netstream.exe

The executable netstream.exe has been detected as malware by 30 anti-virus scanners.
MD5:
2badd895e6f1f094a23ba275bbd344a3

SHA-1:
86d856a8fa24d001f78e6a6076d5607d7ced70ff

SHA-256:
4d7a6b1ee823adaf59b9964d54f243d43d74ebd33938984dd0e492a66fd9126a

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
11/29/2024 4:39:24 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Inject.BCY
-40

AhnLab V3 Security
Malware/Win32.Generic.C1837450
3.8.3.16

Avira AntiVirus
TR/Agent.qlagx
8.3.3.4

Arcabit
Trojan.Inject.BCY
1.0.0.802

avast!
Win32:Rootkit-gen [Rtk]
2014.9-170316

AVG
Crypt7
2018.0.2438

Baidu Antivirus
Win32.Trojan.Kryptik
4.0.3.17316

Bitdefender
Trojan.Inject.BCY
1.0.20.375

Comodo Security
TrojWare.Win32.Filecoder.DA
26760

Dr.Web
Trojan.Siggen7.13804
9.0.1.075

Emsisoft Anti-Malware
Trojan.Inject.BCY
8.17.03.16.04

ESET NOD32
Win32/Kryptik.CQLG (variant)
11.15092

Fortinet FortiGate
W32/Kryptik.ACVH!tr
3/16/2017

F-Secure
Trojan.Inject.BCY
11.2017-16-03_5

G Data
Trojan.Inject.BCY
17.3.A:25.11195B:25.9090

K7 AntiVirus
Trojan
13.10.6.22730

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-1316

Malwarebytes
Trojan.MalPack
v2017.03.16.04

McAfee
Artemis!2BADD895E6F1
5600.6094

Microsoft Security Essentials
TrojanProxy:Win32/Bunitu.Q!bit
1.1.13504.0

MicroWorld eScan
Trojan.Inject.BCY
18.0.0.225

NANO AntiVirus
Trojan.Win32.Yakes.emepkm
1.0.70.15657

Panda Antivirus
Trj/GdSda.A
17.03.16.04

Qihoo 360 Security
Win32/RootKit.Rootkit.7e5
1.0.0.1120

Quick Heal
TrojanProxy.Bunitu
3.17.14.00

Rising Antivirus
Trojan.Kryptik!1.A7BF (cloud:GTZTZw7KoEN)
23.00.65.17314

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
Mal_Cerber-15
7.2.75

Trend Micro
Mal_Cerber-15
10.465.16

VIPRE Antivirus
Trojan.Win32.Generic
56666

File size:
238 KB (243,712 bytes)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\netstream.exe

File PE Metadata
Compilation timestamp:
3/6/2017 5:07:16 AM

OS version:
3.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x224E0

Entry point:
55, 8B, EC, 83, EC, 1C, 57, 68, E2, 10, 00, 00, A1, F4, C7, 43, 00, 50, FF, 15, BC, 35, 42, 00, 85, C0, 74, 0A, B8, 37, 00, 00, 00, E9, 65, 03, 00, 00, EB, 00, 8B, D2, 8B, 55, 08, 8B, D2, 89, 15, FC, C7, 43, 00, 89, 2D, DC, C7, 43, 00, C6, 45, F3, 00, C7, 45, F4, 00, 00, 00, 00, 0F, B6, 4D, F3, 83, C1, 72, 8B, 55, F4, A1, 44, C4, 43, 00, 66, 89, 4C, 50, 08, 0F, B6, 4D, F3, 83, C1, 66, 8B, 55, F4, A1, 44, C4, 43, 00, 66, 89, 4C, 50, 0A, 0F, B6, 4D, F3, 83, C1, 61, 8B, 55, F4, A1, 44, C4, 43, 00, 66, 89, 4C...
 
[+]

Entropy:
4.1000

Developed / compiled with:
Microsoft Visual C++

Code size:
134.5 KB (137,728 bytes)

Remove netstream.exe - Powered by Reason Core Security