trojan.exe

The executable trojan.exe has been detected as malware by 22 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘8515eb34d8f9de5af815466e9715b3e5’.
MD5:
fd0e19e788e75de9db8a4c69ddd25775

SHA-1:
a9301589767ff93ecccd3eec08c9c4fd22c28c09

SHA-256:
fc260c14318e24e4a4ae8044aded8145933c3878727ab0c5363345550ba99372

Scanner detections:
22 / 68

Status:
Malware

Analysis date:
4/1/2025 8:08:44 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Generic
2013.10.08

Avira AntiVirus
TR/ATRAPS.Gen
7.11.106.56

AVG
MSIL
2018.0.2438

Bitdefender
Gen:Variant.Barys.7801
1.0.20.370

Comodo Security
TrojWare.MSIL.Bladabindi.KX
17068

Dr.Web
Trojan.DownLoader10.20172
9.0.1.074

Emsisoft Anti-Malware
Gen:Variant.Barys.7801
8.17.03.15.05

ESET NOD32
MSIL/Bladabindi (variant)
11.8887

Fortinet FortiGate
MSIL/Agent.PPV!tr
3/15/2017

F-Secure
Gen:Variant.Barys.7801
11.2017-15-03_4

G Data
Gen:Variant.Barys.7801
17.3.22

IKARUS anti.virus
Backdoor.MSIL
t3scan.2.0.127

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-1314

Malwarebytes
Trojan.MSIL
v2017.03.15.05

McAfee
BackDoor-FBIB!FD0E19E788E7
5600.6094

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi.B
1.163.1557.0

MicroWorld eScan
Gen:Variant.Barys.7801
18.0.0.222

Norman
Bladabindi.D
11.20170315

Panda Antivirus
Generic Malware
17.03.15.05

Quick Heal
Trojan.Bladabindi.B3
3.17.12.00

Trend Micro House Call
TROJ_GEN.R072C0DJ713
7.2.74

Trend Micro
TROJ_GEN.R072C0DJ713
10.465.15

File size:
28.5 KB (29,184 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\trojan.exe

File PE Metadata
Compilation timestamp:
10/3/2013 4:09:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x891E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.5462

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
26.5 KB (27,136 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
8515eb34d8f9de5af815466e9715b3e5

Command:
"C:\users\{user}\appdata\roaming\trojan.exe"..


Remove trojan.exe - Powered by Reason Core Security