svchost.exe

The executable svchost.exe has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. Although this file uses the name svchost.exe, this is NOT the Windows SvcHost (Service Host) distributed with the OS. The file has been seen being downloaded from callfor.info.
MD5:
a43903553d9a9d58d21eabdceec9362b

SHA-1:
0df4ff157c9dec545bdcaf9db6e5464b15ac90f6

SHA-256:
2e02aa47e2403318d35807ecd1db09ff070b6a9afb2d20b479c8d9054e6d7468

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/16/2024 12:49:25 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.3.10.2

File size:
254 KB (260,096 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\svchost.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:sr85CKtj0Q5QCD6DZTRBW4FQ9NAabGErvXmlQJJxoUDbgyu5OhclobF3OtaxBbFL:k9Al5QCuDlXW4+DiErv2yKU9pclfVU

Entry address:
0x80E4

Entry point:
55, 8B, EC, 83, C4, E0, 33, C0, 89, 45, E0, 89, 45, E8, 89, 45, E4, 89, 45, EC, B8, 54, 80, 40, 00, E8, 12, BE, FF, FF, 33, C0, 55, 68, 20, 82, 40, 00, 64, FF, 30, 64, 89, 20, B8, A8, 91, 40, 00, B9, 0B, 00, 00, 00, BA, 0B, 00, 00, 00, E8, 5C, EF, FF, FF, B8, B4, 91, 40, 00, B9, 09, 00, 00, 00, BA, 09, 00, 00, 00, E8, 48, EF, FF, FF, B8, C0, 91, 40, 00, B9, 03, 00, 00, 00, BA, 03, 00, 00, 00, E8, 34, EF, FF, FF, B8, DC, 91, 40, 00, B9, 03, 00, 00, 00, BA, 03, 00, 00, 00, E8, 20, EF, FF, FF, A1, 10, 92, 40...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
29 KB (29,696 bytes)

The file svchost.exe has been seen being distributed by the following URL.

Remove svchost.exe - Powered by Reason Core Security