csrss.exe

The executable csrss.exe has been detected as malware by 5 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from admin.wbindex.cn.
Version:
1, 1, 16, 41607

MD5:
e934bf46f2a748a89ed40cb3618e5b37

SHA-1:
f2295a300816a688ce4465deed87d083f307972d

SHA-256:
1917320d62fbc5d4080285524bd8d59676a0a35065bae99b843c946e3ed8afd7

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
11/5/2024 2:19:31 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160518-2

Emsisoft Anti-Malware
Gen:Variant.Zusy.193122
16.07.21

ESET NOD32
Win32/Agent.XWK trojan
8.0.319.0

Kaspersky
Trojan-Dropper.Win32.Injector
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.225.1925.0

File size:
455.6 KB (466,496 bytes)

Product version:
1, 1, 16, 41607

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\csrss.exe

File PE Metadata
Compilation timestamp:
2/14/2014 7:49:51 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:KkX1ocjvqT7mLsMSQC7XhfGNsjUiW9wA8P:KkX1ocmT7UsMS9Q0s94

Entry address:
0xEEA8

Entry point:
E8, B2, 72, 00, 00, E9, A4, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, D0, 89, 42, 00, 89, 0D, CC, 89, 42, 00, 89, 15, C8, 89, 42, 00, 89, 1D, C4, 89, 42, 00, 89, 35, C0, 89, 42, 00, 89, 3D, BC, 89, 42, 00, 66, 8C, 15, E8, 89, 42, 00, 66, 8C, 0D, DC, 89, 42, 00, 66, 8C, 1D, B8, 89, 42, 00, 66, 8C, 05, B4, 89, 42, 00, 66, 8C, 25, B0, 89, 42, 00, 66, 8C, 2D, AC, 89, 42, 00, 9C, 8F, 05, E0, 89, 42, 00, 8B, 45, 00, A3, D4, 89, 42, 00, 8B, 45, 04, A3, D8, 89, 42, 00, 8D, 45, 08, A3, E4, 89, 42...
 
[+]

Entropy:
7.7356  (probably packed)

Code size:
114 KB (116,736 bytes)

The file csrss.exe has been seen being distributed by the following URL.

Remove csrss.exe - Powered by Reason Core Security