ssczhixuanss.exe is usually located in the 'c:\downloads\' folder.
Some of the anti-virus scanners at VirusTotal detected ssczhixuanss.exe.
If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.
ssczhixuanss.exe is not signed.
41 of the 69 anti-virus programs at VirusTotal detected the ssczhixuanss.exe file. That's a 59% detection rate.
| Scanner | Detection Name |
|---|---|
| Ad-Aware | Trojan.GenericKD.40539080 |
| AhnLab-V3 | Worm/Win32.FlyStudio.C73982 |
| ALYac | Trojan.GenericKD.40539080 |
| Avast | Win32:Trojan-gen |
| AVG | Win32:Trojan-gen |
| Avira | HEUR/AGEN.1008336 |
| AVware | Trojan.Win32.Autorun.dm (v) |
| BitDefender | Trojan.GenericKD.40539080 |
| ClamAV | Win.Trojan.Hupigon-16689 |
| CMC | Trojan-Dropper.Win32.Flystud!O |
| Cybereason | malicious.0cbcb5 |
| Cylance | Unsafe |
| Cyren | W32/Nuj.A.gen!Eldorado |
| Emsisoft | Trojan.GenericKD.40539080 (B) |
| Endgame | malicious (high confidence) |
| ESET-NOD32 | a variant of Win32/Packed.FlyStudio potentially unwanted |
| F-Prot | W32/Nuj.A.gen!Eldorado |
| F-Secure | Trojan.GenericKD.40539080 |
| GData | Trojan.GenericKD.40539080 |
| Ikarus | Trojan-Dropper.Agent |
| Invincea | heuristic |
| K7AntiVirus | Adware ( 004b897e1 ) |
| K7GW | Adware ( 004b897e1 ) |
| MAX | malware (ai score=86) |
| McAfee | Artemis!06BE3AC11A99 |
| McAfee-GW-Edition | BehavesLike.Win32.Virus.tc |
| Microsoft | Worm:Win32/Nuj.A |
| MicroWorld-eScan | Trojan.GenericKD.40539080 |
| NANO-Antivirus | Trojan.Win32.FlyStudio.dswuoo |
| Panda | Trj/Genetic.gen |
| Qihoo-360 | Win32/Trojan.845 |
| Rising | Worm.Nuj!8.2AD (CLOUD) |
| SentinelOne | static engine - malicious |
| Sophos | W32/SillyFDC-DX |
| Symantec | ML.Attribute.HighConfidence |
| VBA32 | Trojan.Genome.rv |
| VIPRE | Trojan.Win32.Autorun.dm (v) |
| Webroot | W32.Malware.Gen |
| Yandex | Worm.Nuj!th50vHrIoRk |
| Zillya | Worm.AutoRun.Win32.2 |
| Zoner | Trojan.tDeEiPkbb |
The following information was gathered by executing the file inside Cuckoo Sandbox.
Successfully executed process in sandbox.
{
"file_created": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\HtmlView.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\internet.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EThread.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext2.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eGrid.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eAPI.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\shell.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\commobj.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\krnln.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\spec.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext3.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\RegEx.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext5.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EXMLParser.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\dp1.fne"
],
"directory_created": [
"d:\\Dosame\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4"
],
"dll_loaded": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EThread.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\commobj.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\shell.fne",
"kernel32.dll",
"UxTheme.dll",
"C:\\Windows\\system32\\ole32.dll",
"dwmapi.dll",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\shell.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\commobj.fnr",
"C:\\Windows\\syswow64\\MSCTF.dll",
"C:\\Windows\\winhlp32.exe",
"OLEAUT32.DLL",
"comctl32",
"IMM32.dll",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext5.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext5.fne",
"User32.dll",
"comctl32.dll",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext2.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eGrid.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\krnln.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EThread.fnr",
"Gdi32.dll",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eGrid.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext2.fnr",
"Kernel32.dll",
"COMCTL32.DLL"
],
"file_opened": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\8168d339706c26fc573c1bd2be2d83e7ba513bd8c0fd683246dd86242e8f0a2f.bin",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Control Panel\\Desktop",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\VFW",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\8168d339706c26fc573c1bd2be2d83e7ba513bd8c0fd683246dd86242e8f0a2f.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}"
],
"file_written": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\HtmlView.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\internet.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EThread.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext2.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eGrid.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eAPI.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\shell.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\commobj.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\krnln.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\spec.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext3.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\RegEx.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext5.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EXMLParser.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\dp1.fne"
],
"file_failed": [
"d:\\Dosame\\\u00d3\u00c3\u00bb\u00a7\u00d7\u00a2\u00d2\u00e2.txt",
"d:\\",
"C:\\Windows\\System32\\Lendsoft.txt"
],
"file_read": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\8168d339706c26fc573c1bd2be2d83e7ba513bd8c0fd683246dd86242e8f0a2f.bin"
],
"regkey_read": [
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\Segoe UI",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\MS Shell Dlg",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInterval",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInset",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollDelay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations",
"HKEY_CURRENT_USER\\Control Panel\\Desktop\\WheelScrollLines"
]
}[
{
"yara": [],
"sha1": "dc29b98b123f4139fc135bfac4e0fba7ef66e261",
"name": "35941fa6a29c72dc_egrid.fne",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eGrid.fne",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "35941fa6a29c72dc96e355ecc41a02fd8274af1f109ffa1a74bd7dc5a19d6490",
"urls": [
"http:\/\/dywt.com.cn"
],
"crc32": "3B50CB65",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/35941fa6a29c72dc_egrid.fne",
"ssdeep": null,
"size": 430080,
"sha512": "e4b3a4f04dd2dc0b240816d0d4b135b0037633a03e3b4c5e8e1497935bfef71e991a90408f17dba545fb0f1b7e65a9da6e4ab301faebef1dc04ef001be0736b8",
"pids": [
2016
],
"md5": "adaeb3f6dc98280188ec2b234fcd75c4"
},
{
"yara": [],
"sha1": "f2bc1d0d3c77b65694bc300b02da06670dfe5b7e",
"name": "e9b6a384ba5b4314_iext2.fne",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext2.fne",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "e9b6a384ba5b43145151a737d9c8373c0045408898270b708999ebf616324911",
"urls": [],
"crc32": "79FA5100",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/e9b6a384ba5b4314_iext2.fne",
"ssdeep": null,
"size": 252416,
"sha512": "b747f581d4c179f9d6aa12bd34f90c69a8ca12e3c8845876a9cb64d70331d160f4ec7ee30960ab85f8d9245df68b42c66340492182bcbc00e082a4fc7bc732f5",
"pids": [
2016
],
"md5": "c4bafccca1b2e9eca798d806f1469e68"
},
{
"yara": [],
"sha1": "353c621bb52cf6f92cee8aa909805c5f0e2d83c4",
"name": "7e05841502acca93_krnln.fnr",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\krnln.fnr",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "7e05841502acca9359d0512ecf2949ffbfdde7eee68f018ff79555d0e4adbc5d",
"urls": [],
"crc32": "6E684D5F",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/7e05841502acca93_krnln.fnr",
"ssdeep": null,
"size": 510976,
"sha512": "84c714757ad75f44041fc666a3999972bbee44e6cac7283365acc3a46c70b06e6b56a5c804d85fb65b43b74189ec0fd4488f14f692decc333536e426178f0a9b",
"pids": [
2016
],
"md5": "973fdd23f5f951e2251ca9e5023a07bf"
},
{
"yara": [],
"sha1": "bd35b9f4a2338a2ee379cc1e1528b05ff9a77d2f",
"name": "69eaa088634ab34f_eapi.fne",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eAPI.fne",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "69eaa088634ab34f55a745617ec9e3ea7c6bfd0bd04e09685a531cd510a814df",
"urls": [
"http:\/\/dywt.com.cn",
"http:\/\/www.microsoft.com"
],
"crc32": "5B31AF16",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/69eaa088634ab34f_eapi.fne",
"ssdeep": null,
"size": 335872,
"sha512": "0df90738f8f93874760a19ebe79a381c25755da8486770b846ac44f593b2b8b455255b702771af1183528b727d05286f3eb981fae5bf6fe2844b5e849299cf90",
"pids": [
2016
],
"md5": "a9cc5ac8af486090335a7e6b184ca79b"
},
{
"yara": [],
"sha1": "d79ec510795f3684daa55890c1aae7b7068a2100",
"name": "511ec71f077ba20b_commobj.fne",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\commobj.fne",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "511ec71f077ba20b2183b6be557c5f373066f06fff6ed9b0234d026609b346d6",
"urls": [
"http:\/\/dywt.com.cn"
],
"crc32": "DC5CCA40",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/511ec71f077ba20b_commobj.fne",
"ssdeep": null,
"size": 106496,
"sha512": "45120b2652fbfa9c6373902d5fbaf1a6f71541314f0f6bbc6d4f5142fd033944c6cdd16ffe4b9759450d489372a118030ea160ec67c50b50a48972c9947dd9b4",
"pids": [
2016
],
"md5": "1848fd790d88b3ff555a49125733db01"
},
{
"yara": [],
"sha1": "f04c440f5deb8aa3fce90028db044f4c9db937d9",
"name": "ac908f738082beda_exmlparser.fne",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EXMLParser.fne",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "ac908f738082beda2f733fca8f34e96151b0722febbcf790d49b66100114e715",
"urls": [
"http:\/\/dywt.com.cn"
],
"crc32": "55640E6D",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/ac908f738082beda_exmlparser.fne",
"ssdeep": null,
"size": 98304,
"sha512": "4942c1f4b418135c1efaf3894fd6b8bd5838d8d7cc6acaa981fa2d2d6ed622766d30982957b74051f9e99e4cb024e1807a0b602b978cdab38aa8a9564e3a9964",
"pids": [
2016
],
"md5": "dc5dac8cc9dfd9f8643bfb94b37dc025"
},
{
"yara": [],
"sha1": "d7b4a37c9de79ebd2a84904d08202c860a34eb05",
"name": "1e97c1aed1785b35_internet.fne",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\internet.fne",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "1e97c1aed1785b35076cd246086f2b254b71ef0f22400bfa056b05a43d766d79",
"urls": [
"http:\/\/dywt.com.cn"
],
"crc32": "889324BF",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/1e97c1aed1785b35_internet.fne",
"ssdeep": null,
"size": 196608,
"sha512": "c769d7de070c11b7d73f9d6deaf1db16cefa5b980c13ccd25ef25129ea3df51ec6d033265ee5fb466327781cc5360c34e8d1766663d01fd74f6b9c7323482be9",
"pids": [
2016
],
"md5": "43d82c51112e0f95b6b4770548584454"
},
{
"yara": [],
"sha1": "1ac380e5d8dd5c3b5f92a0fdaab7f9e83b6867c2",
"name": "09533a0e86418974_iext.fnr",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext.fnr",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "09533a0e86418974acf36dfd2f87b753a169890494bef4832c45811864b55d51",
"urls": [],
"crc32": "28223707",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/09533a0e86418974_iext.fnr",
"ssdeep": null,
"size": 217088,
"sha512": "1b39241d44dddf72248f3b38e7e8088aa23df4e74fef30580a671af59e45dc7c48a2cce7e3b628a8242db85fae535f2af03a6202cbe5ac73d170af05b147312e",
"pids": [
2016
],
"md5": "6c0b74908c48f17b7c280a8702de36da"
},
{
"yara": [],
"sha1": "fdba176231eb1b485445013b215cf777bfe0ee9d",
"name": "95fab08d70bf925c_shell.fne",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\shell.fne",
"type": "PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows",
"sha256": "95fab08d70bf925c513a6af41c984318d7c9f85eeef9aebc2bbbeddad2700157",
"urls": [
"http:\/\/dywt.com.cn"
],
"crc32": "754C2EBC",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/95fab08d70bf925c_shell.fne",
"ssdeep": null,
"size": 36864,
"sha512": "fcad00f6c71b3fe0aa0a4bfff38e3f203757ee9f6337763c06954608f81cbc901cfa57be624947e40a00d7abedbc956f1b1496d98402a73d0d8a278a61ac3571",
"pids": [
2016
],
"md5": "2031f65a11ab5c18073a2c12f7c50e03"
},
{
"yara": [],
"sha1": "aa546a03aa9fdd81a08b569fb8bd09aad6843f8e",
"name": "1aa9c8e466944014_iext5.fne",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext5.fne",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "1aa9c8e466944014db272f639d5fa79f86d6533f08d6a753cd379b17ba0b1cc6",
"urls": [],
"crc32": "F281EB67",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/1aa9c8e466944014_iext5.fne",
"ssdeep": null,
"size": 327680,
"sha512": "0c34b684ba58fb34ec79b090b0b288e9f9874c57b2f465caec3e15c278ec107729613a5152ced2a7227a8ac14a1915a8d9ff03a23cb5d528de3808c86c553fd7",
"pids": [
2016
],
"md5": "44509383fced4ffcfd46f28a45575fb5"
},
{
"yara": [],
"sha1": "b102c542f950ac959219355e4b9c2836b6b04852",
"name": "becc7e91e08ca903_ethread.fne",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EThread.fne",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "becc7e91e08ca9034c7de085fa16df6b41cd686b1b6db63edcfd52d4e589b57a",
"urls": [
"http:\/\/dywt.com.cn"
],
"crc32": "F48E7A5C",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/becc7e91e08ca903_ethread.fne",
"ssdeep": null,
"size": 49152,
"sha512": "533a6d71ed14ee801cd253eadc05b07a293af5e4b88fc5e14d1d4eb9d8b653f70ceef22cebb11c8cfa3fb24c5315565ee4ea35ed7fe0daa4cddf0b534b02d982",
"pids": [
2016
],
"md5": "d20b00bf558574821727fe2f643a41fa"
},
{
"yara": [],
"sha1": "c033169006bef68bebfa77405c4a35688ab41a99",
"name": "8027e7512cf17388_regex.fnr",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\RegEx.fnr",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "8027e7512cf17388b14c3e2bbf9c3700f875c26d942a4dd27d1dcf8203a192f8",
"urls": [],
"crc32": "6E8CC79C",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/8027e7512cf17388_regex.fnr",
"ssdeep": null,
"size": 217088,
"sha512": "16cb5cffdf935d10bb06b86b874a63e9594e4854359885890fe4641f0e4329fd047daa5f0ddd5a02d241974834b67666b2ad65ef791e110d29637434057808c4",
"pids": [
2016
],
"md5": "a67daddcb30335163cf7d99f282f5ae0"
},
{
"yara": [],
"sha1": "4dc87bcb639257b5b3562c56650f9359867cf2fe",
"name": "a8bc0f0835f6b126_spec.fne",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\spec.fne",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "a8bc0f0835f6b126c975745d328708b583930273c3b1ea83de97e9e56c59376b",
"urls": [
"http:\/\/dywt.com.cn"
],
"crc32": "3F4BE62C",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/a8bc0f0835f6b126_spec.fne",
"ssdeep": null,
"size": 81920,
"sha512": "10219bc0c9e69a7debddbad2265d5686a909fcd62cbff6dbbd6720cd11bf7667e03f0a1a3f0b50467f6c7168df25fdcb26eafca7da5612b32c1894e5338bb817",
"pids": [
2016
],
"md5": "4c00cf5174b6eb6f7409ce061f73071c"
},
{
"yara": [],
"sha1": "b12b47e9c7ea859967ed75facdce4b54f9911a41",
"name": "0352856a5f8645f9_htmlview.fne",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\HtmlView.fne",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "0352856a5f8645f90857baee3d6310e88215f6489b2641b2682ee6cde3b2d4e2",
"urls": [
"http:\/\/dywt.com.cn"
],
"crc32": "CA5DF2F4",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/0352856a5f8645f9_htmlview.fne",
"ssdeep": null,
"size": 229376,
"sha512": "588ac395416b3fca6580f5de872b49aa81a21f97ff482eae286072f4bffeeef332170a27fa866b4a425dffdf0f107d659637eaeda5035d8e8458e6d800c11ae3",
"pids": [
2016
],
"md5": "59f0a258fa01bce2a69d263bea890e40"
},
{
"yara": [],
"sha1": "8c261feba60d1b3a69d583b17d12f21029b9daa0",
"name": "570f270a25280115_dp1.fne",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\dp1.fne",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "570f270a2528011596be10fa9d0ee96d9b1255c82e61c0a3b9ed3a71474ea896",
"urls": [
"http:\/\/dywt.com.cn",
"http:\/\/dywt.com.cn\/RSATool2v14.rar"
],
"crc32": "AA460C30",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/570f270a25280115_dp1.fne",
"ssdeep": null,
"size": 126976,
"sha512": "4156f2ebf8c770368265f3a30051b0825fd9494a6d8c848a87210f82f022a8dbc51c6b648b65414212e4a19effc5d054a6c7de859ff1b97f3a49362f441c8085",
"pids": [
2016
],
"md5": "92044aa003c045ce5ba6f3095515218e"
},
{
"yara": [],
"sha1": "8d42534f45260ab898b691f9c58cf90c0a61a69a",
"name": "5db98291981d62ef_iext3.fne",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext3.fne",
"type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
"sha256": "5db98291981d62efab1b9affb26e3820eeddbdf6a5ab2230abcdb15904e36013",
"urls": [],
"crc32": "2526D54A",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/8868\/files\/5db98291981d62ef_iext3.fne",
"ssdeep": null,
"size": 389120,
"sha512": "fef44696735c25071460ea744a260b8619a9ddb2b1e23211fc285e5eeafb18a2b53be68ed80819d45961e9a6a1eafdabc59bafaf7db32a611681435a1ddbd89f",
"pids": [
2016
],
"md5": "e06347e30b49a024bd49aef1d274d6a7"
}
][
{
"process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\8168d339706c26fc573c1bd2be2d83e7ba513bd8c0fd683246dd86242e8f0a2f.bin",
"process_name": "8168d339706c26fc573c1bd2be2d83e7ba513bd8c0fd683246dd86242e8f0a2f.bin",
"pid": 2016,
"summary": {
"file_created": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\HtmlView.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\internet.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EThread.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext2.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eGrid.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eAPI.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\shell.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\commobj.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\krnln.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\spec.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext3.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\RegEx.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext5.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EXMLParser.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\dp1.fne"
],
"directory_created": [
"d:\\Dosame\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4"
],
"dll_loaded": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EThread.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\commobj.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\shell.fne",
"kernel32.dll",
"UxTheme.dll",
"C:\\Windows\\system32\\ole32.dll",
"dwmapi.dll",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\shell.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\commobj.fnr",
"C:\\Windows\\syswow64\\MSCTF.dll",
"C:\\Windows\\winhlp32.exe",
"OLEAUT32.DLL",
"comctl32",
"IMM32.dll",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext5.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext5.fne",
"User32.dll",
"comctl32.dll",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext2.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eGrid.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\krnln.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EThread.fnr",
"Gdi32.dll",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eGrid.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext2.fnr",
"Kernel32.dll",
"COMCTL32.DLL"
],
"file_opened": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\8168d339706c26fc573c1bd2be2d83e7ba513bd8c0fd683246dd86242e8f0a2f.bin",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Control Panel\\Desktop",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\VFW",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\8168d339706c26fc573c1bd2be2d83e7ba513bd8c0fd683246dd86242e8f0a2f.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}"
],
"file_written": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\HtmlView.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\internet.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EThread.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext2.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eGrid.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eAPI.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\shell.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\commobj.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\krnln.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\spec.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext3.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\RegEx.fnr",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext5.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EXMLParser.fne",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\dp1.fne"
],
"file_failed": [
"d:\\Dosame\\\u00d3\u00c3\u00bb\u00a7\u00d7\u00a2\u00d2\u00e2.txt",
"d:\\",
"C:\\Windows\\System32\\Lendsoft.txt"
],
"file_read": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\8168d339706c26fc573c1bd2be2d83e7ba513bd8c0fd683246dd86242e8f0a2f.bin"
],
"regkey_read": [
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\Segoe UI",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\MS Shell Dlg",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInterval",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInset",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollDelay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\TurnOffSPIAnimations",
"HKEY_CURRENT_USER\\Control Panel\\Desktop\\WheelScrollLines"
]
},
"first_seen": 1597171987.75,
"ppid": 2732
},
{
"process_path": "C:\\Windows\\System32\\lsass.exe",
"process_name": "lsass.exe",
"pid": 476,
"summary": {},
"first_seen": 1597171987.53125,
"ppid": 376
}
][
{
"markcount": 2,
"families": [],
"description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)",
"severity": 1,
"marks": [
{
"category": "section",
"ioc": ".aspack",
"type": "ioc",
"description": null
},
{
"category": "section",
"ioc": ".adata",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "pe_features"
},
{
"markcount": 1,
"families": [],
"description": "The executable uses a known packer",
"severity": 1,
"marks": [
{
"category": "packer",
"ioc": "ASPack v2.12 -> Alexey Solodovnikov",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "peid_packer"
},
{
"markcount": 11,
"families": [],
"description": "Foreign language identified in PE resource",
"severity": 2,
"marks": [
{
"name": "RT_ICON",
"language": "LANG_CHINESE",
"offset": "0x000a0ea8",
"filetype": "data",
"sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
"type": "generic",
"size": "0x000025a8"
},
{
"name": "RT_ICON",
"language": "LANG_CHINESE",
"offset": "0x000a0ea8",
"filetype": "data",
"sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
"type": "generic",
"size": "0x000025a8"
},
{
"name": "RT_ICON",
"language": "LANG_CHINESE",
"offset": "0x000a0ea8",
"filetype": "data",
"sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
"type": "generic",
"size": "0x000025a8"
},
{
"name": "RT_ICON",
"language": "LANG_CHINESE",
"offset": "0x000a0ea8",
"filetype": "data",
"sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
"type": "generic",
"size": "0x000025a8"
},
{
"name": "RT_ICON",
"language": "LANG_CHINESE",
"offset": "0x000a0ea8",
"filetype": "data",
"sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
"type": "generic",
"size": "0x000025a8"
},
{
"name": "RT_ICON",
"language": "LANG_CHINESE",
"offset": "0x000a0ea8",
"filetype": "data",
"sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
"type": "generic",
"size": "0x000025a8"
},
{
"name": "RT_ICON",
"language": "LANG_CHINESE",
"offset": "0x000a0ea8",
"filetype": "data",
"sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
"type": "generic",
"size": "0x000025a8"
},
{
"name": "RT_ICON",
"language": "LANG_CHINESE",
"offset": "0x000a0ea8",
"filetype": "data",
"sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
"type": "generic",
"size": "0x000025a8"
},
{
"name": "RT_ICON",
"language": "LANG_CHINESE",
"offset": "0x000a0ea8",
"filetype": "data",
"sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
"type": "generic",
"size": "0x000025a8"
},
{
"name": "RT_GROUP_ICON",
"language": "LANG_CHINESE",
"offset": "0x000a3450",
"filetype": "MS Windows icon resource - 9 icons, 16x16, 16 colors",
"sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
"type": "generic",
"size": "0x00000084"
},
{
"name": "RT_MANIFEST",
"language": "LANG_CHINESE",
"offset": "0x000a34d4",
"filetype": "XML 1.0 document, ASCII text, with very long lines, with no line terminators",
"sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
"type": "generic",
"size": "0x000001cd"
}
],
"references": [],
"name": "origin_langid"
},
{
"markcount": 16,
"families": [],
"description": "Drops an executable to the user AppData folder",
"severity": 2,
"marks": [
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eGrid.fne",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext2.fne",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\krnln.fnr",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\eAPI.fne",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\commobj.fne",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EXMLParser.fne",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\internet.fne",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext.fnr",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\shell.fne",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext5.fne",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\EThread.fne",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\RegEx.fnr",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\spec.fne",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\HtmlView.fne",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\dp1.fne",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Users\\cuck\\AppData\\Local\\Temp\\E_4\\iext3.fne",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "exe_appdata"
},
{
"markcount": 5,
"families": [],
"description": "The binary likely contains encrypted or compressed data indicative of a packer",
"severity": 2,
"marks": [
{
"entropy": 7.9525418988455,
"section": {
"size_of_data": "0x00003800",
"virtual_address": "0x00001000",
"entropy": 7.9525418988455,
"name": ".text",
"virtual_size": "0x00006000"
},
"type": "generic",
"description": "A section with a high entropy has been found"
},
{
"entropy": 7.089730190864278,
"section": {
"size_of_data": "0x00000600",
"virtual_address": "0x00007000",
"entropy": 7.089730190864278,
"name": ".rdata",
"virtual_size": "0x00001000"
},
"type": "generic",
"description": "A section with a high entropy has been found"
},
{
"entropy": 6.994553782134763,
"section": {
"size_of_data": "0x00000800",
"virtual_address": "0x00008000",
"entropy": 6.994553782134763,
"name": ".data",
"virtual_size": "0x00004000"
},
"type": "generic",
"description": "A section with a high entropy has been found"
},
{
"entropy": 7.996760597544648,
"section": {
"size_of_data": "0x0001d400",
"virtual_address": "0x0000c000",
"entropy": 7.996760597544648,
"name": ".data",
"virtual_size": "0x00091000"
},
"type": "generic",
"description": "A section with a high entropy has been found"
},
{
"entropy": 0.8053892215568862,
"type": "generic",
"description": "Overall entropy of this PE file is high"
}
],
"references": [
"http:\/\/www.forensickb.com\/2013\/03\/file-entropy-explained.html",
"http:\/\/virii.es\/U\/Using%20Entropy%20Analysis%20to%20Find%20Encrypted%20and%20Packed%20Malware.pdf"
],
"name": "packer_entropy"
}
]The Yara rules did not detect anything in the file.
{
"tls": [],
"udp": [
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 546,
"time": 3.078671932220459,
"dport": 137,
"sport": 137
},
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 5226,
"time": 9.079137086868286,
"dport": 138,
"sport": 138
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 7070,
"time": 3.01092791557312,
"dport": 5355,
"sport": 51001
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 7398,
"time": 1.022150993347168,
"dport": 5355,
"sport": 53595
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 7726,
"time": 3.018066883087158,
"dport": 5355,
"sport": 53848
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 8054,
"time": 1.6281030178070068,
"dport": 5355,
"sport": 54255
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 8382,
"time": -0.09102892875671387,
"dport": 5355,
"sport": 55314
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 8710,
"time": 1.5795409679412842,
"dport": 1900,
"sport": 1900
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 28120,
"time": 1.0417909622192383,
"dport": 3702,
"sport": 49152
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 36504,
"time": 3.094132900238037,
"dport": 1900,
"sport": 53598
}
],
"dns_servers": [],
"http": [],
"icmp": [],
"smtp": [],
"tcp": [],
"smtp_ex": [],
"mitm": [],
"hosts": [],
"pcap_sha256": "8d43c12f50e01342596ec755f9cc008e24ee24f18f34b4406f2119089b60c381",
"dns": [],
"http_ex": [],
"domains": [],
"dead_hosts": [],
"sorted_pcap_sha256": "d32923bee8f49643e6c53a02f348b71a3df0d2cc87b6d842e28b572a4b68b435",
"irc": [],
"https_ex": []
}








The instructions below shows how to remove ssczhixuanss.exe with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the ssczhixuanss.exe file for removal, restart your computer and scan it again to verify that ssczhixuanss.exe has been successfully removed. Here are the removal instructions in more detail:
| Property | Value |
|---|---|
| MD5 | 06be3ac11a993818717f4302bb050139 |
| SHA256 | 8168d339706c26fc573c1bd2be2d83e7ba513bd8c0fd683246dd86242e8f0a2f |
These are some of the error messages that can appear related to ssczhixuanss.exe:
ssczhixuanss.exe has encountered a problem and needs to close. We are sorry for the inconvenience.
ssczhixuanss.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.
ssczhixuanss.exe has stopped working.
End Program - ssczhixuanss.exe. This program is not responding.
ssczhixuanss.exe is not a valid Win32 application.
ssczhixuanss.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.
To help other users, please let us know what you will do with the file:
Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.
I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.
No comments posted yet.