631b.exe

Tixati Software Inc.

The executable 631b.exe has been detected as malware by 18 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Ejtion’.
Publisher:
Tri mati  (signed by Tixati Software Inc.)

Product:
Tri mati

Version:
2.08.0005

MD5:
30d6a4866090c496c5d9756aa8f22e21

SHA-1:
a53616d38a5c3bf725511e27280ee6f62309bf91

SHA-256:
9803549f709dc278dab306d129685d03663cbcc75a4816bae9588608165caf2c

Scanner detections:
18 / 68

Status:
Malware

Analysis date:
11/16/2024 5:44:44 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.55911
213

AhnLab V3 Security
Trojan/Win32.Miuref
2015.09.03

Arcabit
Trojan.Symmi.DDA67
1.0.0.425

avast!
Win32:Malware-gen
2014.9-160705

AVG
Generic_vb
2017.0.2691

Bitdefender
Gen:Variant.Symmi.55911
1.0.20.935

Dr.Web
Trojan.Siggen6.23087
9.0.1.0187

Emsisoft Anti-Malware
Gen:Variant.Symmi.55911
8.16.07.05.02

ESET NOD32
Win32/Injector.CHXK (variant)
10.12194

Fortinet FortiGate
W32/Injector.CHTF!tr
7/5/2016

F-Secure
Gen:Variant.Symmi.55911
11.2016-05-07_3

G Data
Gen:Variant.Symmi.55911
16.7.25

IKARUS anti.virus
Trojan.Win32.Injector
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.2017100

Kaspersky
Trojan-Dropper.Win32.VB
14.0.0.-48

Malwarebytes
Trojan.VBCrypt
v2016.07.05.02

MicroWorld eScan
Gen:Variant.Symmi.55911
17.0.0.561

Panda Antivirus
Trj/Genetic.gen
16.07.05.02

File size:
143.3 KB (146,720 bytes)

Product version:
2.08.0005

Original file name:
Tri mati.exe

File type:
Executable application (Win32 EXE)

Language:
Czech (Czech Republic)

Common path:
C:\users\{user}\appdata\local\ejtion\631b.exe

Digital Signature
Authority:
StartCom Ltd.

Valid from:
9/3/2014 6:41:38 AM

Valid to:
9/4/2016 4:25:38 AM

Subject:
E=support@tixati.com, CN=Tixati Software Inc., O=Tixati Software Inc., L=Toronto, S=Ontario, C=CA, Description=i5lM5uso21UxjYzI

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
0FFE

File PE Metadata
Compilation timestamp:
3/15/2015 5:22:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:uNuweTEIzjp/gce/hN7mJqGJ1/Zn547WI:6uNTzc/TmJqQ1FCaI

Entry address:
0x12F0

Entry point:
68, 88, 45, 41, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, AC, 63, 43, F6, B7, 3E, AC, 44, 91, DF, 84, 73, 2E, 48, CE, D8, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, CC, 02, 83, 00, 00, 00, 42, 65, 74, 72, 69, 65, 62, 73, 61, 75, 73, 66, 61, 68, 72, 74, 33, 00, CC, 02, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 04, 7E, D1, 69, 91, 6A, F0, CC, 43, 8D, 6A, 8F, E1, A3, 9B, 01, F3, ED, BB, D7, DF, 06, B8, B6, 46, BA, 6B, 22, 4B, AF, 1B, F7, C4, 3A, 4F, AD...
 
[+]

Entropy:
7.0350

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
120 KB (122,880 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Ejtion

Command:
C:\users\{user}\appdata\local\ejtion\631b.exe


Remove 631b.exe - Powered by Reason Core Security