install.exe

xCore LLC

The executable install.exe has been detected as malware by 13 anti-virus scanners. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
xCore LLC  (signed and verified)

MD5:
7fe2b70ec575bf57eabf306daca78633

SHA-1:
39517b05df0b192638d4a5953545787b10adacaa

SHA-256:
61ad05d70f7eb7b3c22cdc51eb74970f2d261728900fbc9aac394c0cf29c2fe9

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
4/24/2024 10:46:19 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur2.FU.kqX@auoxCKpc
1014

Avira AntiVirus
TR/Rogue.46153
7.11.145.90

AVG
Crypt3.KUU.dropper
2015.0.3492

Bitdefender
Gen:Trojan.Heur2.FU.kqX@auoxCKpc
1.0.20.585

Dr.Web
Trojan.PWS.Wsgame.43600
9.0.1.0117

Emsisoft Anti-Malware
Gen:Trojan.Heur2.FU.kqX@auoxCKpc
8.14.04.27.06

F-Secure
Gen:Trojan.Heur2.FU.kqX@auoxCKpc
11.2014-27-04_1

G Data
Gen:Trojan.Heur2.FU.kqX@auoxCKpc
14.4.24

IKARUS anti.virus
Trojan.Win32.Spy2.FU
t3scan.1.6.1.0

McAfee
Artemis!7FE2B70EC575
5600.7148

MicroWorld eScan
Gen:Trojan.Heur2.FU.kqX@auoxCKpc
15.0.0.351

Trend Micro House Call
TROJ_GEN.F47V0414
7.2.117

VIPRE Antivirus
Trojan.Win32.Generic
28606

File size:
173.6 KB (177,736 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
8/21/2013 5:53:58 PM

Valid to:
8/22/2014 5:53:58 PM

Subject:
E=messages@avxcore.com, CN=xCore LLC, O=xCore LLC, L=Orsk, S=Orenburg, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112150E0FC36F98134C795FC9A4047CAEB9E

File PE Metadata
Compilation timestamp:
4/11/2014 7:35:27 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:U7FOFxKJW85TT7W3FuDD7uQOPsdiH+8qrg:OCKv5TGwmQbYv

Entry address:
0x1A92

Entry point:
55, 8B, EC, 81, EC, 1C, 01, 00, 00, 53, 56, 57, 6A, 04, 68, 00, 10, 00, 00, BE, 58, 02, 00, 00, 56, 6A, 00, FF, 15, 64, 20, 40, 00, 56, 8B, F8, 57, 6A, 00, FF, 15, 58, 20, 40, 00, 8B, 35, 60, 20, 40, 00, 57, FF, D6, BB, 24, 25, 40, 00, 53, 89, 45, FC, FF, D6, 8B, 4D, FC, 2B, C8, 33, C0, 66, 89, 44, 4F, FE, FF, 15, 54, 20, 40, 00, 8D, 4D, F8, 51, 50, FF, 15, 78, 20, 40, 00, 83, 7D, F8, 01, 89, 45, FC, 75, 5B, 85, C0, 74, 07, 50, FF, 15, 50, 20, 40, 00, BE, 14, 01, 00, 00, 56, 8D, 85, E4, FE, FF, FF, 6A, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3 KB (3,072 bytes)

Remove install.exe - Powered by Reason Core Security