jjsg.exe

265G游戏浏览器街机三国辅助

The executable jjsg.exe has been detected as malware by 31 anti-virus scanners. The file has been seen being downloaded from dx2.52z.com.
Product:
265G游戏浏览器街机三国辅助

Version:
2.5.0.0

MD5:
e7371e08c92942d918fe7ca97e65c05c

SHA-1:
3fc4d0829df15abef0a6e8c4f9350e8273dc3a77

SHA-256:
7862a261d746ea315b9becbcb574947d7864e5caeaf258d82d0be6822ae510ce

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
11/27/2024 8:37:40 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1206854
1133

Agnitum Outpost
Trojan.DR.Injector
7.1.1

AhnLab V3 Security
Dropper/Win32.Injector
2013.12.20

Avira AntiVirus
TR/Rogue.KDZ.7051.317
7.11.120.124

avast!
Win32:Rootkit-gen [Rtk]
2014.9-130823

AVG
Dropper.Generic7
2014.0.3538

Baidu Antivirus
Trojan.Win32.Injector
4.0.3.131126

Bitdefender
Trojan.GenericKD.1206854
1.0.20.1650

Bkav FE
W32.SapinH.Trojan
1.3.0.4613

Comodo Security
TrojWare.Win32.TrojanDownloader.Agent.RRR
17467

Dr.Web
Trojan.KillProc.22109
9.0.1.0235

Emsisoft Anti-Malware
Trojan.GenericKD.1206854
8.13.11.26.01

ESET NOD32
Win32/TrojanDownloader.Agent.RRR (variant)
7.9190

Fortinet FortiGate
W32/Agent.RRR!tr.dldr
8/23/2013

F-Secure
Trojan.GenericKD.1206854
11.2013-26-11_3

G Data
Trojan.GenericKD.1206854
13.11.22

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.2.2.29

K7 AntiVirus
Trojan
13.174.10560

Kaspersky
Trojan-Dropper.Win32.Injector
14.0.0.3766

Malwarebytes
Trojan.Chad
v2013.08.23.05

McAfee
Dropper-FDT!E7371E08C929
5600.7176

MicroWorld eScan
Trojan.GenericKD.1206854
14.0.0.990

NANO AntiVirus
Trojan.Win32.KillProc.brmetk
0.28.0.57029

Norman
Troj_Generic.KHLCQ
11.20130823

Panda Antivirus
Trj/CI.A
13.08.23.05

Rising Antivirus
PE:Trojan.Win32.Generic.14A51628!346363432
23.00.65.131124

Sophos
Mal/Generic-S
4.96

Trend Micro House Call
TROJ_GEN.R0GCFDR
7.2.235

Trend Micro
TROJ_GEN.R0GCFDR
10.465.23

Vba32 AntiVirus
TrojanDropper.Injector
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
22074

File size:
2.7 MB (2,793,512 bytes)

Product version:
2.5.0.0

Copyright:
作者版权所有 请尊重并使用正版

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\jjsg.exe

File PE Metadata
Compilation timestamp:
1/24/2013 6:32:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:LitV1YKegFa6M8bciHu/SOoqdjA2XeeD4c:Li1YKTDbcEu/NdM2Xh9

Entry address:
0x1FF16

Entry point:
E8, B6, A5, 00, 00, E9, 16, FE, FF, FF, 6A, 0C, 68, C8, 66, 04, 01, E8, 64, 4F, 00, 00, 33, DB, 89, 5D, E4, 33, C0, 8B, 75, 08, 3B, F3, 0F, 95, C0, 3B, C3, 75, 20, E8, 90, 05, 00, 00, C7, 00, 16, 00, 00, 00, 53, 53, 53, 53, 53, E8, C7, DD, FF, FF, 83, C4, 14, 83, C8, FF, E9, 00, 01, 00, 00, 33, C0, 39, 5D, 0C, 0F, 95, C0, 3B, C3, 74, D4, 89, 75, 08, 56, E8, E4, 02, 00, 00, 59, 89, 5D, FC, F6, 46, 0C, 40, 0F, 85, A6, 00, 00, 00, 56, E8, 02, 6F, 00, 00, 59, 83, F8, FF, 74, 2E, 56, E8, F6, 6E, 00, 00, 59, 83...
 
[+]

Entropy:
6.4168

Code size:
229 KB (234,496 bytes)

The file jjsg.exe has been seen being distributed by the following URL.

Remove jjsg.exe - Powered by Reason Core Security