62684.exe

Install

Shan Feng

The application 62684.exe by Shan Feng has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘x9NkpZ34c933a9pZ’.
Publisher:
Develop Ltd.  (signed by Shan Feng)

Product:
Install

Version:
4,2,4,7

MD5:
1a4fb2380048b7d334004942a6691e5d

SHA-1:
694729ff737974715e5c8a969b26c70e78e0f1db

SHA-256:
357f99dbeeacfd19c091d714f29772a7caa67694dcd44149f3ee276cbd69dbe1

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 3:56:19 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Mutabaha.1252
9.0.1.05190

McAfee
Trojan.Artemis!1A4FB2380048
18.0.204.0

Reason Heuristics
PUP.Elex.ShanFeng.Installer (M)
16.7.8.1

File size:
350.3 KB (358,680 bytes)

Product version:
2,7,3,1

Copyright:
(C) Develop Ltd.

Trademarks:
(C) Develop Ltd.

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\62684.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
2/4/2016 2:00:00 AM

Valid to:
2/4/2017 1:59:59 AM

Subject:
CN=Shan Feng, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
35000007A9C98043CA459BAC1DA3B29C

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:F4Ih+pwoOEhw6PDUBZqLhEEqDxhgHcxX3HpeTFhBgxXqwfohgjGmpdYh+Cu3:KI0pgEhw6y3Egxh2cxXZeTr6YwfohgCM

Entry address:
0x13B3

Entry point:
55, 89, E5, 83, EC, 08, C7, 05, F8, 7A, 45, 00, 01, 00, 00, 00, E8, 84, 74, 04, 00, C9, E9, 66, FD, FF, FF, 55, 89, E5, 83, EC, 08, C7, 05, F8, 7A, 45, 00, 00, 00, 00, 00, E8, 69, 74, 04, 00, C9, E9, 4B, FD, FF, FF, 90, 90, 90, 66, 90, 66, 90, 55, 89, E5, 83, EC, 18, A1, A8, D9, 44, 00, 85, C0, 74, 3C, C7, 04, 24, 00, E0, 44, 00, FF, 15, 00, 83, 45, 00, 83, EC, 04, 85, C0, BA, 00, 00, 00, 00, 74, 16, C7, 44, 24, 04, 0E, E0, 44, 00, 89, 04, 24, FF, 15, 04, 83, 45, 00, 83, EC, 08, 89, C2, 85, D2, 74, 09, C7...
 
[+]

Code size:
293 KB (300,032 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
x9NkpZ34c933a9pZ

Command:
"C:\users\{user}\appdata\local\temp\{random}.tmp\skipreg


Remove 62684.exe - Powered by Reason Core Security