tcheck.exe

The executable tcheck.exe has been detected as malware by 12 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from eos.teb.org.tr.
MD5:
d7779e59201a83e88bd31f73aaaeda5d

SHA-1:
6d84488a525172ad3cba2e17b3a3fe6f4b6e5442

SHA-256:
907bc1edfe88dffd47c6d2909f0e02e77b2fbfa6d8935f9061747164b8632e54

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
12/27/2024 2:41:17 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11827941
707

Agnitum Outpost
Trojan.Rogue
7.1.1

Bitdefender
Trojan.Generic.11827941
1.0.20.295

Comodo Security
TrojWare.Win32.TrojanDownloader.Delf.gen
18767

Emsisoft Anti-Malware
Trojan.Generic.11827941
8.15.02.28.12

F-Secure
Trojan.Generic.11827941
11.2015-28-02_7

G Data
Trojan.Generic.11827941
15.2.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.7.8.0

K7 AntiVirus
Riskware
13.183.13642

MicroWorld eScan
Trojan.Generic.11827941
16.0.0.177

nProtect
Trojan.Generic.11827941
14.10.10.01

Trend Micro House Call
TROJ_GEN.R02SH09IU14
7.2.59

File size:
1.4 MB (1,496,064 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\tebeos2010\tcheck.exe

File PE Metadata
Compilation timestamp:
4/18/2014 4:34:48 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:rRWubL2Uua6oSxQs8MBAhBsiuK4p/x9b6RsLxT9kYhfx0H8Vaanwz+dT4T:11Kiuvp/uRsllhfxoawzQs

Entry address:
0x13D1F4

Entry point:
55, 8B, EC, B9, 05, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, B8, 61, 53, 00, E8, 9C, E9, EC, FF, 33, C0, 55, 68, 27, D3, 53, 00, 64, FF, 30, 64, 89, 20, 6A, 00, E8, 3F, E7, ED, FF, 33, C0, 55, 68, A5, D2, 53, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E8, 33, C0, E8, E7, 76, EC, FF, 8B, 45, E8, 8D, 55, EC, E8, 00, 50, ED, FF, 8B, 55, EC, B8, 9C, 82, 54, 00, E8, E7, AB, EC, FF, 8D, 45, DC, B9, 44, D3, 53, 00, 8B, 15, 9C, 82, 54, 00, E8, A0, B0, EC, FF, 8B, 55, DC, 8D, 45, E0, B9, 00, 00, 00, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.2 MB (1,291,776 bytes)

The file tcheck.exe has been seen being distributed by the following URL.

Remove tcheck.exe - Powered by Reason Core Security