svchost.exe

The executable svchost.exe has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘3c64bd3165c924988281c4e25c05361e’. Although this file uses the name svchost.exe, this is NOT the Windows SvcHost (Service Host) distributed with the OS. The file has been seen being downloaded from fs05n2.sendspace.com.
MD5:
3a8e3ba1b7ce60d4c178b4b311dd2b2b

SHA-1:
5b940d8c4d31e750535b800ab0ccbe2c56215b0a

SHA-256:
56f46ea9a5f93a490675558d3d52a17e9fec7d6adce75b182b3d4030e08fdc07

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/15/2024 9:32:14 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Trojan.Rootkit (H)
16.5.18.23

File size:
23.5 KB (24,064 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\svchost.exe

File PE Metadata
Compilation timestamp:
5/18/2016 4:20:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:6W3qbCKml4hoo9IMVCGpOsjhEv6/ghrrgOpt3xmRvR6JZlbw8hqIusZzZdQ:6SN0aatpAnARpcnuZ

Entry address:
0x74BE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
21.5 KB (22,016 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
3c64bd3165c924988281c4e25c05361e

Command:
"C:\users\{user}\appdata\local\temp\svchost.exe"..


The file svchost.exe has been seen being distributed by the following URL.

Remove svchost.exe - Powered by Reason Core Security