xathu_v1.exe

Xạ Thủ

四三九九网络股份有限公司

The executable xathu_v1.exe has been detected as malware by 10 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from m.f24.photo.zdn.vn.
Publisher:
四三九九网络股份有限公司

Product:
Xạ Thủ

Version:
3.0.0.1

MD5:
7c44e8436d8ef82c56ed9222953c9aa9

SHA-1:
0b7daa90f162d73c2ca14c85031409d11f8bb1b5

SHA-256:
a60f566c4f79b99efe83a8b1c39d43c203284263816f196ff92ae44d08febb0a

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
11/16/2024 2:29:36 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160518-2

AVG
Win32/Sality
2015.0.4591

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.96

Microsoft Security Essentials
Threat.Undefined
1.223.1669.0

Norman
Win32.Sality.3
28.05.2016 15:32:18

VIPRE Antivirus
Threat.4721115
50170

File size:
930.5 KB (952,872 bytes)

Product version:
3.0.0.1

Copyright:
四三九九网络股份有限公司 保留所有权利

Original file name:
Hxjyyn.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\xathu_v1.exe

File PE Metadata
Compilation timestamp:
9/14/2015 2:14:25 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:hKJV9fovwKFOKqDX5XAvr04RF0DR/uQ91TzR:hK3ho4KFi16rlRF0Dg6V

Entry address:
0x236CD

Entry point:
60, 81, D0, 12, C7, A0, 1E, BD, 9D, 86, 98, 97, C1, E8, 31, 8B, F7, 80, E5, 56, 8B, FB, 3B, EB, 77, 01, F3, FE, CC, F2, 81, FE, 63, 15, 00, 00, F7, C7, D2, 1E, 32, 60, 0F, BD, CB, F2, 52, 80, CC, 22, 69, D9, A7, 66, 30, 50, F7, C6, 8E, 98, 64, B2, C6, C7, E3, 0F, C1, DB, E8, 87, 00, 00, 00, 8A, DA, 0F, BD, F1, C7, C7, 11, 8D, 0C, 21, 0F, C1, EE, F7, C0, 1D, 5E, AF, 25, 0F, AF, D9, 0F, B3, F5, C0, E3, 79, B9, 78, 05, 00, 00, 84, EB, 4B, 81, F1, 57, 05, 00, 00, 0F, BA, F0, 4A, 0F, BD, D0, 6B, C9, 24, 0F, C0...
 
[+]

Code size:
227 KB (232,448 bytes)

The file xathu_v1.exe has been seen being distributed by the following URL.

Remove xathu_v1.exe - Powered by Reason Core Security