龍族補血程式.exe

QMacro

fuzhou tian xia chuang shi digital Co.,Ltd

The executable 龍族補血程式.exe, “QMacro's macro runner.” has been detected as malware by 10 anti-virus scanners.
Publisher:
vrBrothers Corporation.   (signed by fuzhou tian xia chuang shi digital Co.,Ltd)

Product:
QMacro

Description:
QMacro's macro runner.

Version:
9, 3, 1, 11269

MD5:
31bfc8a8d53d1e542d79bb4325122680

SHA-1:
f804d3565eca394ee6a8a29d3fb98c8a5a840080

SHA-256:
995c14ce0a091af612f44649026b8f14e9f7789ba760d9e2c77c29eeb3ea8d3a

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
4/24/2024 10:52:51 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.KeyLogger
7.1.1

Avira AntiVirus
TR/Drop.Small.joq
7.11.215.136

AVG
Dropper.Generic6
2018.0.2505

Clam AntiVirus
Win.Trojan.Small-7266
0.98/21511

McAfee
Bot-FGM!31BFC8A8D53D
5600.6161

NANO AntiVirus
Trojan.Win32.Drop.cucmbm
0.30.0.296

Norman
Smalltroj.ABDHX
11.20170107

Qihoo 360 Security
Win32/Trojan.1f8
1.0.0.1015

Trend Micro House Call
HV_SMALL_BK0836A8.TOMC
7.2.7

Zillya! Antivirus
Dropper.Small.Win32.9093
2.0.0.2092

File size:
2.6 MB (2,738,992 bytes)

Product version:
9, 3, 1, 11269

Copyright:
(C) vrBrothers Corporation. All rights reserved.

Original file name:
mymacro.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\08\龍族自動喝水\龍族補血程式.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/12/2011 8:00:00 AM

Valid to:
4/12/2013 7:59:59 AM

Subject:
CN="fuzhou tian xia chuang shi digital Co.,Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="fuzhou tian xia chuang shi digital Co.,Ltd", L=fuzhou, S=fujian, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
209E746C15A85E547AFAF6A4C3277C81

File PE Metadata
Compilation timestamp:
7/30/2012 11:42:03 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x61328

Entry point:
55, 8B, EC, 6A, FF, 68, 20, 51, 4D, 00, 68, 2E, 12, 46, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 60, 7F, 4B, 00, 59, 83, 0D, A0, F6, 56, 00, FF, 83, 0D, A4, F6, 56, 00, FF, FF, 15, 5C, 7F, 4B, 00, 8B, 0D, 3C, 8F, 54, 00, 89, 08, FF, 15, 58, 7F, 4B, 00, 8B, 0D, 38, 8F, 54, 00, 89, 08, A1, 54, 7F, 4B, 00, 8B, 00, A3, 9C, F6, 56, 00, E8, D0, 01, 00, 00, 39, 1D, F8, 65, 52, 00, 75, 0C, 68, 64, 15, 46, 00, FF, 15, 50, 7F...
 
[+]

Entropy:
5.8109

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
728 KB (745,472 bytes)

Remove 龍族補血程式.exe - Powered by Reason Core Security