hdat2_4.9.3_downloader.exe

Cheng Du VTools Information Technology

The application hdat2_4.9.3_downloader.exe by Cheng Du VTools Information Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from www.8appstore.net. While running, it connects to the Internet address rimmer.core.ignum.cz on port 80 using the HTTP protocol.
Publisher:

MD5:
15eb4aac121da8dc1f8a5af2206746bf

SHA-1:
92595eabc9e96d5fe90c46e865a93aa5176d9157

SHA-256:
c92c86b0a06c72fbbeb3aac810900ff776e8b5bd1ce3afea83ca7330a6c72466

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/27/2024 6:57:30 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ChengDuV (M)
16.4.6.18

File size:
781.8 KB (800,592 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\hdat2_4.9.3_downloader.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/10/2011 6:00:00 PM

Valid to:
1/25/2014 5:59:59 PM

Subject:
CN=Cheng Du VTools Information Technology, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Cheng Du VTools Information Technology, L=ChengDu, S=SiChuan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1B5D68E0AFA12E8F1159C668DD228431

File PE Metadata
Compilation timestamp:
8/2/2013 12:58:58 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:m5UnZzPkMXdh4JIc+GIQDDIDtEtVJF1ohHuT5ZJLSM0O:lzP34OcDcZEXJFepuJSMN

Entry address:
0x1CE6C0

Entry point:
60, BE, 00, 90, 53, 00, 8D, BE, 00, 80, EC, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
600 KB (614,400 bytes)

The file hdat2_4.9.3_downloader.exe has been seen being distributed by the following URL.

http://www.8appstore.net/.../downloadfile.html?swid=628699

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to rimmer.core.ignum.cz  (217.31.49.32:80)

Remove hdat2_4.9.3_downloader.exe - Powered by Reason Core Security