security_cleaner.exe

The executable security_cleaner.exe has been detected as malware by 25 anti-virus scanners. The file has been seen being downloaded from wtwgmeqgq.servebeer.com.
MD5:
546218a6b8ad8d62dc02bdb379ab77c9

SHA-1:
016590a41b6293d4e747c12d5d03d82089aff48f

SHA-256:
71e82c0c3cae1b263d1f1213de43b7de15c5c135e9087f9c7166b4486b002ce3

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
12/28/2024 1:38:22 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.CProtection
2013.05.19

Avira AntiVirus
TR/Kazy.170856.6
7.11.79.62

avast!
Win32:Kryptik-LOY [Trj]
2014.9-160217

AVG
Generic33.E
2017.0.2830

Bitdefender
Gen:Variant.Kazy.170822
1.0.20.240

Dr.Web
Trojan.Fakealert.20509
9.0.1.048

Emsisoft Anti-Malware
Gen:Variant.Kazy.170856
8.16.02.17.02

ESET NOD32
Win32/Kryptik.BAFN (variant)
10.8348

Fortinet FortiGate
W32/CProtection.QTJ!tr
2/17/2016

F-Secure
Gen:Variant.Kazy.170856
11.2016-17-02_4

G Data
Gen:Variant.Kazy.170822
16.2.22

IKARUS anti.virus
Trojan-PWS.Win32.Zbot
t3scan.2.0.0.0

K7 AntiVirus
Riskware
13.167.8711

Kaspersky
Trojan-FakeAV.Win32.CProtection
14.0.0.647

Malwarebytes
Rogue.Agent
v2016.02.17.02

McAfee
RDN/Generic FakeAlert!cm
5600.6486

Microsoft Security Essentials
Trojan:Win32/Rimod
1.163.1557.0

MicroWorld eScan
Gen:Variant.Kazy.170822
17.0.0.144

Norman
Ransom.FLP
11.20160217

Panda Antivirus
Trj/Genetic.gen
16.02.17.02

Sophos
Troj/FakeAV-GPB
4.89

SUPERAntiSpyware
Trojan.Agent/Gen-Dropper
9318

Trend Micro House Call
TROJ_GEN.RCBCCE7
7.2.48

Trend Micro
TROJ_GEN.RCBCCE7
10.465.17

VIPRE Antivirus
Trojan.Win32.Fakeav.gnw
17876

File size:
237 KB (242,688 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\security_cleaner.exe

File PE Metadata
Compilation timestamp:
12/23/2012 2:24:14 PM

OS version:
8.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
30.22

CTPH (ssdeep):
6144:TF1JmS8/LD4c8Dd1fAOv0II3LFkNxE5EpT/i:D6/Lb851fAE0II7FkN9Z/i

Entry address:
0x15E2

Entry point:
55, 8B, EC, 81, EC, 38, 01, 00, 00, 66, 0F, BE, 85, CF, FE, FF, FF, 53, 56, 57, 68, 64, F2, 41, 00, C7, 45, F4, 44, E9, 41, 00, 68, F7, 01, 00, 00, C7, 45, F4, 1C, EE, 41, 00, C7, 45, E8, 04, 01, 00, 00, 66, A3, AA, E8, 41, 00, FF, 15, A4, E0, 49, 00, BE, FC, F0, 41, 00, 8D, 7D, CC, A5, A5, A5, 66, A5, BE, 0C, F1, 41, 00, 8D, 7D, E0, 8D, 45, E0, A5, 50, 8D, 45, CC, 50, 66, A5, FF, 15, 8C, E0, 49, 00, 68, 14, F1, 41, 00, 68, 18, F1, 41, 00, FF, 15, 90, E0, 49, 00, 68, 00, 00, 10, 02, 33, DB, 53, 53, 68, 24...
 
[+]

Entropy:
7.4662

Developed / compiled with:
Microsoft Visual C++

Code size:
35.5 KB (36,352 bytes)

The file security_cleaner.exe has been seen being distributed by the following URL.

Remove security_cleaner.exe - Powered by Reason Core Security