colorbricks.exe

Gamehitzone Inc.

The application colorbricks.exe by Gamehitzone has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from indir.gezginler.net and multiple other hosts.
Publisher:
GameHitZone.com   (signed by Gamehitzone Inc.)

MD5:
3ad7be14b5b1edc344020a61ead01737

SHA-1:
53ae9862f6d616c2f6828fcd71f7209b5027a74e

SHA-256:
b44cbb9469e7db14be34cb5f6d6a2dd8a28b7b3bdfe0ee7702d0d5cefe6d4c0f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/18/2024 6:56:58 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.Gamehitzone
15.5.16.5

File size:
17.7 MB (18,556,680 bytes)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\colorbricks.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/3/2014 5:33:05 AM

Valid to:
1/3/2018 5:33:05 AM

Subject:
E=abuse@gamehitzone.com, CN=Gamehitzone Inc., O=Gamehitzone Inc., L=Belize City, S=Belize, C=BZ

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11212DA109C716E14D8F300F2D8DD9ACEBA0

File PE Metadata
Compilation timestamp:
10/12/2013 10:19:32 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:2yXEOdc8cZo+2lvYkgpeJCMBEg7BZGi/aNqRTE3RiYxgm16T/:HUgcX2lgkgp+JKKBZf/akRTsiYxN+

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9975

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file colorbricks.exe has been seen being distributed by the following 3 URLs.

http://indir.gezginler.net/i/34587/.../

Remove colorbricks.exe - Powered by Reason Core Security