xinput1_3.zip.exe

ucc22

The application xinput1_3.zip.exe by ucc22 has been detected as a potentially unwanted program by 14 anti-malware scanners.
Publisher:
ucc22  (signed and verified)

MD5:
0cd969c4b10272846e56b4f2e63f0cb7

SHA-1:
4c81493c66eb868637e94e11646fdae34f98fa68

SHA-256:
1943756e2be0ea7a26b89b898e9e7d51a390b5c51abfa8fc6ac0b40f3b361352

Scanner detections:
14 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 9:32:35 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.MulDown
2013.02.11

Avira AntiVirus
SPR/Tool.954814
7.11.60.154

AVG
Generic5
2017.0.2719

Bitdefender
Application.Generic.468677
1.0.20.795

Comodo Security
UnclassifiedMalware
15223

ESET NOD32
Win32/Adware.Kraddare.FY (variant)
10.7992

F-Secure
Application.Generic.468677
11.2016-07-06_3

G Data
Application.Generic.468677
16.6.22

IKARUS anti.virus
AdWare.Win32.Kraddare
t3scan.1.3.5.0

MicroWorld eScan
Application.Generic.468677
17.0.0.477

Panda Antivirus
Suspicious file
16.06.07.06

Trend Micro House Call
TROJ_SPNR.09A313
7.2.159

Trend Micro
TROJ_SPNR.09A313
10.465.07

VIPRE Antivirus
Trojan.Win32.Generic
15480

File size:
932.4 KB (954,776 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\Music\들을만하군\xinput1_3.zip.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/13/2012 9:00:00 AM

Valid to:
6/14/2013 8:59:59 AM

Subject:
CN=ucc22, OU=Management, O=ucc22, L=Yongin-si, S=Gyeonggi-do, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
14BA1A66053A94827BDF1F62C79FBDCD

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:ScoLqDmtr2mJfs6ep3OwiRwngdCLDHiyJQjqbJNHTWA+NrCegj8:SNm0zt83OZ1dKDCXODzWA+NrC7w

Entry address:
0xBDBFC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 74, D5, 4B, 00, E8, 30, 88, F4, FF, 33, C0, 55, 68, 58, DC, 4B, 00, 64, FF, 30, 64, 89, 20, A1, 6C, 19, 4C, 00, 8B, 00, E8, 7A, 33, FB, FF, 8B, 0D, 78, 1B, 4C, 00, A1, 6C, 19, 4C, 00, 8B, 00, 8B, 15, F4, 84, 4B, 00, E8, 7A, 33, FB, FF, A1, 6C, 19, 4C, 00, 8B, 00, E8, EE, 33, FB, FF, 33, C0, 5A, 59, 59, 64, 89, 10, 68, 5F, DC, 4B, 00, C3, E9, 5B, 5E, F4, FF, EB, F8, E8, 7C, 63, F4, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6631

Developed / compiled with:
Microsoft Visual C++

Code size:
755.5 KB (773,632 bytes)

Remove xinput1_3.zip.exe - Powered by Reason Core Security