disprun.exe

Taiming Li

The application disprun.exe by Taiming Li has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
xgdr  (signed by Taiming Li)

Product:
xgdr

Version:
7,3,7601,1407

MD5:
ace53cb9343f078c97b979fa2903ff40

SHA-1:
beea1f792ee589439e10bea90e33edf3d605d8c9

SHA-256:
b05e16e766b9b00624c9bbcb78314681ac4e9797358b1476f8fb68d56e07d88d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 4:57:24 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ELEX.TaimingL (M)
16.6.6.10

File size:
523.6 KB (536,216 bytes)

Product version:
7,3,7601,1407

Copyright:
Copyright (C) 2014

Original file name:
DoDispat.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\{b7f41433-adc5-43ea-98c2-bd74b16e9f56}\disprun.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
12/7/2014 7:00:00 PM

Valid to:
12/16/2015 7:00:00 AM

Subject:
CN=Taiming Li, O=Taiming Li, L=Shennongjia, S=Hubei, C=CN

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0895B92BC339D60B3B6DD4375EF2BA08

File PE Metadata
Compilation timestamp:
12/11/2014 2:22:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:BqJfgCgCqzsfs4nP2x185oW+09b45lBA+ObuDGCDVRzOiE8ECMRM:UgCxqzsfZn+385o6yEuDG4XaiAvRM

Entry address:
0x37237

Entry point:
E8, EB, BE, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 0C, 53, 85, C0, 74, 52, 8B, 54, 24, 08, 33, DB, 8A, 5C, 24, 0C, F7, C2, 03, 00, 00, 00, 74, 16, 8A, 0A, 83, C2, 01, 32, CB, 74, 72, 83, E8, 01, 74, 32, F7, C2, 03, 00, 00, 00, 75, EA, 83, E8, 04, 72, 12, 57, 8B, FB, C1, E3, 08, 03, DF, 8B, FB, C1, E3, 10, 03, DF, EB, 1B, 5F, 83, C0, 04, 74, 0E, 8A, 0A, 83, C2, 01, 32, CB, 74, 40, 83, E8, 01, 75, F2, 5B, C3, 83, E8, 04, 72, E5, 8B, 0A, 33, CB, BF...
 
[+]

Entropy:
6.0699

Code size:
344.5 KB (352,768 bytes)

Remove disprun.exe - Powered by Reason Core Security