tshohstg1qhw@26_36.exe

游涌

Publisher:
mdbox  (signed by 游涌)

Product:
mdbox

Version:
2.0.0.3

MD5:
ef623c0380965bd0f167cea107e7074d

SHA-1:
c29b9cd267cb9ed66ce01d052304c22be15a5f9e

SHA-256:
297fd96e2e0eaf17b113f5d2fbda10695bb6a68d297931f47cd4b71bb3739f9f

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/6/2024 6:36:49 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Virus.W32.Dh{Iyql?}!c
2.1.4+

AVG
Win32/DH{IyQl?}
2017.0.2657

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.1.6.0

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
704.1 KB (720,984 bytes)

Product version:
2.0.0.3

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\tshohstg1qhw@26_36.exe

Digital Signature
Signed by:

Authority:
WoSign CA Limited

Valid from:
9/15/2015 4:37:47 PM

Valid to:
9/15/2016 4:37:47 PM

Subject:
CN=游涌, E=edsoki@126.com, L=株洲市, S=湖南省, C=CN

Issuer:
CN=WoSign Class 2 Code Signing CA G2, O=WoSign CA Limited, C=CN

Serial number:
4954828C3EE4981163597B3FF2C95210

File PE Metadata
Compilation timestamp:
10/9/2015 3:19:27 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:5RrycSX7IdD8PWJ/CRj4qXNgEtAoXdT/TjmKYAyRrMEGbbw0aRInN+bpob4LeDu0:5VFuKjwOqXtAotT/TjmK0xGbbw0GWTbt

Entry address:
0x41846

Entry point:
E8, 84, 86, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 57, 33, DB, 6A, 07, 33, C0, 59, 8D, 7D, E4, 89, 5D, E0, F3, AB, 39, 5D, 10, 75, 18, E8, 89, 14, 00, 00, C7, 00, 16, 00, 00, 00, E8, BB, 25, 00, 00, 83, C8, FF, E9, 97, 00, 00, 00, 8B, 45, 0C, 56, 8B, 75, 08, 3B, C3, 74, 19, 3B, F3, 75, 15, E8, 62, 14, 00, 00, C7, 00, 16, 00, 00, 00, E8, 94, 25, 00, 00, 83, C8, FF, EB, 72, C7, 45, EC, 42, 00, 00, 00, 89, 75, E8, 89, 75, E0, 3D, FF, FF, FF, 3F, 76, 09, C7, 45, E4, FF, FF, FF, 7F, EB...
 
[+]

Entropy:
6.7567

Code size:
349 KB (357,376 bytes)

The file tshohstg1qhw@26_36.exe has been seen being distributed by the following URL.

Scan tshohstg1qhw@26_36.exe - Powered by Reason Core Security