set_dzhrxurh.exe

Sonny Sun Interactive

The application set_dzhrxurh.exe by Sonny Sun Interactive has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
Application Snappy System Installer  (signed by Sonny Sun Interactive)

Product:
Application Snappy System Installer

Version:
59.1.0.139

MD5:
0a9105c4aced19e26389a30ac9b5f7d0

SHA-1:
eb4b34483ecd9e2e09ef86681d29726aca6c58a9

SHA-256:
5f2f8deaa3a8eecae954c9877ec0cbaeb0790255a41f19a854bbd12f37612c8f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 5:58:32 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DownloadAdmin (M)
16.7.28.18

File size:
1.1 MB (1,113,344 bytes)

Product version:
59.1.0.139

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\set_dzhrxurh.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
3/8/2016 4:13:39 PM

Valid to:
3/8/2017 4:13:39 PM

Subject:
CN=Sonny Sun Interactive, O=Sonny Sun Interactive, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0093AC568FBE0B686A

File PE Metadata
Compilation timestamp:
7/10/2015 5:33:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:kz10ENiH/GIj66PB+qaROZHoeNb046kZkllJjqZ+UZ:Gh6THoeNAKMTjO+

Entry address:
0x593D

Entry point:
E8, AE, CC, 07, 00, E9, A8, C0, 07, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 04, 68, 30, 9D, 49, 00, 68, 6C, A8, 49, 00, 50, E8, 3C, 4C, 07, 00, 83, C4, 0C, B8, 01, 00, 00, 00, C3, CC, CC, CC, 83, 3D, 64, 0F, 4E, 00, 00, 55, 8B, 2D, 80, 51, 48, 00, 74, 40, 53, 8B, 1D, 84, 51, 48, 00, 56, 57, 8B, 3D, 88, 51, 48, 00, BE, 64, 0F, 4E, 00, 8B, 46, FC, 8B, 0E, 8B, 11, 68, 03, 01, 00, 00, 50, 52, FF, D7, 85, C0, 76, 0D, 8B, 06, 8B, 08, 51, FF, D3, 8B, 56, FC, 52, FF, D5, 83, C6, 08, 83, 3E, 00, 75, D7...
 
[+]

Entropy:
7.4815

Code size:
524.5 KB (537,088 bytes)

Remove set_dzhrxurh.exe - Powered by Reason Core Security