Gridinsoft Logo
File Icon

The BDY-KT_2024-KG.exe File Analysis

Technical Analysis

File Name BDY-KT_2024-KG.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
SSDEEP Hash
6144:BZmKB24o/FpybjPuRS7AFQ/NpiIjPKmXkPv50iYDsYjuDqg2B+5odTpcnTrIxMcp:BkFFkPWFQ/fPjCP7KA9Vo/6TLo
Scanner Version 1.0.216.174
Database Version 2025-05-20 10:00:28 UTC

Suspicious File Detected

Detected by 39 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
55%
Detection Rate
386,048
File Size (bytes)
39/71
Engines Detected
2025-05-20
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
15496ac57fa6a9399a02c09e9c7ca1ee
SHA1
98f0165735b5b190ce975824a89232b3449d8607
SHA256
add444f8daae234c00f3dd712e2ce7460b772d29be32c569dbddac63541e1307
SHA512
8049b6764fbbf2ee674158adb38fbd4bf8d49752751e87f64411b98c814a93e47a52284fb9bab893e7bf49a8973321788c71c23d1a241245b6cf91a7404b40eb
ImpHash
df73e4c0e7dfda71a2a0a95bb98a724a

Security Engines with Detections (39 of 71)

Bkav
W32.AIDetectMalware Malicious
Lionic
Hacktool.Win32.Keygen.3!c Malicious
Elastic
malicious (moderate confidence) Malicious
MicroWorld-eScan
Application.Generic.3906415 Malicious
CTX
exe.hacktool.keygen Malicious
CAT-QuickHeal
Hacktool.Keygen Malicious
Skyhigh
BehavesLike.Win32.Generic.fc Malicious
McAfee
Artemis!15496AC57FA6 Malicious
Cylance
Unsafe Malicious
Sangfor
Hacktool.Win32.Keygen.Vcby Malicious
CrowdStrike
win/malicious_confidence_60% (D) Malicious
K7GW
Trojan ( 0051918e1 ) Malicious
K7AntiVirus
Trojan ( 0051918e1 ) Malicious
Symantec
ML.Attribute.HighConfidence Malicious
APEX
Malicious Malicious
Paloalto
generic.ml Malicious
BitDefender
Application.Generic.3906415 Malicious
Emsisoft
Application.Generic.3906415 (B) Malicious
VIPRE
Application.Generic.3906415 Malicious
McAfeeD
Real Protect-LS!15496AC57FA6 Malicious
SentinelOne
Static AI - Suspicious PE Malicious
Trapmine
malicious.high.ml.score Malicious
Sophos
Generic Reputation PUA (PUA) Malicious
Webroot
Win.Hacktool.Gen Malicious
Google
Detected Malicious
Varist
W32/ABApplication.SZGK-8226 Malicious
Antiy-AVL
HackTool/Win32.KeyGen Malicious
Microsoft
HackTool:Win32/Keygen Malicious
Arcabit
Application.Generic.D3B9B6F Malicious
GData
Application.Generic.3906415 Malicious
Cynet
Malicious (score: 100) Malicious
VBA32
BScope.Trojan.Click Malicious
ALYac
Application.Generic.3906415 Malicious
Malwarebytes
MachineLearning/Anomalous.100% Malicious
Panda
Trj/CI.A Malicious
Rising
Hacktool.Keygen!8.B29 (CLOUD) Malicious
MaxSecure
Trojan.Malware.848626.susgen Malicious
Fortinet
W32/PossibleThreat Malicious
DeepInstinct
MALICIOUS Malicious
32 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 9e3850bd04540b3e2ad195dc360196f2
Fuzzy: 5d7093192eeacc410b8149d64cebc26e
dHash: 0f2359e4f0693b0f
Image Base 0x00400000
Entry Point 0x004be3e0
Compilation Time 2024-11-21 00:23:36
Checksum 0x00000000 (Actual: 0x0006732f)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
Digital Signature No valid SignedData structure was found.
Imports 4 libraries
COMDLG32, KERNEL32, msvcrt, USER32
Exports 0 functions
Resources 9 Resources
Sections 3 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
UPX0 0x00001000 409,600 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
UPX1 0x00065000 368,640 bytes 366,592 bytes 7.93 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 04CA8A688ABC664417A2995568628E12
.rsrc 0x000bf000 20,480 bytes 18,944 bytes 2.50 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE DAD638D863D1079B98F779686A7F1173
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 9 (235,899 bytes)
Resource Type Count Total Size Percentage
DLL 1 34,308 bytes
14.5%
MODULE 1 40,430 bytes
17.1%
RT_BITMAP 2 142,592 bytes
60.4%
RT_ICON 1 16,936 bytes
7.2%
RT_DIALOG 2 946 bytes
0.4%
RT_GROUP_ICON 1 20 bytes
0%
RT_MANIFEST 1 667 bytes
0.3%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
39 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware