shubiaoliandian.exe

鼠标连点

游戏盒子

The executable shubiaoliandian.exe, “鼠标连点 Setup ” has been detected as malware by 15 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from dlc2.pconline.com.cn.
Publisher:
游戏盒子

Product:
鼠标连点

Description:
鼠标连点 Setup

MD5:
46412054e9eca71581528ecf41c4b3aa

SHA-1:
a59cf494395a494d00197730bc803f5218395f49

SHA-256:
8bf60a846f6193cd52df15f332e7cd55e9b1441ed8569257862e9b82370cdefc

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
11/24/2024 2:58:39 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.W32.Pasta!c
2.1.4+

Avira AntiVirus
TR/Graftor.103356.39
8.3.3.4

avast!
Win32:Malware-gen
2014.9-160724

AVG
Generic33
2017.0.2672

Bkav FE
W32.Clod951.Trojan
1.3.0.8042

Fortinet FortiGate
W32/Pasta.ABWN!tr
7/24/2016

G Data
Win32.Trojan.Agent.RFHSNK
16.7.25

IKARUS anti.virus
Trojan.Win32.Pasta
t3scan.2.0.9.0

K7 AntiVirus
Riskware
13.227.19779

Kaspersky
Trojan.Win32.Pasta
14.0.0.-143

McAfee
Artemis!46412054E9EC
5600.6328

NANO AntiVirus
Trojan.Win32.Pasta.dzuxqg
1.0.30.8482

Panda Antivirus
Trj/CI.A
16.07.24.01

Vba32 AntiVirus
Trojan.Pasta
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
49804

File size:
3.2 MB (3,321,759 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\shubiaoliandian.exe

File PE Metadata
Compilation timestamp:
10/10/2012 1:50:03 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:JIlm/zEKTH0jlOiw0sWinXJNk2fQqA2TfRYQ:Y6wKTBiV6XJNk2zdZ7

Entry address:
0xF3C4

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 78, ED, 40, 00, E8, E0, 71, FF, FF, 33, C0, 55, 68, 91, FA, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 4D, FA, 40, 00, 64, FF, 32, 64, 89, 22, A1, 48, 3B, 41, 00, E8, CA, F7, FF, FF, E8, D9, F3, FF, FF, 8D, 55, EC, 33, C0, E8, FF, C4, FF, FF, 8B, 55, EC, B8, 50, 66, 41, 00, E8, 62, 58, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 50, 66, 41, 00, B2, 01...
 
[+]

Entropy:
7.9865

Developed / compiled with:
Microsoft Visual C++

Code size:
59 KB (60,416 bytes)

The file shubiaoliandian.exe has been seen being distributed by the following URL.

Remove shubiaoliandian.exe - Powered by Reason Core Security