羲宎蚔牁.exe

Ali213 Game Launcher

杭州凤侠网络科技有限公司

The application 羲宎蚔牁.exe by 杭州凤侠网络科技有限公司 has been detected as a potentially unwanted program by 7 anti-malware scanners. According to AVG, this software downloads additional adware offers during setup. While running, it connects to the Internet address h26-210-66-47.seed.net.tw on port 80 using the HTTP protocol.
Publisher:
游侠网  (signed by 杭州凤侠网络科技有限公司)

Product:
Ali213 Game Launcher

Description:
游侠绿色版启动工具

Version:
1.0.0.6

MD5:
119d406497fe8ed14602b17cfb539e63

SHA-1:
617dd5857be002a5b0fe5e5e7afdf606ad0538bf

SHA-256:
56666140cb1003bb561360bdd0997cd2ce5378dad704f72f307264d6559951ad

Scanner detections:
7 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 4:48:45 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Downloader.Generic13
2016.0.3219

McAfee
Artemis!119D406497FE
5600.6875

NANO AntiVirus
Riskware.Win32.Agent.daquxy
0.28.2.62483

Reason Heuristics
Threat.Win.Reputation.IMP
15.1.24.22

Trend Micro House Call
Suspicious_GEN.F47V0917
7.2.24

Vba32 AntiVirus
TrojanClicker.Agent
3.12.26.3

Zillya! Antivirus
Trojan.Agent.Win32.480344
2.0.0.1945

File size:
4.6 MB (4,797,432 bytes)

Product version:
1.0.0.6

Copyright:
www.ali213.net

Original file name:
Game Launcher.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
WoSign CA Limited

Valid from:
7/25/2014 5:58:26 PM

Valid to:
9/25/2015 5:58:26 PM

Subject:
CN=杭州凤侠网络科技有限公司, E=ali213@ali213.net, O=杭州凤侠网络科技有限公司, L=杭州市, S=浙江省, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
585891A9A57B46E259BB40F686FA96A7

File PE Metadata
Compilation timestamp:
4/28/2014 3:36:27 AM

OS version:
4.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:K9OkYfHMx7N5oj1/Uoej1/8Gz8Na4OhtrqNkGyz9nTDJoA:KQGN5oCoa1/4NJOhtrqNafiA

Entry address:
0x57CA3

Entry point:
E8, F9, 9D, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, 38, 08, 00, 00, 8B, FF, 51, C7, 01, 1C, B4, 47, 00, E8, 76, 9E, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, CC, FF, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 83, C1, 09, 51, 83, C0, 09, 50, E8, B2, 9E, 00, 00, F7, D8, 59, 1B, C0, 59, 40, 5D, C2, 04, 00, C7, 01, 24, B4, 47, 00, E9, 08, A0, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, 24, B4, 47, 00, E8...
 
[+]

Entropy:
6.5748

Code size:
487 KB (498,688 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to h26-210-66-47.seed.net.tw  (210.66.47.26:80)

Remove 羲宎蚔牁.exe - Powered by Reason Core Security