mtkdroidtools.exe

MD5:
fa8c473d26961df027cf5bb4e0c84b8a

SHA-1:
79e6275da88f869c6d6b51be9a95bf1bf4a06a30

Scanner detections:
6 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/27/2024 2:54:01 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Trojan.Win32.Asim
4.0.3.14620

McAfee
Artemis!FA8C473D2696
5600.7094

Norman
Suspicious_Gen4.FPVKR
11.20140620

Rising Antivirus
PE:Trojan.Injector!1.9DEE
23.00.65.14618

Trend Micro House Call
TROJ_GEN.R0CBH05LB13
7.2.171

VIPRE Antivirus
Trojan.Win32.Generic
26858

File size:
459.5 KB (470,528 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
12/5/2013 3:25:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.50

CTPH (ssdeep):
12288:ZpH9oxYF/borfqM0b9LnwQX5wRVDutqe:loxYhcrqfLnwi50kq

Entry address:
0x1000

Entry point:
68, C4, 02, 00, 00, 68, 00, 00, 00, 00, 68, BC, 32, 47, 00, E8, FE, B3, 02, 00, 83, C4, 0C, 68, 00, 00, 00, 00, E8, FD, B3, 02, 00, A3, C0, 32, 47, 00, 68, 00, 00, 00, 00, 68, 00, 10, 00, 00, 68, 00, 00, 00, 00, E8, EA, B3, 02, 00, A3, BC, 32, 47, 00, B8, 3C, D4, 46, 00, A3, 24, 33, 47, 00, E8, D2, 55, 05, 00, E8, 4D, 47, 05, 00, E8, 23, 47, 05, 00, E8, AC, 3D, 05, 00, E8, 65, 3C, 05, 00, E8, D2, 3B, 05, 00, E8, 68, 39, 05, 00, E8, AA, 20, 05, 00, E8, C0, 1E, 05, 00, E8, 45, 0A, 05, 00, E8, 82, FC, 04, 00...
 
[+]

Packer / compiler:
PKLITE32, 0x1.1

Code size:
343.5 KB (351,744 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to misc.v.dropbox.com  (108.160.172.200:80)

TCP (HTTP):
Connects to static.khi77.pie.net.pk  (221.120.207.20:80)

TCP (HTTP):
Connects to ec2-54-162-67-35.compute-1.amazonaws.com  (54.162.67.35:80)

Scan mtkdroidtools.exe - Powered by Reason Core Security