xathu_v1.exe

Xạ Thủ

四三九九网络股份有限公司

The executable xathu_v1.exe has been detected as malware by 10 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from m.f24.photo.zdn.vn.
Publisher:
四三九九网络股份有限公司

Product:
Xạ Thủ

Version:
3.0.0.1

MD5:
c97523ec6f93ff7a194333faea8acd06

SHA-1:
63a048f14eee1a98915d8295d03291e2b2a0ed59

SHA-256:
aa0463a88145ac5db1c842b4e442f190c495fd46a3c1d0924608635bbf53c5b0

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/16/2024 2:52:45 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160215-2

AVG
Win32/Sality
2015.0.4533

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.215.2092.0

Norman
Win32.Sality.3
29.02.2016 03:11:57

File size:
926.5 KB (948,776 bytes)

Product version:
3.0.0.1

Copyright:
四三九九网络股份有限公司 保留所有权利

Original file name:
Hxjyyn.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\xathu_v1.exe

File PE Metadata
Compilation timestamp:
9/14/2015 2:14:25 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:xKJV9sovwKFOKqDX5XAvr04RF0DR/uQaR2T9Q8:xK3io4KFi16rlRF0DgaS8

Entry address:
0x236CD

Entry point:
60, 8D, 35, FE, A3, FE, 31, 68, 5F, 89, B2, 00, 68, 43, 7E, 49, 00, 0F, CE, 0F, BF, D9, 80, C5, 5B, 0F, AD, FE, 0F, CE, 0F, AF, C3, 0F, AB, EB, E8, 6E, 00, 00, 00, F7, D5, 69, D6, F6, 06, DB, 7F, 2D, 5F, 11, E7, CE, 0F, B3, C3, B2, 58, FE, C0, 69, D0, E1, 35, 4A, E1, 69, D0, 06, 66, 3A, 84, 8B, D1, F3, 0F, CF, 55, 04, B8, 5B, 81, FA, 26, B9, 00, 00, 75, 04, 84, EA, 31, CA, EB, 09, 84, C6, BA, 95, C9, 37, 22, 86, F0, 53, 0F, AD, D0, 5E, 0F, BA, E7, 8C, 0F, BD, C3, 81, F8, AF, 07, 52, 7C, 6B, ED, 00, 0F, A5...
 
[+]

Entropy:
7.5905

Code size:
227 KB (232,448 bytes)

The file xathu_v1.exe has been seen being distributed by the following URL.

Remove xathu_v1.exe - Powered by Reason Core Security