xion_v1.0b127.exe

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
MD5:
b3917fa036f298c488de7eb56b70d1c1

SHA-1:
6fba4dadc6a5211dc5443d3b5cc3f8a183f88de5

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/30/2024 10:49:47 AM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Trojan.Win32.Generic.126B2B11!309013265
23.00.65.14324

Trend Micro House Call
PAK_Generic.001
7.2.85

Trend Micro
PAK_Generic.001
10.465.26

File size:
2.7 MB (2,803,728 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\documents and settings\eigenaar\bureaublad\downloads\xion_v1.0b127.exe

File PE Metadata
Compilation timestamp:
6/6/2009 11:41:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:qionaIigWK4YVM5SNT9cJCtGh92sUx59QoFGEZDOEensbhbotBQKB6y2WMXmoaZw:qXEXK4YV8JCty2sUx5VFtOEensbxOBQf

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file xion_v1.0b127.exe has been discovered within the following programs.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
Xion v1.0 (build 127)  by r2 studios
Xion is a high fidelity, easily skinnable, out of this world audio player.
xion.r2.com.au
About 2% of users remove it
 
Powered by Should I Remove It?

The file xion_v1.0b127.exe has been seen being distributed by the following 21 URLs.

http://gsf-cf.softonic.com/6fb/a4d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53724&instance=softonic_es&type=PROGRAM&Expires=1470793765&Signature=QYPVa8ggwR5e8pJEIr6qB2ZMBC6M44KYqs8Ne9PuewvjLhz03HAoJ3G6UnHSvzcoNQBvpNyQm0fFGQArewmnf8waNfdBkD7JW~QNCvtanByBt1jNwWZKZDI8edWb~zDQnnQq4SFeMrDiCGuW~hEaKQC~tYypQ18auwmen6NP3aA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=xion_v1.0b127.exe

http://gsf-cf.softonic.com/6fb/a4d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53724&instance=softonic_es&type=PROGRAM&Expires=1455114336&Signature=G9nuQfQ32ls5SZJfGg0uVLWpSshsAuZoDxPfkv9L6wMNQwlW0SkJI9znz5GISPiDVoMyYyyoWT5Y-mKPTC9xYWBer2-mQjE8anNby3y0Vm8pcKiasP6XMzUZzC2ZhUtV7Aw~WNGejwh57BUhLcnSJInmZgQn~Qn8x1Xpqxqjo8A_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=xion_v1.0b127.exe

https://mega.nz/temporary/.../qIMgAYQL

http://gsf-cf.softonic.com/6fb/a4d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53724&instance=softonic_es&type=PROGRAM&Expires=1452838869&Signature=CCeoco7qyq6814Wj-5FbhCd7aCSVGWVG6tyShD61RiqDKp~TnC1kzvnEuEHpXE5BiDi9JBSUFU5VRdFO5gwqe8L2T7LxU~XLvG2bkYQS-aSGKw6Fv9X-8agQ30cJy65GcOLXkeMV1f-jRABuTMdNlh7xtr3-UVqkrCuqcBJTPW0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=xion_v1.0b127.exe

http://gsf-cf.softonic.com/6fb/a4d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53724&instance=softonic_es&type=PROGRAM&Expires=1478351615&Signature=HQ8evXPb6JGy9iy7oHYZj41ulYzpX9CUyKEBnYRiH6-cnyp2OYbQpvnaPTPStKr8TQC9Rxds2X8qqCOD6GCmOheVbjwH9uBhnuuiUhXMXezG~R7jdKqT4VOgY3QNLOJSXcXhoYUpbT0IvimhYyuABKlJs6sYNDR~IvgCqu9ndaM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=xion_v1.0b127.exe

http://gsf-cf.softonic.com/6fb/a4d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53724&instance=softonic_es&type=PROGRAM&Expires=1474775175&Signature=bulgf1-O~hqywqkkR0nVNK-f2gUc2FzzDpQ4PY9SLG4XSfXUefDQoP89cmzez3HDcPFAimQv5pcmMoPOKVvt9Uevl0z1rVkZJ9r-rNWznOfNj6X2UR3qouANTUO56rPmK5yvt0Re6Re5GCFZmw5wgw5DhZrfqQm2rdzwq-L-vy4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=xion_v1.0b127.exe

http://gsf-cf.softonic.com/6fb/a4d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53724&instance=softonic_es&type=PROGRAM&Expires=1442654108&Signature=JsRNmg6HqbjLioX~b6UdyiGgf1BoDXia3JK6Qqf0wcr8c2LUVAvt3K6f9kiHWAbmV~6mXHOEeh6bVjbfqJ~ECDHHiecQmedWRk7mMs9HzVHkzO21oryHRZpvosNozyyKZ8T9RCb6v3sf6qmnEMt0iNBkIMTw8fxQgXh2YO6sNMA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=xion_v1.0b127.exe

http://gsf-cf.softonic.com/6fb/a4d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53724&instance=softonic_es&type=PROGRAM&Expires=1473144978&Signature=W9HSEYuTr1zPzEoNQehAukNBEk7wYxhyD4ZmI97u4EGa2~OsNe8y7TG5A8lN4lBSDB3igld92RBjY18tnlqOFrzbEGvEVwzQ4U-aaG587CrDAiYT2Gu7Fi3rUVIPWOkaqkBjLEyF4FoSoBbR3ZqxHaM1kcIu2NYVu6SwEcR7vpU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=xion_v1.0b127.exe

http://gsf-cf.softonic.com/6fb/a4d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53724&instance=softonic_es&type=PROGRAM&Expires=1480483933&Signature=gWpmowM1vpGEziizTWwWk~EPGqd4NZNDRjTWBY5Kr~l~BR154UD2ZxF99I-yV~jOF3aLZ0P~dtq7nvCwscqiepbW21gtyYspF3nmlZ02OId6NaGL6iLbaBWl9csqfK0YEvNfoJKdOmxSIRYim-7A2Ra9MmxOy1052S-5pL2bIqM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=xion_v1.0b127.exe

http://gsf-cf.softonic.com/6fb/a4d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53724&instance=softonic_pl&type=PROGRAM&Expires=1473316654&Signature=bHE3tLgBIB1zl-WT2g3RlXWRaUeMaHZjY-ASDXeh1xzXtbNxmX3wuWgwALCGTlL48uiv8ok-TcHrG6UtSwpvF2JEaZ5paL-bykGR1Rw2XInIg7Ncwp~ry9i80ulohCCVFZdfa0Jw491eKNKxZQ6oZ7mP5UVGK5B3ZfpcF8kV7bA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=xion_v1.0b127.exe

http://gsf-cf.softonic.com/6fb/a4d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53724&instance=softonic_es&type=PROGRAM&Expires=1470622235&Signature=NoXUZ1kw6V4BeovF64pojWEOIvuFcC7lkHBTWvWS1HBudiFR8PLeoYgOifVYMVln18tI5xcNQkMxc65geq~Nm84APfKrnHNc4jGeRzCnCI-GWPpLGMGRmp4BtBaMVeDalriIhNMtjtFNeIRM8Gw3KjZCsKGbpm~4RcAHWMeJ5LU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=xion_v1.0b127.exe

http://gsf-cf.softonic.com/6fb/a4d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53724&instance=softonic_es&type=PROGRAM&Expires=1470315687&Signature=MfG6Wjs0xfEbixBi-DmitjW7cv-I2X5NyGyGqrdODYYZkH~VOJynN3UlXqLZiccfA~cjqw0CJRCpEwXPFbS0cgzrsO1KfKw5bvV9R1L4YfQ-eClltYS64BuQF-FjLhS3JLfO873wzYLO-mx3JfYlszTUks0FjRCDog-h~bg7BdU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=xion_v1.0b127.exe

http://gsf-cf.softonic.com/6fb/a4d/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53724&instance=softonic_es&type=PROGRAM&Expires=1465028965&Signature=Ao1iq1SKZUs9kXd6RJXCOq7mO7M1Qp5GgC910Yb7T-6mQ~Yl4J7Z7AgqojhCdpFKVvcMF6SEi8muLzwcWIwg7j-3ZNK8WU-w4GuVC0iLFLLxMUuRY8eoHxkIBqZsDyH7aa7UWrhSoM~0jYtRpa6xg~SDErkCOehTN-9V3G1~iGM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=xion_v1.0b127.exe

Scan xion_v1.0b127.exe - Powered by Reason Core Security