crsetup_full.exe

Chinese Reader

Loqu8, Inc.

This is a setup and installation application. The file has been seen being downloaded from download.loqu8.net.
Publisher:
MDBG   (signed by Loqu8, Inc.)

Product:
Chinese Reader

Description:
Chinese Reader Installation

Version:
6.8.2.370

MD5:
e73d7c711a063eae06085abbf554733a

SHA-1:
7f9fe64d2a969ffa2a8a1f99444947d3b156853f

SHA-256:
720ea784cf8712fb2fb6cf8368448ada36f82e905c9fc3e3f37a144c3544a978

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 6:01:12 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
TrojWare.Win32.TrojanDropper.Agent.PNA
20417

Dr.Web
Trojan.Hoster.661
9.0.1.0362

NANO AntiVirus
Trojan.Win32.GameHack.dcjlni
0.28.6.64267

File size:
40.6 MB (42,582,552 bytes)

Product version:
6.8.2.370

Copyright:
Copyright © 2007-13 Loqu8. All rights reserved worldwide.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\crsetup_full.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
5/8/2011 7:00:00 PM

Valid to:
5/8/2014 6:59:59 PM

Subject:
CN="Loqu8, Inc.", O="Loqu8, Inc.", STREET=2272 Towne Cir, L=Mountain View, S=CA, PostalCode=94040, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00D647634AC81E0DE83AA479D491FF1046

File PE Metadata
Compilation timestamp:
4/14/2013 11:48:13 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
786432:2EswKbporBBbBkr4O/TFFBgtqQfpWDE8Eq3gMdQZ8SiBThmHl:nVwiBBbuLFBEFfpWS0+8ql

Entry address:
0x1808F

Entry point:
E8, 6A, 3B, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 38, 73, 42, 00, E8, 97, F9, FF, FF, 6A, 0E, E8, AB, 1C, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, 04, D4, 42, 00, BA, 00, D4, 42, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, D2, F2, FF, FF, 59, FF, 76, 04, E8, C9, F2, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, 86, F9, FF, FF, C3, 8B, D0, EB, C5, 6A, 0E, E8, 76, 1B, 00, 00, 59, C3, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
7.9989  (probably packed)

Code size:
123 KB (125,952 bytes)

The file crsetup_full.exe has been seen being distributed by the following URL.

Scan crsetup_full.exe - Powered by Reason Core Security