desksd123_configure.exe

速达桌面版

Beijing Tuo Lang Technology Co., Ltd

The executable desksd123_configure.exe has been detected as malware by 7 anti-virus scanners.
Publisher:
速达桌面版主程序  (signed by Beijing Tuo Lang Technology Co., Ltd)

Product:
速达桌面版

Description:
速达桌面版主程序

Version:
1.3.7.30

MD5:
a1cacc7f10f4bb8540e171238641d954

SHA-1:
8e2406257c679c1c0fe428ecf35637e2588dedf6

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/26/2024 11:31:50 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AegisLab AV Signature
DangerousObject.Multi.Gen
2.1.4+

Bkav FE
W32.Clod6b0.Trojan
1.3.0.4923

Emsisoft Anti-Malware
Win32.Expiro.BK
8.15.03.22.10

ESET NOD32
Win32/FlyStudio (variant)
9.9359

IKARUS anti.virus
Trojan.Win32.Pasta
t3scan.2.2.29

McAfee
Artemis!A1CACC7F10F4
5600.6819

Trend Micro House Call
TROJ_GEN.F47V0718
7.2.81

File size:
3.6 MB (3,751,976 bytes)

Product version:
1.3.7.30

Copyright:
速达桌面版主程序

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\soft\files\wzsd123\desksd123_configure.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/26/2012 8:00:00 AM

Valid to:
9/25/2014 7:59:59 AM

Subject:
CN="Beijing Tuo Lang Technology Co., Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing Tuo Lang Technology Co., Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
32D2EA5448D5823DACFDD58DCAD631A8

File PE Metadata
Compilation timestamp:
7/5/2013 3:42:26 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:ijPeUu4BiZaPDsdyUQQOxbjFYY8XtViMsNg:I2UrBiZaOyURCYBXtViBN

Entry address:
0x8962C0

Entry point:
60, BE, 00, D0, 92, 00, 8D, BE, 00, 40, AD, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 4D, 44, 89, 00, 57, 83, C3, 04, 53, 68, BD, 92, 36, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Entropy:
7.9754  (probably packed)

Code size:
3.4 MB (3,579,904 bytes)

Remove desksd123_configure.exe - Powered by Reason Core Security