fxbox_crk.exe

The application fxbox_crk.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from s10164.chomikuj.pl.
MD5:
3c45bbed5dfde09f2475cc66e4984bba

SHA-1:
c7fe4a2e268af6b85fd4c304212ce073fbbd30b9

SHA-256:
d4844052be1a60bc031c72ff14f8e6a9368c48160bb07c9bf93de481e56b2e90

Scanner detections:
10 / 68

Status:
Potentially unwanted

Analysis date:
2/25/2025 12:53:51 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clod6dd.Trojan
1.3.0.4959

ESET NOD32
Win32/HackTool.Patcher (variant)
9.10323

K7 AntiVirus
Hacktool
13.183.13166

Malwarebytes
RiskWare.Tool.CK
v2015.01.02.07

McAfee
RDN/Generic PUP.x!ym
5600.6898

nProtect
Trojan/W32.Agent.10240.LZ
14.08.27.01

Sophos
Generic PUA MH
4.98

Trend Micro House Call
PAK_Generic.001
7.2.2

Trend Micro
PAK_Generic.001
10.465.02

VIPRE Antivirus
Trojan.Win32.Generic
32590

File size:
10 KB (10,240 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\fxbox_crk.exe

File PE Metadata
Compilation timestamp:
4/2/2040 9:16:18 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
96:nPAD8galUsf+bnY+HJZz5MdnTRVa7gK8yqXTDmbxymRUt2bJ:nYYgalUdbY+bwT6h3qWbx7RUc1

Entry address:
0x150A

Entry point:
74, 00, E9, EF, 5A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Packer / compiler:
PE-PACK v1.0 by ANAKiN, 0x1998 (00?)

Code size:
2.5 KB (2,560 bytes)

The file fxbox_crk.exe has been seen being distributed by the following URL.

Remove fxbox_crk.exe - Powered by Reason Core Security