xecprobeloader.exe

XECURE LAB CO., LTD.

The executable xecprobeloader.exe has been detected as malware by 7 anti-virus scanners.
Publisher:
XECURE LAB CO., LTD.  (signed and verified)

MD5:
7f8c295f5b0e0ab0a1059d62abd6f782

SHA-1:
419b350167b1e01b02330f47ca3505627f8a6a8f

SHA-256:
91e41d8213e03751e0a52aac29a41eebcc7b3a1facd0ee6126d5c105dc896b7d

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/26/2024 5:20:10 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Black.Gen2
7.11.91.16

Comodo Security
UnclassifiedMalware
16609

ESET NOD32
Win32/Packed.VMProtect.ABD (variant)
8.8581

Fortinet FortiGate
W32/Generic
7/30/2014

McAfee
Artemis!7F8C295F5B0E
5600.7054

Sophos
Mal/Behav-363
4.91

Trend Micro House Call
TROJ_GEN.F47V0701
7.2.211

File size:
2.4 MB (2,480,688 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/17/2012 8:00:00 AM

Valid to:
9/18/2014 7:59:59 AM

Subject:
CN="XECURE LAB CO., LTD.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="XECURE LAB CO., LTD.", L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
212CA239866F88C3D5B000B3004A569C

File PE Metadata
Compilation timestamp:
6/17/2013 8:33:02 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:tqSFKoYjEyPV1g14B/L82a2+wTGAuSewNdniLY3hvg2E4wjZJFZ8ci+K:tqqMH21uL2hwTGAjewN3R4JnFZ8cVK

Entry address:
0x2797CB

Entry point:
9C, 8D, 64, 24, 04, 0F, 8B, CD, CB, 22, 00, 60, C7, 44, 24, 1C, 77, AF, 15, 85, E8, B7, D4, 24, 00, C1, 7B, 6F, 98, D8, 2F, D5, 2D, A3, 25, 94, EB, A2, 50, AD, 8D, 5E, 34, 75, 59, 72, 04, 79, B9, 99, C3, E0, 9E, 6E, 9C, AC, 8D, 22, D3, 8E, 21, EF, 55, 9F, 24, B4, 6F, C3, E8, 78, DB, DF, 68, 88, 63, F7, 80, 70, 3F, 03, 40, 40, DF, 23, 48, 18, 93, 47, C4, B5, 2D, 7C, 4D, C1, F7, 45, 46, 35, 99, 3C, A5, C7, CB, 50, 36, 1D, 5B, C1, C8, EE, 7C, 19, 58, F4, 89, 09, 52, 46, 89, 98, 9F, 29, 85, CA, 24, 81, 1A, F0...
 
[+]

Entropy:
7.9950  (probably packed)

Code size:
125.5 KB (128,512 bytes)

Remove xecprobeloader.exe - Powered by Reason Core Security