chlenix.exe

uploader

The executable chlenix.exe has been detected as malware by 26 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from rghost.net.
Product:
uploader

Version:
1.0.0.0

MD5:
0aa2d8d0813294952c07b3f2c189dc12

SHA-1:
22bb67da8f5f61df24ea33d017ccc9236031797f

SHA-256:
e56a1f2078f3a049a9e118e5a0420f7d52b60de175503434bd935cc993465a2d

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
12/26/2024 5:17:59 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2996995
216

AegisLab AV Signature
Gen.Variant.Graftor!c
2.1.4+

Avira AntiVirus
TR/Crypt.TPM.Gen
8.3.3.4

Arcabit
Trojan.Generic.D2DBB03
1.0.0.672

avast!
Win32:Malware-gen
2014.9-160703

AVG
Generic14_c
2017.0.2694

Bitdefender
Trojan.GenericKD.2996995
1.0.20.925

Bkav FE
HW32.Packed
1.3.0.7744

Comodo Security
UnclassifiedMalware
24838

Emsisoft Anti-Malware
Trojan.GenericKD.2996995
8.16.07.03.11

ESET NOD32
Win32/Packed.Themida suspicious (variant)
10.13358

Fortinet FortiGate
PossibleThreat
7/3/2016

F-Secure
Trojan.GenericKD.2996995
11.2016-03-07_1

G Data
Trojan.GenericKD.2996995
16.7.25

K7 AntiVirus
Trojan
13.222.19349

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.-37

Malwarebytes
Trojan.MalPack.Themida
v2016.07.03.11

McAfee
Artemis!0AA2D8D08132
5600.6350

MicroWorld eScan
Trojan.GenericKD.2996995
17.0.0.555

NANO AntiVirus
Trojan.Win32.TPM.dzopwb
1.0.30.8000

nProtect
Trojan.GenericKD.2996995
16.04.19.01

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16701

Sophos
Generic PUA CC (PUA)
4.98

Trend Micro
TROJ_GEN.R01TC0EAG16
10.465.03

VIPRE Antivirus
Trojan.Win32.Generic
48750

ViRobot
Trojan.Win32.Z.Agent.1610240.C[h]
2014.3.20.0

File size:
1.5 MB (1,610,240 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
uploader.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\chlenix.exe

File PE Metadata
Compilation timestamp:
12/24/2015 10:41:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:JdOeIhehBkVOvklI1EeSJGkq7YPNdvja4kdgKf//Z0f7vl55KGNVm5/BaW/RCJ:JdA4kV72L7ANta5//Z4tZNVGMW54

Entry address:
0x40E000

Entry point:
EB, 08, 0F, 70, 18, 00, 00, 00, 00, 00, E9, 00, 20, 00, 00, 54, 41, 47, 47, 00, 20, 00, 00, 1D, 1B, 00, 00, 01, 00, 30, 82, 1B, 19, 06, 09, 2A, 86, 48, 86, F7, 0D, 01, 07, 02, A0, 82, 1B, 0A, 30, 82, 1B, 06, 02, 01, 01, 31, 09, 30, 07, 06, 05, 2B, 0E, 03, 02, 1A, 30, 82, 0F, 20, 06, 09, 2A, 86, 48, 86, F7, 0D, 01, 07, 01, A0, 82, 0F, 11, 04, 82, 0F, 0D, D0, 00, 01, 00, 01, C1, B1, A1, 02, 00, 03, 00, 07, 00, 00, 00, 26, 00, 00, 00, 01, 00, F2, A0, 80, 06, 13, 91, 13, 02, 17, 10, 74, 64, 07, 1F, 08, AF, 00...
 
[+]

Entropy:
7.9437  (probably packed)

Code size:
17.5 KB (17,920 bytes)

The file chlenix.exe has been seen being distributed by the following URL.

Remove chlenix.exe - Powered by Reason Core Security