y0kkzacrgmhk.exe

PARTNER SOLUTIONS

The application y0kkzacrgmhk.exe by PARTNER SOLUTIONS has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
PARTNER SOLUTIONS  (signed and verified)

MD5:
0f772c806baa0b17683d427e2f223c31

SHA-1:
c79ff08375b25f9f797277c9d20408bf94323812

SHA-256:
39deb1820412533948032ec2cb0bbf9c01e89f99d43b78c3921b9d3eef82d46a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 3:44:11 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Somoto (M)
17.3.8.23

File size:
1 MB (1,074,720 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\y0kkzacrgmhk.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/8/2015 6:00:00 AM

Valid to:
9/8/2016 5:59:59 AM

Subject:
CN="""PARTNER SOLUTIONS"", OOO", O="""PARTNER SOLUTIONS"", OOO", STREET="Carla Faberge, 8-B, office 408", L=Saint-Petersburg, S=Saint-Petersburg, PostalCode=195112, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0080369869C233B6CEAE812635F74AEA4B

File PE Metadata
Compilation timestamp:
6/20/1992 4:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x65C08

Entry point:
90, 90, 90, BE, 04, 00, 00, 00, 90, 8D, 05, E4, E5, 46, 00, C7, 00, 77, 65, 33, 48, 68, E4, E5, 46, 00, E8, C1, FD, FF, FF, 4E, 75, E6, 90, EB, 08, 90, 22, 75, 05, 90, 90, 90, 90, 68, 90, 5C, 46, 00, E9, F5, C5, 04, 00, 0F, C8, 40, 85, C4, 66, 3B, FD, 0F, C8, F9, F8, F7, D8, F9, 66, F7, C6, 8E, 0D, 80, FE, E3, 33, D8, F5, 03, F8, E9, 4C, B3, 06, 00, 8B, 4C, 25, 00, 66, D3, E0, 66, 1D, CD, 45, 66, 8B, 44, 25, 04, 8D, AD, 06, 00, 00, 00, F5, 36, 66, 89, 01, E9, 21, 8E, 04, 00, 48, 33, D8, 03, F8, E9, 7E, B9...
 
[+]

Code size:
949.5 KB (972,288 bytes)

Remove y0kkzacrgmhk.exe - Powered by Reason Core Security