poke.exe.infected.000

D4S

CHEN PROGRAM STUDY

The file poke.exe.infected.000 has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from dc241.4shared.com.
Publisher:
CHEN PROGRAM STUDY

Product:
D4S

Version:
1.00

MD5:
8f145efffa914dcb60475e0e08d4f659

SHA-1:
7127e26f30b0427aa4f06f9cece4ea2fb7c1ec29

SHA-256:
18b7c6515f1e6e2d4d5f9b821e29724e640581e26da376ba22afa1133c884817

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 12:23:16 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Generic.CHENPROGRAMSTUDY.Meta (M)
16.1.7.7

File size:
713.3 KB (730,371 bytes)

Product version:
1.00

Trademarks:
CPS

Original file name:
D4S.EXE

Language:
Chinese (Traditional, Taiwan)

File PE Metadata
Compilation timestamp:
1/18/2002 8:17:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
4.20

CTPH (ssdeep):
12288:QE0kf+rtOb1alWLzf3/H0ay9k/eCZPLWCPd6LSncryITAa1BcoKASaJC4/70G:p0k4y/Lr3Ma5NZP6CPd+SY9TAa4jAHTh

Entry address:
0xE5001

Entry point:
60, E9, 3D, 04, 00, 00, E9, 25, 05, 01, 01, EC, 01, BC, 31, 3A, 45, 01, 04, DE, 2C, 9E, D1, 40, 45, 01, 84, BE, FD, 4A, 45, 01, 01, 8A, 9E, FD, 4A, 45, 01, 10, 86, 67, 04, 01, 01, C8, 86, 34, 3A, 45, 01, 01, 01, 01, 01, 8E, 86, 05, 4B, 45, 01, 51, 00, 96, 01, 4C, 45, 01, 8A, 86, 01, 4B, 45, 01, 8C, F9, 8E, 9E, 12, 4B, 45, 01, 54, 51, 00, 96, FD, 4B, 45, 01, 8A, 86, FD, 40, 45, 01, 8E, 9E, 1F, 4B, 45, 01, 54, 58, 00, 96, FD, 4B, 45, 01, 8A, 86, 01, 41, 45, 01, 8E, 86, B6, 3A, 45, 01, 00, E1, 29, 17, 01, 01...
 
[+]

Packer / compiler:
ASProtect v1.1

Code size:
723 KB (740,352 bytes)

The file poke.exe.infected.000 has been seen being distributed by the following URL.

Remove poke.exe.infected.000 - Powered by Reason Core Security