c.and.c.generals.zero.hour.exe

Command & Conquer: Generals Zero Hour

RICH MEDIA SYSTEMS INC.

The application c.and.c.generals.zero.hour.exe by RICH MEDIA SYSTEMS INC has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from generals-zero-hour.joydownload.com and multiple other hosts.
Publisher:
RICH MEDIA SYSTEMS INC.  (signed and verified)

Product:
Command & Conquer: Generals Zero Hour

Version:
1.0.0.0

MD5:
6cc14951f09153e82c52ebb74dddf785

SHA-1:
c620ead01ca1a005d2fa4f250fe8848a1c618946

SHA-256:
4efa86a7418012c532df9fdcf3b5e25f04eb0690bdd40915fcf605711e116796

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 12:44:14 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.RICHMEDIASYSTEMS.Installer (M)
15.12.20.16

File size:
415.9 KB (425,864 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\c.and.c.generals.zero.hour.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/16/2015 7:00:00 PM

Valid to:
2/17/2016 6:59:59 PM

Subject:
CN=RICH MEDIA SYSTEMS INC., O=RICH MEDIA SYSTEMS INC., L=HENDERSON, S=Nevada, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
3F87144C25AF8BCF29F29C5A1FEEF4BA

File PE Metadata
Compilation timestamp:
5/19/2013 7:53:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:Uiu2fXzK81OOY+2/YU+w7JOI2VsZTgEODxP1IzHyyYQuLS:I2B1OrgUv/ZTgEOPqS3QuG

Entry address:
0x331C

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 30, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, BC, 70, 40, 00, 55, FF, 15, AC, 72, 40, 00, 6A, 08, A3, 98, 92, 42, 00, E8, A8, 2E, 00, 00, A3, E4, 91, 42, 00, 55, 8D, 44, 24, 34, 68, B4, 02, 00, 00, 50, 55, 68, 90, 06, 42, 00, FF, 15, 7C, 71, 40, 00, 68, 7C, 93, 40, 00, 68, E0, 81, 42, 00, E8, 13, 2B, 00, 00, FF, 15, 34, 71, 40, 00, BB, 00, 40, 43, 00, 50, 53, E8, 01, 2B, 00, 00...
 
[+]

Entropy:
7.8402

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file c.and.c.generals.zero.hour.exe has been seen being distributed by the following 18 URLs.

http://generals-zero-hour.joydownload.com/get_azure_file/wUiS4WnYccXBwj zXP7oQkEsml0kPD 1E1v4ZNbB47pquHf14WJxy9EcXlm2Nu/iTG3LlQoNcDLQWPfNTfdo3cE/gYSDUkTE7SS7BkX9qj3m3 fa7dPem3FJo5Q3hlZQXzWtCz5/hpdwvWumCyrcAuBOw4TrNj8Neu5ncU1NYvO0SzAqOpHTfkRnzrPvUSwmcpexiLknBTCws1GMlv1mFtb5YsntZXBWzcCvFqounBcHrdGpn1O7ZKx/.../ykG1prZNni6Ex6B3K89ewmz3yPdFg4we3ES

http://generals-zero-hour.joydownload.com/get_azure_file/wUiS4WnYccXDyCf4UfO5CV530RJ0YyqsWxLzaNbB4rZouCev/itvgY5Mclq/N/6 LXj/ylJSIDbEW7DlTac8mrNhwMOZAASW/y3/BwX9vHGt3ayN 8vT0mlIoZ8i8EsTCiK5eSACwZ18vHqmGX3zFf4D1r cnUZPfFnPRNMOa39RD47asWNLBoonqD2GWUve4/gkrRhHGLjuFvE3/VqDoDrL576OjNO1IK3H M2mxgH5sv3jlLqN/MhhSflCc1X/.../zDU75pJD2gFZ7ai2D 3gfntPQOmDoHBXPg7l1bwji1CnfAAkze3ES

http://generals-zero-hour.joydownload.com/get_azure_file/wUiS4WnYccXAwj uQbjxCggnkkU3LTPkEhz4coqK6bYk5ib0oWh42agQfBmzdsjiSCbilRYJbiCScbzlR6tPnPwi2pPVUh6avCX7BlSx4S tgLbbqNPKk2FKppAzkV4BXnStGGE2hshq9CzwSCTAHugDj4TzPHQNabk4PUxWcO rBzM6OpLcLVgojanuAHFwJtCwgLF2EyPv8AXSxKApRoC2M8ioZWMKgJ3pSKs2lF4f74LviV3qZel/lCa0Q5YJ/.../joZCYkigjYaRIBo4 M21g6ba1FkNrjx3z3dtOAXmpRlSx9ojvngUkOnTEuG4W3dvVOzGiRkvP0aMrewmz3yPdFgkye3ES

http://generals-zero-hour.joydownload.com/get_azure_file/wUiS4WnYccXEwj /TeqjC1c0kw48PjyiGhD1Y9jVteh152f0sDcx2dBNJ0DtevylYSfjhxdKOSCGHeO1Tuprl wi1s3eDQ6b7Sv9Hk20sn 1maOI8ozKmiBBopU6kSZcBSjzFE1r45Z3q2mrBiCHKukel9mZaHJFdux6egoEcKX2VnBtLJeNZkdzxeSmTjQuO4/z2ecnWTzk5xiewLxxTsf/L9/2MDQezcr F oujV1MuZr2zlL ZLh0nySiAMlP5YSxQHP79cjEiCdjbbBJV4Y/.../CsXhBihATzjolWGHXrBwawqZnu1VZ8amDP 2AW18vQN2CjBkvfgug7LRD7livWDhg0e3ES

http://generals-zero-hour.joydownload.com/get_azure_file/wUiS4WnYccXAwj uQbjxCggnkkU3LTPkEh74coqM6bdjr3f14WJwwckKKFXsK7H/NWHlmQBKOSCGGeO1G7IlyPpqx8yPRFXF7SShBkf8 3G9geeO7cvT0mlMq4d32gsWCzHkGDU2nsUj7H6yGjrbFa5Xkc3gMzIFbbo1LB4HOOz9VXBtPpeaNBBhhqfuACQneYL30v8 TWO5uEiPxat D9G3dsi8bnlU28K7D JnlRkf/96k0Q3qZel/lCysEbxDv5nvXQr3xMTOz25xO/.../ZmFb76flA08p2wS7lNdFEybzUlSw48a1jkpnYmDP 2AV1dPBZyf2EAOM1LliI1eyijyPW093e3ES

Remove c.and.c.generals.zero.hour.exe - Powered by Reason Core Security