xdm.exe

XDM

Subhra Das Gupta

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘xdm’.
Publisher:
Subhra Das Gupta

Product:
XDM

Description:
Xterme Download Manager

Version:
4.0.0.0

MD5:
b4cd3471e36522fbf22f3662d2ea601f

SHA-1:
99db20ce3c57f810eee729979294e2057df3db62

SHA-256:
753e7bc33667ecf00c20c94ad90442f10cc5df91f7260efd0bd2ec8d0d6b19ed

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 6:30:59 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Trojan.Win32.Dapato
4.0.3.14221

Kaspersky
Trojan-Dropper.Win32.Dapato
14.0.0.4278

Qihoo 360 Security
Win32/Trojan.Multi.daf
1.0.0.1015

File size:
598.5 KB (612,864 bytes)

Product version:
4.0.0.0

Copyright:
Copyright © 2014

Original file name:
xdm.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\xdm\xdm.exe

File PE Metadata
Compilation timestamp:
2/15/2014 7:23:31 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:4B3EuRMY1PJjG5sP+/ICIGXBBICIGXBEICIGXBLICIGXB9ICIGXBEICIGXBcICI1:yMY1BGyFnuv

Entry address:
0x92DAE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 03, 00, 03, 00, 00, 00, 28, 00, 00, 80, 0E, 00, 00, 00, 40, 00, 00, 80, 10, 00, 00, 00, 58, 00, 00, 80, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5864

Code size:
579.5 KB (593,408 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
xdm

Command:
C:\users\{user}\appdata\local\xdm\xdm.exe -m


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to lynx.ninite.com  (198.58.113.72:80)

TCP (HTTP):
Connects to lhr14s19-in-f3.1e100.net  (173.194.34.67:80)

Scan xdm.exe - Powered by Reason Core Security