patch.exe

The application patch.exe has been detected as a potentially unwanted program by 25 anti-malware scanners. The file has been seen being downloaded from dc495.4shared.com.
MD5:
ea12df4f4a531c23352c9b4afd1993e1

SHA-1:
1d0a4701e279f0e3cefde8b99412a61cea3b9dcb

SHA-256:
ae2796ca6ef86b04bfbc9ffdc4622e100e14f00c41b5898094cbe5f517656cbc

Scanner detections:
25 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 6:32:54 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.23268
1097

Agnitum Outpost
HackTool.Patcher
7.1.1

Avira AntiVirus
TR/Strictor.23268.1
7.11.124.148

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.1422

Bitdefender
Gen:Variant.Strictor.23268
1.0.20.165

Bkav FE
W32.Clod65c.Trojan
1.3.0.4613

Comodo Security
UnclassifiedMalware
17587

ESET NOD32
Win32/HackTool.Patcher (variant)
8.9274

Fortinet FortiGate
W32/CRACK.AE!tr
2/2/2014

F-Prot
W32/Backdoor2.DAPG
v6.4.7.1.166

F-Secure
Gen:Variant.Strictor.23268
11.2014-02-02_1

G Data
Gen:Variant.Strictor.23268
14.2.22

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.2.29

K7 AntiVirus
Riskware
13.175.10807

Malwarebytes
PUP.RiskwareTool.CK
v2014.02.02.06

McAfee
Artemis!EA12DF4F4A53
5600.7231

MicroWorld eScan
Gen:Variant.Strictor.23268
15.0.0.99

NANO AntiVirus
Trojan.Win32.Strictor.bkownq
0.28.0.57029

Norman
Troj_Generic.IRHZF
11.20140202

Panda Antivirus
Trj/CI.A
14.02.02.06

Sophos
Troj/Crack-AE
4.96

Total Defense
Win32/Cracker.CC
37.0.10498

Trend Micro House Call
TROJ_SPNR.0CE713
7.2.33

Trend Micro
TROJ_SPNR.0CE713
10.465.02

VIPRE Antivirus
Trojan.Win32.Generic
25284

File size:
18.7 MB (19,559,424 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\detong\office tab\patch.exe

File PE Metadata
Compilation timestamp:
2/19/2008 6:36:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
196608:VjD41HfXJDXwVKtgKYONSJlhan7G/41ofXJDXwVKtgKYONSJlhan7G1:Vv0XNnYdjTXNnYdh

Entry address:
0x10E7

Entry point:
6A, 00, E8, B4, 26, 00, 00, A3, E0, 93, 40, 00, E8, F4, 27, 00, 00, C7, 05, 0A, 9E, 40, 00, 94, 00, 00, 00, 68, 0A, 9E, 40, 00, E8, A2, 26, 00, 00, 83, 3D, 0E, 9E, 40, 00, 05, 72, 59, 68, 0E, 91, 40, 00, E8, 83, 26, 00, 00, 50, 68, 19, 91, 40, 00, 50, E8, 7D, 26, 00, 00, A3, 9E, 9E, 40, 00, 58, 68, 4C, 91, 40, 00, 50, E8, 6C, 26, 00, 00, A3, A6, 9E, 40, 00, 68, 2D, 91, 40, 00, E8, 57, 26, 00, 00, 68, 37, 91, 40, 00, 50, E8, 52, 26, 00, 00, A3, A2, 9E, 40, 00, 6A, 0A, 6A, 00, 6A, 00, FF, 35, E0, 93, 40, 00...
 
[+]

Entropy:
7.2197

Packer / compiler:
TASM / MASM

Code size:
25 KB (25,600 bytes)

The file patch.exe has been seen being distributed by the following URL.

Remove patch.exe - Powered by Reason Core Security