3h3box_setup.exe

Xiamen xunrui network tech Co.,Ltd

The application 3h3box_setup.exe, “当游游戏盒为您精心准备近万款热门经典游戏。最快更新,最实用攻略,最真实评分。 ” by Xiamen xunrui network tech Co.,Ltd has been detected as a potentially unwanted program by 17 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from gamebox.3h3.com.
Publisher:
当游游戏盒子   (signed by Xiamen xunrui network tech Co.,Ltd)

Product:
当游游戏盒子

Description:
当游游戏盒为您精心准备近万款热门经典游戏。最快更新,最实用攻略,最真实评分。

Version:
1.0.1.232

MD5:
e41e8a4c424271c7c8ff314d09d6f164

SHA-1:
8cc12fdb8ee438a4872fd2005d725ca15de1b2a2

SHA-256:
66aa65d187f5a8faae6c88e4e13bcd04a377424959741157332100bef626a55f

Scanner detections:
17 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 10:17:54 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/WDJiange.9122040
8.3.2.2

Comodo Security
ApplicUnwnt
23504

ESET NOD32
Win32/Adware.WDJiange
10.12494

Fortinet FortiGate
Riskware/WDJiange
1/7/2016

G Data
Win32.Application.Agent.MT96F1
16.1.25

K7 AntiVirus
Adware
13.212.17709

Kaspersky
Trojan-Downloader.Win32.Refroso
14.0.0.852

Malwarebytes
PUP.Optional.ChinAd
v2016.01.07.04

McAfee
Artemis!E41E8A4C4242
5600.6527

NANO AntiVirus
Trojan.Win32.Adload.dpvxet
0.30.26.3947

Panda Antivirus
Generic Suspicious
16.01.07.04

Quick Heal
TrojanDownloader.Refroso.g8
1.16.14.00

Sophos
Generic PUA IM (PUA)
4.98

Vba32 AntiVirus
TrojanDownloader.Adload
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
44918

ViRobot
Trojan.Win32.S.Agent.9122040[h]
2014.3.20.0

Zillya! Antivirus
Downloader.Adload.Win32.18389
2.0.0.2484

File size:
8.7 MB (9,122,040 bytes)

Product version:
1.0.1.232

Copyright:
Copyright © 2012-2013 当游游戏盒子, Inc.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\3h3box_setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/11/2014 8:00:00 AM

Valid to:
7/11/2016 7:59:59 AM

Subject:
CN="Xiamen xunrui network tech Co.,Ltd", OU=技术部, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Xiamen xunrui network tech Co.,Ltd", L=Xiamen, S=Fujian, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3682911F02B732A9CE35DE5E8F3BC575

File PE Metadata
Compilation timestamp:
10/13/2013 4:19:32 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:Lztu4YND5y/IChtJhged1z3ZUdWlt8Dvh6dnLVW6EAHZgV:LpzE5ywChzhg6LMJh6d5bD8

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9493

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file 3h3box_setup.exe has been seen being distributed by the following URL.

http://gamebox.3h3.com/3h3box_Setup.exe

Remove 3h3box_setup.exe - Powered by Reason Core Security