crossfire_sa.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from br.cfpatch.z8games.com.
MD5:
271fa6c18d3b8c2fb683e2135298b49f

SHA-1:
b2f3da441e34bf59c9440463fe6d4afd83b04699

SHA-256:
518957c78a413ff69e5cc6f92b28f64fe02ba92a7ab1067b341e9e2942a34863

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 6:25:09 AM UTC  (today)

File size:
2.4 MB (2,520,792 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\crossfire_sa.exe

File PE Metadata
Compilation timestamp:
12/2/2013 11:21:01 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:SRU/FdSqGDJoT52MXt5vgF5nQ8FR463kYnCTrYq8yuVwo41nofx:/8R46nMC41A

Entry address:
0xF3FC3

Entry point:
85, 3B, 02, 00, 00, FF, 35, F8, DE, 5F, 00, 8D, 85, 7C, FB, FF, FF, 56, 50, E8, 01, 07, 01, 00, 83, C4, 0C, 85, C0, 0F, 85, 1D, 02, 00, 00, 68, 10, C6, 58, 00, 8D, 85, 7C, FB, FF, FF, 56, 50, E8, E4, 06, 01, 00, 83, C4, 0C, 85, C0, 0F, 85, 00, 02, 00, 00, 68, 12, 20, 01, 00, 8D, 85, 7C, FB, FF, FF, 68, 90, C6, 58, 00, 50, E8, 2D, 0C, 01, 00, 83, C4, 0C, 83, F8, 03, 0F, 85, FB, 00, 00, 00, E9, E3, 01, 00, 00, 83, F8, 26, 73, 5D, 6A, 35, 58, D1, EB, 2B, C3, 50, 56, 8D, 85, 7C, FB, FF, FF, 68, 40, 02, 00, 00...
 
[+]

Code size:
1.5 MB (1,580,032 bytes)

The file crossfire_sa.exe has been seen being distributed by the following URL.

Scan crossfire_sa.exe - Powered by Reason Core Security