Shan Feng - 19% Detection Rate *

Did you just run into a download or a file on your computer that has been digitally signed by Shan Feng? Some of the security products refers to the detected files as Gen:Variant.Adware.Ghoskwa.1 and Trojan.GenericKD.3472954. The detection rate for the Shan Feng files collected here is 19%. Please read on for more details.

You will typically notice Shan Feng when running the file. The publisher name is displayed as the "Verified publisher" in the UAC dialog as the screenshot shows:

Screenshot where Shan Feng appears as the verified publisher in the UAC dialog

You can view additional details from the Shan Feng certificate with the following steps:

  1. Open Windows Explorer and locate the Shan Feng file
  2. Right-click the file and select Properties
  3. Click on the Digital Signatures tab
  4. Click the View Certificate button

Here is a screenshot of a file signed by Shan Feng:

Screenshot of the Shan Feng certificate

As you can see in the screenshot above, Windows states that "This digital signature is OK". This means that the file has been published by Shan Feng and that the file has not been tampered with.

If you click the View Certificate button shown in the screenshot above, you can see all the details of the certificate, such as when it was issued, who issued the certificate, how long it is valid, and so on. You can also see the address for Shan Feng, such as the street name, city and country.

thawte SHA256 Code Signing CA has issued the Shan Feng certificates. You can also see the details of the issuer by clicking the View Certificate button shown in the screenshot above.

Shan Feng Files

These are the Shan Feng files I've gathered, thanks to the FreeFixer users.

Detection RatioFile Name
1/54Birdsarah.exe
7/55Nobean.exe
5/52ToolrainUpdate.exe
3/56Birdmay.exe
12/57googleupdate.exe
2/52Lefttoe.exe
1/57protect.exe
34/59Guntony_server.exe
3/55chrome.exe
1/54libexif.dll
1/57wow_helper.exe
13/56googleupdatesetup.exe
9/57goopdateres_gu.dll
9/57GoogleUpdateSetup.exe
2/56chr.exe
27/56Boobseed.exe
9/54Yesdear.exe
18/55BigjaneUpdate.exe
43/67BirdkissUpdate.exe

Scanner and Detection Names

Here's the detection names for the Shan Feng files. I have grouped the detection names by each scanner engine. Thanks to VirusTotal for the scan results.

ScannerDetection Names
ALYacGen:Variant.Adware.Ghoskwa.1, Trojan.GenericKD.3472954, Gen:Variant.Strictor.112324
AVGElex.AGH, Generic.C9D, Generic.C7D, Generic.C91, Generic_s.ITX, Win32:Adware-gen [Adw]
AVwareTrojan.Win32.Generic!BT
Ad-AwareGen:Variant.Adware.Ghoskwa.1, Trojan.GenericKD.3472954, Gen:Variant.Strictor.112324
AegisLabTroj.Crypt.Zpack!c, Gen.Variant.Adware!c, Elex.Agh.Gen!c, Troj.Obfuscate.Efgy!c
AhnLab-V3PUP/Win32.Ghokswa.C1449526, Malware/Win32.Generic.N2070183364, PUP/Win32.Agent.C1560263
Antiy-AVLGrayWare[AdWare]/Win32.Elex
ArcabitTrojan.Adware.Ghoskwa.1, Trojan.Generic.D34FE3A, Trojan.Strictor.D1B6C4
AvastWin32:Dropper-gen [Drp], Win32:Adware-gen [Adw], Win32:Malware-gen
AviraTR/Crypt.ZPACK.qhxa, TR/Crypt.ZPACK.ecxf, ADWARE/ELEX.njvy, TR/Crypt.ZPACK.qsug, ADWARE/Adware.prtu, TR/Obfuscate.efgy, TR/Crypt.ZPACK.ivhg
BaiduWin32.Trojan.WisdomEyes.151026.9950.9998
BitDefenderGen:Variant.Adware.Ghoskwa.1, Trojan.GenericKD.3472954, Gen:Variant.Strictor.112324
CAT-QuickHealPUA.Shanfeng.Gen
ComodoApplication.Win32.Agent.wrzes
CrowdStrikemalicious_confidence_100% (D)
Cybereasonmalicious.1b8fb7
CyrenW32/Trojan.TICM-2344, W32/Trojan.OPDJ-0293
DrWebAdware.Mutabaha.1406, Adware.Mutabaha.1111, Adware.Mutabaha.1291, Adware.Mutabaha.1431, Adware.Mutabaha.1625, Adware.Mutabaha.3412
ESET-NOD32a variant of Win32/Obfuscated.NHQ, a variant of Win32/ELEX.IX potentially unwanted, a variant of Win32/Obfuscated.NHA
EmsisoftGen:Variant.Adware.Ghoskwa.1 (B), Trojan.GenericKD.3472954 (B), Gen:Variant.Strictor.112324 (B)
Endgamemalicious (moderate confidence), malicious (high confidence)
F-SecureGen:Variant.Adware.Ghoskwa, Trojan.GenericKD.3472954, Gen:Variant.Strictor.112324
FortinetRiskware/Elex, PossibleThreat
GDataGen:Variant.Adware.Ghoskwa.1, Trojan.GenericKD.3472954, Win32.Trojan.Agent.RC8AIO, Gen:Variant.Strictor.112324
IkarusTrojan.Crypt, PUA.Elex, Trojan.Win32.Obfuscated, PUA.Monetizer
Invinceavirus.win32.chir.b@mm, heuristic
JiangminAdWare.ELEX.qv, AdWare.ELEX.asq
K7AntiVirusAdware ( 004f69cb1 ), Trojan ( 004f489f1 ), Adware ( 004f1e241 )
K7GWAdware ( 004f69cb1 ), Trojan ( 004f489f1 )
Kasperskynot-a-virus:HEUR:AdWare.Win32.Elex.gen
MAXmalware (ai score=100)
MalwarebytesPUP.Optional.Ghokswa, Adware.Ghoskwa
McAfeeRDN/Generic.tfr, Artemis!B7A9EE13ED2E, RDN/Generic.grp, Artemis!207EC3B1B8CB
McAfee-GW-EditionRDN/Generic.tfr, Artemis, RDN/Generic.grp, Artemis!PUP
MicroWorld-eScanGen:Variant.Adware.Ghoskwa.1, Trojan.GenericKD.3472954, Gen:Variant.Strictor.112324
MicrosoftTrojan:Win32/Ghokswa
NANO-AntivirusRiskware.Win32.Mutabaha.edufyi, Riskware.Win32.Mutabaha.eektjl, Riskware.Win32.Mutabaha.egvhnw
PandaPUP/BrowseFox, Generic Malware, PUP/Winzipper
Qihoo-360QVM19.1.Malware.Gen, HEUR/QVM19.1.0000.Malware.Gen, HEUR/QVM19.1.2011.Malware.Gen, HEUR/QVM10.1.0000.Malware.Gen, HEUR/QVM10.1.Malware.Gen, HEUR/QVM19.1.25D1.Malware.Gen, HEUR/QVM19.1.Malware.Gen
RisingPE:Malware.Generic/QRS!1.9E2D [F], PE:Malware.Generic(Thunder)!1.A1C4 [F], Malware.XPACK-HIE/Heur!1.9C48
SUPERAntiSpywarePUP.ELEX/Variant
SentinelOnestatic engine - malicious
SophosGeneric PUA AA (PUA), Mal/Generic-S, Generic PUA CO (PUA), Generic PUA AM (PUA)
SymantecTrojan.Gen.2, Trojan.Gen
TencentWin32.Adware.Malware.Llum, Win32.Adware.Malware.Rmka, Win32.Adware.Elex.Hoos
TrendMicroTROJ_GEN.R002C0CHU16, TROJ_GEN.R047C0OHA16, TROJ_GEN.R00JC0PGV16
TrendMicro-HouseCallTROJ_GEN.R002C0CHU16, TROJ_GEN.R047C0OHA16, TROJ_GEN.R00JC0PGV16
VBA32Signed-Adware.Mutabaha, suspected of Trojan.Downloader.gen.h
VIPRETrojan.Win32.Generic!BT
ViRobotAdware.Mutabaha.473472[h]
WebrootMalicious, W32.Adware.Gen
YandexRiskware.Agent!, Trojan.Obfuscated!uGZRXyOUYt8
ZillyaAdware.MutabahaCRTD.Win32.5114, Trojan.ObfuscatedCRTD.Win32.9451
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Elex.gen

* How the Detection Percentage is Calculated

The detection percentage is based on that I've collected 1066 scan reports for the Shan Feng files. 202 of these scan results came up with some sort of detection. You can view the full details of the scan results by examining the files listed above.

Analysis Details

The analysis has been done on certificates with the following serial numbers:

Comments

No comments posted yet.

Leave a reply