LiuCAI.exe

嘸蝦米輸入法工具集

行易有限公司

The executable LiuCAI.exe has been detected as malware by 11 anti-virus scanners. While running, it connects to the Internet address boshiamy.com on port 80 using the HTTP protocol.
Publisher:
行易有限公司

Product:
嘸蝦米輸入法工具集

Version:
2.0.0.0

MD5:
0e77545c17ced61eebf341b68a94b795

SHA-1:
1831a4314c4d9b9de0fd9992259d9f90d3a89067

SHA-256:
fab06a27a9bf2fed70c35097d1c65af05ca8ddacd0888e5aac64b58df05778a3

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
4/19/2024 3:16:14 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.JP.dmKfaqxTz3cb
848

Avira AntiVirus
TR/Spy.56320.265
7.11.160.154

Bitdefender
Gen:Trojan.Heur.JP.dmKfaqxTz3cb
1.0.20.1410

Comodo Security
UnclassifiedMalware
18849

Emsisoft Anti-Malware
Gen:Trojan.Heur.JP.dmKfaqxTz3cb
8.14.10.09.10

F-Secure
Gen:Trojan.Heur.JP.dmKfaqxTz3cb
11.2014-09-10_5

G Data
Gen:Trojan.Heur.JP.dmKfaqxTz3cb
14.10.24

IKARUS anti.virus
Trojan.Win32.Spy
t3scan.1.6.1.0

MicroWorld eScan
Gen:Trojan.Heur.JP.dmKfaqxTz3cb
15.0.0.846

Norman
Suspicious_Gen5.APEFR
11.20141009

Trend Micro House Call
TROJ_GEN.F47V0429
7.2.282

File size:
55 KB (56,320 bytes)

Product version:
2.0.0.0

Copyright:
Copyright (C) 2012-2013 Boshiamy C&C Ltd.

Original file name:
LiuCAI.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
5/12/2013 4:02:11 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:jTY6pz/WJhVWM5Lrb77frInouy87C284lUh:fYEz295/bXrgout7C2sh

Entry address:
0x21380

Entry point:
60, BE, 00, 70, 41, 00, 8D, BE, 00, A0, FE, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 3E, FD, 01, 00, 57, 83, C3, 04, 53, 68, 76, A3, 00, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Entropy:
7.7552  (probably packed)

Code size:
44 KB (45,056 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to boshiamy.com  (208.113.170.48:80)

Remove LiuCAI.exe - Powered by Reason Core Security