xathu_v1.exe

Xạ Thủ

四三九九网络股份有限公司

The executable xathu_v1.exe has been detected as malware by 12 anti-virus scanners. The file has been seen being downloaded from m.f24.photo.zdn.vn.
Publisher:
四三九九网络股份有限公司

Product:
Xạ Thủ

Version:
3.0.0.1

MD5:
11e3957e1a0d54f309582e27a92d4ce2

SHA-1:
2df4b8fad7b967352ac44bb055a1497acfec8ae0

SHA-256:
c4d81e321cc29060e1195d4eeaeeb0b7e9cf45313a442337357e55357805da00

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
11/16/2024 2:35:02 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160310-2

AVG
Win32/Sality
2015.0.4533

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.215.2092.0

Norman
Win32.Sality.3
29.02.2016 05:46:54

Sophos
Virus 'Mal/Sality-D'
5.23

VIPRE Antivirus
Threat.4721115
29708

File size:
926.5 KB (948,776 bytes)

Product version:
3.0.0.1

Copyright:
四三九九网络股份有限公司 保留所有权利

Original file name:
Hxjyyn.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\xathu_v1.exe

File PE Metadata
Compilation timestamp:
9/14/2015 2:14:25 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:xKJV9VovwKFOKqDX5XAvr04RF0DR/uQDvh/:xK33o4KFi16rlRF0DgevB

Entry address:
0x236CD

Entry point:
60, 0F, BF, E9, 0F, BA, EA, D4, F2, 8A, E4, 3D, CA, CB, 00, 00, 77, 09, C1, F9, 6A, F7, C3, 2A, 61, C0, F2, C6, C2, 01, 0F, CE, 4A, F6, C4, 4C, E8, 33, 00, 00, 00, B9, 00, 00, 00, 00, 43, F6, C0, 97, C0, F0, 4D, 0F, C0, C3, 87, EE, 81, C1, 01, 00, 00, 00, 88, E2, 45, 0F, BA, E5, 7E, F2, 88, DF, 0F, BF, C3, C6, C2, 9E, 81, F9, 0B, 02, 00, 00, 0F, 82, D2, FF, FF, FF, BA, D4, AF, 22, C3, D2, FB, F7, D9, FE, C5, 0F, C0, CD, 2B, F3, 8A, F5, 80, F5, 15, 33, DB, FE, C5, 87, EF, D0, D0, 0F, AC, C9, C9, 0F, CF, F3...
 
[+]

Entropy:
7.5870

Code size:
227 KB (232,448 bytes)

The file xathu_v1.exe has been seen being distributed by the following URL.

Remove xathu_v1.exe - Powered by Reason Core Security