hfxrushloader.exe

浩方登陆器

Shanghai Holdfast Online Information Technology Co. Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘xrush’.
Publisher:
上海浩方在线信息技术有限公司  (signed by Shanghai Holdfast Online Information Technology Co. Ltd.)

Product:
浩方登陆器

Version:
1.0.0.601

MD5:
3b6b5dc98703f9d52f4c7fb377ef7296

SHA-1:
d374a68812d23c5da95ec0c367c20e5a7ea45627

SHA-256:
e78ad72958684a544bc246c438e1917a459e715ecc636ef134854a24f9003e14

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 7:14:00 AM UTC  (today)

File size:
215.9 KB (221,120 bytes)

Product version:
1.0.0.601

Copyright:
版权所有(C) 2011,上海浩方在线信息技术有限公司. 保留所有权利.

Original file name:
浩方登陆器

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\Program Files\xrushhf\hfxrushloader.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/9/2010 7:00:00 AM

Valid to:
9/7/2013 6:59:59 AM

Subject:
CN=Shanghai Holdfast Online Information Technology Co. Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Shanghai Holdfast Online Information Technology Co. Ltd., L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
32DFBEB9914DE39E73A0E7B35976D09E

File PE Metadata
Compilation timestamp:
6/3/2011 8:46:28 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:+tFmUm0gNdEPMl2+bxbIHBsiMlNvqt8OEX1luaYpCmiH4NG88bpLcu:+LKEPnSx8qiMLiKOEmaaiEGdFl

Entry address:
0x63170

Entry point:
60, BE, 00, 90, 44, 00, 8D, BE, 00, 80, FB, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.3841

Packer / compiler:
UPX 2.90LZMA

Code size:
108 KB (110,592 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
xrush

Command:
C:\Program Files\xrushhf\hfxrushloader.exe


Scan hfxrushloader.exe - Powered by Reason Core Security