~dlC9FE.exe

Gamebox Setup

337 Technology Limited

The application ~dlC9FE.exe by 337 Technology Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from asset.337.com.
Publisher:
337 Technology Limited  (signed and verified)

Product:
Gamebox Setup

Description:
Setup

Version:
1.0.20.17288

MD5:
654754af7fffe0dd167c8e3831aea544

SHA-1:
444fa4d56a4cf4bdf0dfcde67df85c0bee625e20

SHA-256:
48ad98ffd508e9c45a4437497fbd7bd7b424b7c3892324109eef35a247f868ff

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/24/2024 3:47:24 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ELEX.337Technology.Installer (M)
16.2.26.3

File size:
19.5 MB (20,477,000 bytes)

Product version:
1.0.20.17288

Copyright:
Copyright (c) 2011-2014 337 Technology Limited

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\~dlc9fe.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/25/2012 6:04:18 AM

Valid to:
6/26/2015 6:04:18 AM

Subject:
CN=337 Technology Limited, O=337 Technology Limited, L=香港, S=香港, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A511A565DC1022CCD7BA41E2E418FE65

File PE Metadata
Compilation timestamp:
10/14/2014 9:02:06 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
393216:3n7oQgD7P4CrMBmyulipZlHDfC7etN5Xn86Omgsf33BC/0e:cQgXPrtI3QszX8Epf3O0e

Entry address:
0xF944

Entry point:
E8, 9E, 62, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 85, F6, 75, 13, E8, 7A, 27, 00, 00, 6A, 16, 5E, 89, 30, E8, 12, 35, 00, 00, 8B, C6, EB, 24, 68, 80, 00, 00, 00, FF, 75, 10, FF, 75, 0C, E8, 17, 00, 00, 00, 83, C4, 0C, 89, 06, 85, C0, 74, 04, 33, C0, EB, 07, E8, 4A, 27, 00, 00, 8B, 00, 5E, 5D, C3, 6A, 0C, 68, 68, EC, 42, 00, E8, B1, 39, 00, 00, 33, C9, 89, 4D, E4, 33, C0, 8B, 7D, 08, 85, FF, 0F, 95, C0, 85, C0, 75, 17, E8, 21, 27, 00, 00, C7, 00, 16, 00, 00, 00, E8, B8, 34, 00, 00, 33, C0...
 
[+]

Code size:
135.5 KB (138,752 bytes)

The file ~dlC9FE.exe has been seen being distributed by the following URL.

Remove ~dlC9FE.exe - Powered by Reason Core Security