setup_9513_46395.exe

闪压

天行信息技术有限公司

The executable setup_9513_46395.exe has been detected as malware by 27 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.tnmbx01.com.
Publisher:
天行信息技术有限公司

Product:
闪压

Description:
闪压安装程序

Version:
1, 0, 0, 6.1

MD5:
1bdeb37e307184431c1e36413a24e0f7

SHA-1:
4c30da6697471021e947c61ae3047960cc21d23b

SHA-256:
903633feba2699f68810238d74fdddfe19283d7886dc37b15c222cbd5ba19eef

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
5/17/2024 6:09:45 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.55410
214

Agnitum Outpost
Packed/Upack
7.1.1

AhnLab V3 Security
Trojan/Win32.HDC
2015.09.17

Avira AntiVirus
TR/Crypt.XPACK.Gen2
8.3.2.2

Arcabit
Trojan.Symmi.DD872
1.0.0.541

avast!
Win32:Dropper-gen [Drp]
2014.9-160704

AVG
upack
2017.0.2692

Baidu Antivirus
Trojan.Win32.Upack
4.0.3.1674

Bitdefender
Gen:Variant.Symmi.55410
1.0.20.930

Clam AntiVirus
Win.Trojan.Maozhi
0.98/21511

Comodo Security
TrojWare.Win32.GameThief.Nilage.~CRSA
23247

Dr.Web
DLOADER.Trojan
9.0.1.0186

Emsisoft Anti-Malware
Gen:Variant.Symmi.55410
8.16.07.04.06

F-Secure
Gen:Variant.Symmi.55410
11.2016-04-07_2

G Data
Gen:Variant.Symmi.55410
16.7.25

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.210.17239

McAfee
Artemis!1BDEB37E3071
5600.6348

Microsoft Security Essentials
VirTool:Win32/Obfuscator.C
1.1.12002.0

MicroWorld eScan
Gen:Variant.Symmi.55410
17.0.0.558

NANO AntiVirus
Trojan.Win32.XPACK.dfporj
0.30.24.3283

Panda Antivirus
Trj/Genetic.gen
16.07.04.06

Sophos
Mal/EncPk-BW
4.98

Total Defense
Heur/TrojanHorse.ZCGJ!suspicious
37.1.62.1

Trend Micro House Call
PAK_Generic.006
7.2.186

Trend Micro
PAK_Generic.006
10.465.04

VIPRE Antivirus
Packed.Win32.Upack
43806

File size:
3.6 MB (3,794,270 bytes)

Product version:
1, 0, 0, 6

Copyright:
Copyright (C) 2014 天行信息技术有限公司

Original file name:
Install

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup_9513_46395.exe

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
0.57

CTPH (ssdeep):
98304:894ovO4dUGWB0f+2a3u/4jn/TV+wV6BriEdeZiNd4Vg35+0G:89OeG0f7n/4ruB3wg4a3FG

Entry address:
0x87C0EC

Entry point:
60, E8, 09, 00, 00, 00, 6A, BF, 87, 00, E9, 06, 02, 00, 00, 33, C9, 5E, 87, 0E, E3, F4, 2B, F1, 8B, DE, AD, 2B, D8, AD, 03, C3, 50, 97, AD, 91, F3, A5, 5E, AD, 56, 91, 01, 1E, AD, E2, FB, AD, 8D, 6E, 10, 01, 5D, 00, 8D, 7D, 1C, B5, 1C, F3, AB, 5E, AD, 53, 50, 51, 97, 58, 8D, 54, 85, 5C, FF, 16, 72, 57, 2C, 03, 73, 02, B0, 00, 3C, 07, 72, 02, 2C, 03, 50, 0F, B6, 5F, FF, C1, E3, 03, B3, 00, 8D, 1C, 5B, 8D, 9C, 9D, 0C, 10, 00, 00, B0, 01, E3, 29, 8B, D7, 2B, 55, 0C, 8A, 2A, 33, D2, 84, E9, 0F, 95, C6, 52, FE...
 
[+]

Entropy:
7.9967

Packer / compiler:
WinUpack v0.39 final (relocated image base)

Code size:
1.3 MB (1,377,280 bytes)

The file setup_9513_46395.exe has been seen being distributed by the following URL.

Remove setup_9513_46395.exe - Powered by Reason Core Security