rp generator.exe

WindowsApplication1

The executable rp generator.exe has been detected as malware by 3 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download686.mediafire.com.
Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
40fd56d0809eec2c04a5e359a2014492

SHA-1:
b76bf1650e91d3daa78e22f86399dca867f5edb3

SHA-256:
eaf1f15a0a776b0da7e450103dcf5381e7b900507a5950c3b96a650c669d2fe4

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
12/26/2024 6:43:05 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Spy.Agent.OKR
7.11.142.108

ESET NOD32
MSIL/PSW.Agent.OKR
10.9661

Qihoo 360 Security
Win32/Trojan.PSW.45c
1.0.0.1015

File size:
24 KB (24,576 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
WindowsApplication1.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
4/5/2014 2:18:19 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:Dfk07oETEomI8NjhMj/WeGvrlAKbWhozLk24jXP9Iqzb3XEYenTp6NngPPazPTrF:4077NiTMCekAr62XPtzBgkTr

Entry address:
0x6ADE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
19 KB (19,456 bytes)

The file rp generator.exe has been seen being distributed by the following URL.

Remove rp generator.exe - Powered by Reason Core Security