svchost.exe

The executable svchost.exe has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. Although this file uses the name svchost.exe, this is NOT the Windows SvcHost (Service Host) distributed with the OS. The file has been seen being downloaded from callfor.info.
MD5:
ddb0de4f027ac18dcfd710de0f94797c

SHA-1:
c26b25bbe1ed9cc54e6659e08c621272cc972414

SHA-256:
7f76875d6a13dcfd5749659f02e9355fb87244b8a445c1b8e47bf5f6efda9ffe

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/16/2024 12:26:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.2.18.18

File size:
213.5 KB (218,624 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\svchost.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:sr85CKtj0Q5QCD6DZTRBW4FQ9NAabGErvXmlQJJxoUDbgyu5OhclobF3Otaxd:k9Al5QCuDlXW4+DiErv2yKU9pclfU

Entry address:
0x80E4

Entry point:
55, 8B, EC, 83, C4, E0, 33, C0, 89, 45, E0, 89, 45, E8, 89, 45, E4, 89, 45, EC, B8, 54, 80, 40, 00, E8, 12, BE, FF, FF, 33, C0, 55, 68, 20, 82, 40, 00, 64, FF, 30, 64, 89, 20, B8, A8, 91, 40, 00, B9, 0B, 00, 00, 00, BA, 0B, 00, 00, 00, E8, 5C, EF, FF, FF, B8, B4, 91, 40, 00, B9, 09, 00, 00, 00, BA, 09, 00, 00, 00, E8, 48, EF, FF, FF, B8, C0, 91, 40, 00, B9, 03, 00, 00, 00, BA, 03, 00, 00, 00, E8, 34, EF, FF, FF, B8, DC, 91, 40, 00, B9, 03, 00, 00, 00, BA, 03, 00, 00, 00, E8, 20, EF, FF, FF, A1, 10, 92, 40...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
29 KB (29,696 bytes)

The file svchost.exe has been seen being distributed by the following URL.

Remove svchost.exe - Powered by Reason Core Security