happyboxpro.exe

上海去秀网络科技有限公司

The executable happyboxpro.exe has been detected as malware by 13 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘happyboxrun’.
Publisher:
happy游戏盒  (signed by 上海去秀网络科技有限公司)

Product:
happy游戏盒

Version:
1.0

MD5:
75b849ab4498c3c16ab8ffbc905d301d

SHA-1:
9511bb93631796561134468ac210585ec06db40c

SHA-256:
6c14c6b69dc5a020a2d87b1b743dbeadc0e6b8e268097b0dfd4da97f8871ae13

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
11/24/2024 7:40:59 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.Black.Gen2!c
2.1.4+

Avira AntiVirus
TR/Black.Gen2
8.3.3.4

AVG
Win32/Blacked
2017.0.2701

Baidu Antivirus
Win32.Packed.VMProtect
4.0.3.16626

Bkav FE
W32.Clod748.Trojan
1.3.0.7744

ESET NOD32
Win32/Packed.VMProtect.ABD (variant)
10.13309

Fortinet FortiGate
W32/VMProtBad.A!tr
6/26/2016

IKARUS anti.virus
Trojan.Win32.VMProtect
t3scan.2.0.9.0

K7 AntiVirus
Trojan
13.221.19261

McAfee
Artemis!75B849AB4498
5600.6357

Sophos
Mal/VMProtBad-A
4.98

Trend Micro
TROJ_GEN.R0ADC0OD816
10.465.26

VIPRE Antivirus
Trojan.Win32.Generic
48506

File size:
977.1 KB (1,000,560 bytes)

Product version:
1.0

Copyright:
happy游戏盒

Trademarks:
happy游戏盒

Original file name:
happy游戏盒

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\happybox\happyboxpro.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
10/9/2015 4:28:45 PM

Valid to:
10/9/2016 4:28:45 PM

Subject:
CN=上海去秀网络科技有限公司, O=上海去秀网络科技有限公司, L=上海市, S=上海市, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
46A1FFA3386ECEB8F967E31575033D0C

File PE Metadata
Compilation timestamp:
10/12/2015 3:29:57 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:8PZKNCduSlC8Q3Y2cAhoDpp2j+3LD+ExSePHS8wS83:8PMCdu4CfKC9gLD+Eoe/S8wS83

Entry address:
0x1E4401

Entry point:
60, 55, 68, 32, 17, 45, 04, E8, 47, A4, F2, FF, C2, 98, 29, E5, BD, 62, 52, 84, D4, 2A, 8F, 66, CC, 9F, 92, 47, 3A, EF, 06, B5, C6, D0, 3F, B6, 37, D4, 01, E8, C2, 9F, 32, DD, 42, DF, B2, 71, 9D, 6C, 88, 82, 31, 4D, 8A, 5B, 97, B5, F8, D2, 09, DD, 2A, 49, 6F, 87, B8, 93, AD, CA, EA, FF, 47, 90, CC, D5, AA, 64, 1E, 06, B4, 4A, E3, BA, 9C, 85, FB, E4, E2, A0, 10, A6, D9, 86, A2, 85, 19, B0, 3A, 91, 63, 78, 39, FD, DF, 69, A4, 41, D7, 61, 88, 8D, 96, 96, 4F, 35, B0, 5E, EB, 07, 94, 82, E2, 64, 7B, 6D, 24, 59...
 
[+]

Entropy:
7.9100  (probably packed)

Code size:
195.5 KB (200,192 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
happyboxrun

Command:
"C:\Program Files\happybox\happyboxpro.exe" apprun


Remove happyboxpro.exe - Powered by Reason Core Security