scandsk.exe

The executable scandsk.exe has been detected as malware by 12 anti-virus scanners. The file has been seen being downloaded from www2.rtu1yca135.2waky.com.
MD5:
94b002265eb1fed9749dcef5d6acfbd1

SHA-1:
158a99bc1c8a6dee46b7266dbc57283060c01d65

SHA-256:
750afdb1194508a29aac7a63e18995f913c4dfcfc41fc79e45f1ae23463600cd

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
11/25/2024 10:51:42 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Simda-IS [Trj]
160518-2

Dr.Web
Trojan.Rodricter.21
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Kazy.82792
11.5.0.6191

ESET NOD32
Win32/Kryptik.AMLP trojan
8.0.319.0

F-Prot
W32/Simda.T.gen
4.6.5.141

F-Secure
Variant.Kazy.82792
5.15.96

Kaspersky
Backdoor.Win32.Simda
15.0.0.562

McAfee
Trojan.Generic FakeAlert.ma
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.219.2198.0

Norman
Gen:Variant.Kazy.82792
19.05.2016 05:17:13

Sophos
Virus 'Mal/EncpkLEE-B'
5.23

VIPRE Antivirus
Threat.4782630
48772

File size:
715.5 KB (732,685 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\scandsk.exe

File PE Metadata
Compilation timestamp:
12/29/2007 3:06:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:L6H4lgph9uw8TXJelx1bW0/Ae5mwLaENaNkhFyx0xlRJXvHvoVtC6oDF5a:L6KgkwiXIlRYe5LaENa4o0RJXvPozChe

Entry address:
0xA42F0

Entry point:
55, 8B, EC, 81, EC, 68, 01, 00, 00, BA, 5A, 90, 00, 00, 8B, CD, 85, CA, 77, 3E, 2B, D2, B9, 39, 50, 00, 00, 23, D1, 83, E1, 00, FC, 83, E1, 00, 81, D9, EA, 88, 00, 00, C7, 85, AC, FE, FF, FF, 00, 00, 00, 00, 8B, D1, FF, 8D, AC, FE, FF, FF, C7, 85, E0, FE, FF, FF, CE, 9A, 00, 00, F7, 95, E0, FE, FF, FF, B9, DA, 36, 00, 00, FC, 53, C7, 85, 0C, FF, FF, FF, A1, 1E, 00, 00, 81, AD, 0C, FF, FF, FF, D5, 24, 00, 00, C7, 45, B8, 0C, 4B, 00, 00, BA, 4A, 24, 00, 00, EB, 42, 8B, 9D, E0, FE, FF, FF, 8B, 4D, B8, FC, BB...
 
[+]

Entropy:
5.4893

Developed / compiled with:
Microsoft Visual C++

Code size:
28 KB (28,672 bytes)

The file scandsk.exe has been seen being distributed by the following URL.

Remove scandsk.exe - Powered by Reason Core Security