xy1patch.exe

XYPatch 应用程序

NetEase(Hangzhou)Network Tech.Co.,Ltd.

The executable xy1patch.exe, “XYPatch Microsoft 基础类应用程序” has been detected as malware by 6 anti-virus scanners.
Publisher:
网易公司  (signed by NetEase(Hangzhou)Network Tech.Co.,Ltd.)

Product:
XYPatch 应用程序

Description:
XYPatch Microsoft 基础类应用程序

Version:
2, 0, 0, 1

MD5:
8b1b853c7887e8e5289594ceaba5edc6

SHA-1:
ff752e5071d271bc0327647db933327902c4a5ec

SHA-256:
a2bd182efe8ea31a32ebfa17572d15860481c756ffaa526f4fbccd1efebc17ab

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
4/25/2024 5:07:31 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/Themida
7.1.1

Bkav FE
HW32.Packed
1.3.0.4959

Dr.Web
Trojan.Spambot.4139
9.0.1.0298

IKARUS anti.virus
Trojan.Win32.VBKrypt
t3scan.1.8.3.0

VIPRE Antivirus
Trojan.Win32.Generic
34878

Zillya! Antivirus
Trojan.KillAV.Win32.7798
2.0.0.1984

File size:
832.2 KB (852,152 bytes)

Product version:
2, 0, 0, 1

Copyright:
版权所有 (C) 2001,2003

Original file name:
XYPatch.EXE

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\Program Files\????\xy1patch.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/29/2009 8:00:00 PM

Valid to:
8/14/2010 7:59:59 PM

Subject:
CN="NetEase(Hangzhou)Network Tech.Co.,Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="NetEase(Hangzhou)Network Tech.Co.,Ltd.", L=hangzhou, S=hangzhou, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2FB6380D1C63861957EB225D247FFAC6

File PE Metadata
Compilation timestamp:
8/17/2009 4:02:51 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:+IJ3xzSrlFXRVNWPEXAOtiFU+g4LSqBCV:9J3x0XRHh/8FU+ZSvV

Entry address:
0x43014

Entry point:
B8, 00, 00, 00, 00, 60, 0B, C0, 74, 68, E8, 00, 00, 00, 00, 58, 05, 53, 00, 00, 00, 80, 38, E9, 75, 13, 61, EB, 45, DB, 2D, 37, 30, 44, 00, FF, FF, FF, FF, FF, FF, FF, FF, 3D, 40, E8, 00, 00, 00, 00, 58, 25, 00, F0, FF, FF, 33, FF, 66, BB, 19, 5A, 66, 83, C3, 34, 66, 39, 18, 75, 12, 0F, B7, 50, 3C, 03, D0, BB, E9, 44, 00, 00, 83, C3, 67, 39, 1A, 74, 07, 2D, 00, 10, 00, 00, EB, DA, 8B, F8, B8, B1, 3C, 0F, 00, 03, C7, B9, 6D, 32, 04, 00, 03, CF, EB, 0A, B8, B1, 3C, 4F, 00, B9, 6D, 32, 44, 00, 50, 51, E8, 87...
 
[+]

Entropy:
7.8879

Packer / compiler:
Themida/WinLicense V1.8.0.2 +

Code size:
176 KB (180,224 bytes)

Remove xy1patch.exe - Powered by Reason Core Security