x-ray pro

WindowsApplication1

The file x-ray pro has been detected as malware by 9 anti-virus scanners.
Publisher:
Hewlett-Packard*  (Invalid match)

Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
9d00c1bb93f6f15b1cf7897679b1fed4

SHA-1:
41d8c0a660cf0d4a6056e39d92f368893eef6504

SHA-256:
bde4e59ea053f569a6bfe71295ed1978d3d0aced4a66672ecc478e8601917372

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
11/30/2024 8:10:10 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
MSIL8
2016.0.2941

Baidu Antivirus
Trojan.MSIL.FakeTool
4.0.3.151029

Bkav FE
W32.Clod4e4.Trojan
1.3.0.7383

ESET NOD32
MSIL/FakeTool.AGL
9.12470

IKARUS anti.virus
Trojan.MSIL.FakeTool
t3scan.1.9.5.0

K7 AntiVirus
Hacktool
13.212.17657

McAfee
Artemis!9D00C1BB93F6
5600.6597

VIPRE Antivirus
Trojan.Win32.Generic
44846

Zillya! Antivirus
Downloader.Plocust.Win32.259907
2.0.0.2476

File size:
109 KB (111,616 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Hewlett-Packard 2015

Original file name:
X-Ray Pro.exe

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\x-ray%20pro

File PE Metadata
Compilation timestamp:
2/7/2015 1:48:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:iuyAuZCYqm+EVx+QyoUlbrYuRuhuW6TFdQhIJUA5bgu:iEfWVQQypEK68s

Entry address:
0x1AC7E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7950

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
99.5 KB (101,888 bytes)

The file x-ray pro has been seen being distributed by the following URL.

Remove x-ray pro - Powered by Reason Core Security