svchost.exe

The executable svchost.exe has been detected as malware by 15 anti-virus scanners. This is a setup program which is used to install the application. Although this file uses the name svchost.exe, this is NOT the Windows SvcHost (Service Host) distributed with the OS. The file has been seen being downloaded from m.55900f6043109d0c94f1287fab1ef610.com.
MD5:
05d2ab7748c436b3da0048732c8bd7f4

SHA-1:
abc0e2d8b0d568b8f42d71d8d3fb6224ecc82661

SHA-256:
5760d3cee06d12f93aed4762a46108be6e1ac95b1a6fe6a8d09a941369a26f34

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
12/29/2024 6:32:58 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Dropper/Win32.Malware
2014.09.21

Avira AntiVirus
TR/Agent.334526
7.11.200.118

avast!
Win32:Malware-gen
2014.9-150409

Baidu Antivirus
Trojan.Win32.Reconyc
4.0.3.1549

Comodo Security
UnclassifiedMalware
20659

Fortinet FortiGate
W32/Reconyc.DLNP!tr
4/9/2015

IKARUS anti.virus
Trojan.Win32.Reconyc
t3scan.1.8.6.0

K7 AntiVirus
Riskware
13.190.14599

Kaspersky
Trojan.Win32.Reconyc
14.0.0.2220

McAfee
RDN/Generic.bfr!ia
5600.6801

NANO AntiVirus
Trojan.Win32.Reconyc.dlyqyr
0.30.0.64448

Norman
CoinMiner.AN
11.20150409

Qihoo 360 Security
HEUR/QVM20.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.4.8.22

Sophos
Mal/Generic-S
4.98

File size:
332.2 KB (340,158 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\temp\svchost.exe

File PE Metadata
Compilation timestamp:
6/15/1971 8:54:16 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.24

CTPH (ssdeep):
6144:XFpbUdEjryhv5oNP4wOwo5A31WXl2LcyVIC1w85GEmqa:XvUdE3yhv5oN7oa31jImICpmqa

Entry address:
0x1570

Entry point:
83, EC, 1C, C7, 04, 24, 01, 00, 00, 00, FF, 15, 9C, 41, 44, 00, E8, FB, FB, FF, FF, 8D, 74, 26, 00, 8D, BC, 27, 00, 00, 00, 00, 83, EC, 1C, C7, 04, 24, 02, 00, 00, 00, FF, 15, 9C, 41, 44, 00, E8, DB, FB, FF, FF, 8D, 74, 26, 00, 8D, BC, 27, 00, 00, 00, 00, A1, C8, 41, 44, 00, FF, E0, 89, F6, 8D, BC, 27, 00, 00, 00, 00, A1, BC, 41, 44, 00, FF, E0, 90, 90, 90, 90, 90, 90, 90, 90, 90, 55, 89, E5, 83, EC, 18, C7, 04, 24, 00, 10, 44, 00, E8, 3E, 21, 00, 00, BA, 00, 00, 00, 00, 83, EC, 04, 85, C0, 74, 15, C7, 44...
 
[+]

Code size:
10.5 KB (10,752 bytes)

The file svchost.exe has been seen being distributed by the following URL.

Remove svchost.exe - Powered by Reason Core Security