xmlspy.2013-patch.exe

The application xmlspy.2013-patch.exe has been detected as a potentially unwanted program by 29 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from dl3.c6.sendfile.vip.xunlei.com.
MD5:
df624de375266fab7b12b4ac34fa3a5c

SHA-1:
28b9a590334834364715cac63654205fd6474a8e

SHA-256:
5caefd052f9e6e2ca27671d7b2ca7e1854062a65165dfc6a37c1a9503149e4e0

Scanner detections:
29 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 10:59:55 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.FU.ouW@aSxVQCe
622

Agnitum Outpost
Riskware.HackTool
7.1.1

AhnLab V3 Security
Packed/Win32.Morphine
2015.04.17

avast!
Win32:Patcher-AK [PUP]
2014.9-150524

AVG
Crack
2016.0.3100

Baidu Antivirus
HackTool.Win32.Patcher.H1210s
4.0.3.15524

Bitdefender
Gen:Trojan.Heur.FU.ouW@aSxVQCe
1.0.20.720

Comodo Security
TrojWare.Win32.Agent.WFN
21792

Emsisoft Anti-Malware
Gen:Trojan.Heur.FU.ouW@aSxVQCe
8.15.05.24.12

ESET NOD32
Win32/HackTool.Patcher.AD potentially unsafe (variant)
9.11486

Fortinet FortiGate
Riskware/GamePatcher
5/24/2015

F-Prot
W32/Agent.KFY
v6.4.7.1.166

F-Secure
Gen:Trojan.Heur.FU.ouW@aSxVQCe
11.2015-24-05_1

G Data
Gen:Trojan.Heur.FU.ouW@aSxVQCe
15.5.25

IKARUS anti.virus
possible-Threat.Patcher
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.202.15623

Malwarebytes
PUP.Riskware.Patcher
v2015.05.24.12

McAfee
Artemis!DF624DE37526
5600.6756

MicroWorld eScan
Gen:Trojan.Heur.FU.ouW@aSxVQCe
16.0.0.432

NANO AntiVirus
Riskware.Win32.Patcher.djroej
0.30.16.1110

Norman
Suspicious_Gen4.ERAGD
11.20150524

Panda Antivirus
Trj/CI.A
15.05.24.12

Reason Heuristics
Threat.Win.Reputation.IMP
15.5.23.20

Rising Antivirus
PE:Trojan.Win32.Generic.133A3741!322582337
23.00.65.15522

Sophos
Troj/Agent-WFN
4.98

Trend Micro House Call
TROJ_SPNR.0BA213
7.2.144

Trend Micro
TROJ_SPNR.0BA213
10.465.24

VIPRE Antivirus
Trojan.Win32.Agent.wfn
39406

Zillya! Antivirus
Tool.Patcher.Win32.5094
2.0.0.2141

File size:
232 KB (237,568 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
5/3/2012 1:50:41 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:dvz91FTDof1RT1R1YzJxgiFUOto9jlZh/4/wvC:tz31mYz/giFto9zh/4h

Entry address:
0x102B

Entry point:
E8, 07, 00, 00, 00, 6A, 00, E8, 05, 01, 00, 00, 55, 8B, EC, 81, C4, F4, FB, FF, FF, 56, 57, 53, 6A, 00, E8, 04, 01, 00, 00, A3, 30, 30, 40, 00, C7, 45, F8, 00, 00, 00, 00, 6A, 0A, 68, 00, 30, 40, 00, 6A, 00, E8, DE, 00, 00, 00, 0B, C0, 74, 21, 89, 45, FC, FF, 75, FC, 6A, 00, E8, FD, 00, 00, 00, 89, 45, F4, FF, 75, FC, 6A, 00, E8, E4, 00, 00, 00, 0B, C0, 74, 03, 89, 45, F8, 83, 7D, F8, 00, 74, 32, 6A, 04, 68, 00, 10, 00, 00, FF, 75, F4, 6A, 00, E8, D8, 00, 00, 00, 8B, F8, FF, 75, F4, FF, 75, F8, 57, E8, BE...
 
[+]

Entropy:
7.9471  (probably packed)

Code size:
512 Bytes (512 bytes)

The file xmlspy.2013-patch.exe has been seen being distributed by the following URL.

Remove xmlspy.2013-patch.exe - Powered by Reason Core Security