universal_keygen_generatorby anzaq.com.exe

WindowsApplication1

The executable universal_keygen_generatorby anzaq.com.exe has been detected as malware by 6 anti-virus scanners. The file has been seen being downloaded from doc-14-64-docs.googleusercontent.com.
Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
c7759d3e6a348f07261d4e7686a4b862

SHA-1:
dedec07dce73ba5393596457420b6ff3ef0257ef

SHA-256:
b752c585b1f5adbc5b8a71915ca20e45b2f9d514cc0169bc531dfa7717496db9

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
1/13/2025 3:50:17 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Vitro
160518-2

Emsisoft Anti-Malware
Win32.Virtob.Gen.12
11.5.0.6191

ESET NOD32
Win32/Virut.NBP virus
8.0.319.0

F-Prot
W32/Virut.AK!Generic
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.225.227.0

Norman
Win32.Virtob.Gen.12
28.05.2016 13:03:37

File size:
1.5 MB (1,552,384 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2012

Original file name:
Universal KeyGen Generator.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\universal_keygen_generatorby anzaq.com.exe

File PE Metadata
Compilation timestamp:
5/23/2018 1:28:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:WcRFYeUGsrGxsWZqdDO4f/BJla2HDO3wOnZLI2FI1lC6ADMx2wNFtY2VLwa4hiMu:luGuGKBqSGBe2b6AD2Nt3Lwa5M3BGB

Entry address:
0x180D48

Entry point:
80, EF, 00, 90, 83, EC, 30, 60, 83, C4, 24, 31, CD, 71, 00, 83, D0, 97, E8, ED, 00, 00, 00, 03, 5C, 24, FC, 2A, DB, 83, EB, 3C, F7, D6, 83, EB, 44, 0F, B7, 93, BC, 1C, 00, 00, 90, 81, D2, 2B, EE, FF, FF, 0F, 89, E4, FF, FF, FF, B5, 41, B0, 79, 8B, 94, 1A, 56, 2E, 00, 00, 66, 83, FA, 45, BF, 7A, 05, F3, 8F, 75, CE, FC, B4, DD, 90, 03, 93, 80, 1C, 00, 00, 66, 81, F2, 92, 5A, BE, 60, 57, 13, 06, F6, D5, F7, D0, 75, B4, F7, D6, B2, 1F, 87, CF, 68, 15, 19, A8, 7E, 81, C3, 80, 1C, 00, 00, FE, CC, 19, C7, E8, 99...
 
[+]

Entropy:
5.0460

Code size:
1.4 MB (1,426,432 bytes)

The file universal_keygen_generatorby anzaq.com.exe has been seen being distributed by the following URL.

Remove universal_keygen_generatorby anzaq.com.exe - Powered by Reason Core Security