RouterScan.exe threat report

MD5 d8faceb388b52af0f5be46c2977cb838
Latest seen 2024-08-26 23:03:37 (2 years ago)
First seen 2024-06-16 23:02:02 (2 years ago)
Size 2 MB
Publisher Stas'M Corp.

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Agent. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Agent
Recommended action
Scan and remove
Last analysis
2024-08-26 23:03:37 (2 years ago)
File hash
d8faceb388b52af0f5be46c2977cb838
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Agent.

Timeline

First seen 2024-06-16 23:02:02 (2 years ago); latest analysis 2024-08-26 23:03:37 (2 years ago).

Publisher context

Company metadata: Stas'M Corp.. Product metadata: Router Scan by Stas'M.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

RouterScan.exe is a Windows file recorded in the ThreatInfo database. It is associated with Router Scan by Stas'M. The reported company name is Stas'M Corp.. The current detection status is Trojan.Agent, based on the latest analysis from 2024-08-26 23:03:37 (2 years ago).

If RouterScan.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Agent.

Product Name: Router Scan by Stas'M
Company Name: Stas'M Corp.
MD5: d8faceb388b52af0f5be46c2977cb838
Size: 2 MB
First Published: 2024-06-16 23:02:02 (2 years ago)
Latest Published: 2024-08-26 23:03:37 (2 years ago)
Status: Trojan.Agent (on last analysis)
Analysis Date: 2024-08-26 23:03:37 (2 years ago)
RouterScan.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%sysdrive%\__reseau\_rso\routerscan
%sysdrive%\__reseau\_rso\routerscan\router scan v2.60.rar
%profile%\downloads
%profile%\downloads

ThreatInfo has observed RouterScan.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

50.0%
50.0%

The strongest geographic signal for this file is France with 50.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for RouterScan.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

RouterScan.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0020bbe8

PE Sections:

Name Size of data MD5
.text 2132480 ef1b9d45334ffd504d71103eeccb294d
.itext 7680 7152d8c721608d1e69e5ca5c1b9d3816
.data 59392 3c67b54dd6fa794f2d46401b0e6b0eaf
.bss 0 d41d8cd98f00b204e9800998ecf8427e
.idata 16384 22e5ab998c16a886fd6075bb6bf478c2
.didata 1024 e746df75c1f743a1bad06a423bf68d7b
.tls 0 d41d8cd98f00b204e9800998ecf8427e
.rdata 512 958180eaf2bf34b8da1f8698faf21fa6
.reloc 166912 5b4db33c00ec9795d9da8daeb0012e03
.rsrc 338432 ef85b211ad1f25f551c4c72075dedba3

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: