chrlike.exe

Sice Xing

The application chrlike.exe by Sice Xing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Sice Xing  (signed and verified)

MD5:
2ff4b5acafe2bd0680477185c90b2165

SHA-1:
2eb72c2b127873e79c6779e0a50c1d0cebe9525b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 2:43:23 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex (M)
16.8.22.5

File size:
477.4 KB (488,832 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\tools\chrlike.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
6/27/2016 3:00:00 AM

Valid to:
4/2/2017 2:59:59 AM

Subject:
CN=Sice Xing, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1ED032BEEC009922FC8C2EE527491299

File PE Metadata
Compilation timestamp:
6/28/2016 4:23:25 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
6144:lLIFKxNeKVxbXOUaQUlS+6IuYIRB8ZcPx6VHUjpUIf/4oTCjqnln2nB:lLcw5eULUl8YW8j01UU5THsnB

Entry address:
0x37DE8

Entry point:
8E, 1A, 72, 00, 00, BD, D1, A7, 99, AB, 85, 57, F8, C7, 14, 00, ED, 19, 8E, 16, D5, 59, 00, 00, 00, 00, 23, 2D, 03, 0A, 0A, D2, 83, 09, 2B, 80, 9F, DF, 1C, A9, 55, 99, 88, 9A, 01, AC, AE, A6, 94, BD, A0, 8D, A3, AB, DA, 14, 8A, 67, B7, 80, B4, 18, A9, A6, 99, A6, 93, BB, A3, AB, AE, 09, 02, AB, 4F, 00, 00, 00, 00, D4, 22, 70, 76, 59, 38, 70, 5D, 0A, 30, 03, F3, 5A, D7, BC, F0, E5, 77, 13, 00, 41, 99, 04, AE, 2C, 9A, 93, 3F, 8E, A3, AB, AE, A6, EB, 11, 8E, 16, FF, 00, 00, 00, 00, A6, B9, 22, 38, AB, 64, 00...
 
[+]

Code size:
351.5 KB (359,936 bytes)

Remove chrlike.exe - Powered by Reason Core Security