright (C) 2013-2015 Collective Intelligence forum.ru-board

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\keys\keys_kaspersky\kaspersky reset trial 5.0.0.111\krt_5.0.0.111.exe

File PE Metadata
Compilation timestamp:
5/8/2015 5:03:05 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:dpXQwjz9oa4Es4ZlyM98aWdaypL/aoPahBeSZA4KlAGez5RoT06inDqWfTFJIMLT:dPzaZg0dB1ahQS/KMRV6inm+TFJFLT

Entry address:
0x186310

Entry point:
55, 8B, EC, 83, C4, F0, B8, 5C, E3, 57, 00, E8, B4, 4B, E8, FF, A1, FC, FB, 58, 00, 8B, 00, E8, C0, 34, FA, FF, A1, FC, FB, 58, 00, 8B, 00, B2, 01, E8, D2, 51, FA, FF, 8B, 0D, C8, F8, 58, 00, A1, FC, FB, 58, 00, 8B, 00, 8B, 15, 8C, BC, 57, 00, E8, B2, 34, FA, FF, 8B, 0D, 20, F9, 58, 00, A1, FC, FB, 58, 00, 8B, 00, 8B, 15, E4, E3, 56, 00, E8, 9A, 34, FA, FF, A1, FC, FB, 58, 00, 8B, 00, E8, F2, 35, FA, FF, E8, 31, 0C, E8, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.5 MB (1,592,832 bytes)

The file krt_5.0.0.111.exe has been seen being distributed by the following 2 URLs.

Remove krt_5.0.0.111.exe - Powered by Reason Core Security