dota 2 item hack with speed hack game changer play v1.0.exe

The executable dota 2 item hack with speed hack game changer play v1.0.exe has been detected as malware by 39 anti-virus scanners. Infected by a mass-mailing worm and virus that sends itself to email addresses gathered from the compromised computer and exploits remote vulnerabilities and attempts to infect files. The file has been seen being downloaded from dc581.2shared.com.
Version:
0.0.0.0

MD5:
a4f7c787613e1d227b3bb145927611e9

SHA-1:
7bb8b97dcd5051e01b5cbea286fe450788b1441a

SHA-256:
1dfa52201d0c94ac91f89aa101ae8e13f5971b0da5b88e5b530045ac2c87d85b

Scanner detections:
39 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 8:43:14 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Runouce.B@mm
5742874

Agnitum Outpost
I-Worm.Chir.B
7.1.1

AhnLab V3 Security
Win32/ChiHack.6652
2015.10.07

Avira AntiVirus
W32/Chir.B
8.3.2.2

Arcabit
Win32.Runouce.E2C45E
1.0.0.576

avast!
Malware-gen
150810-3

AVG
Dropper.Generic
2016.0.2964

Baidu Antivirus
Virus.Win32.Runouce.$a
4.0.3.15107

Bitdefender
Win32.Runouce.B@mm
1.0.20.1400

Bkav FE
W32.ChirBPE
1.3.0.7237

Clam AntiVirus
WIN.Worm.Brontok
0.98/21511

Comodo Security
EmailWorm.Win32.Runonce.~v001
23366

Dr.Web
Trojan.PWS.Siggen.27583
9.0.1.05190

Emsisoft Anti-Malware
Win32.Runouce.B@mm
10.0.0.5366

ESET NOD32
Win32/Chir.B virus
7.0.302.0

Fortinet FortiGate
W32/Chir.B@mm
10/7/2015

F-Prot
W32/Thecid.B@mm
4.6.5.141

F-Secure
Win32.Runouce.B@mm
5.14.151

G Data
Win32.Runouce.B@mm
15.10.25

IKARUS anti.virus
Virus.Win32.Prorat
t3scan.1.9.5.0

K7 AntiVirus
EmailWorm
13.210.17446

Kaspersky
Email-Worm.Win32.Runouce
15.0.0.543

McAfee
W32/Chir.b@MM
5600.6620

Microsoft Security Essentials
Threat.Undefined
1.207.2189.0

MicroWorld eScan
Win32.Runouce.B@mm
16.0.0.840

NANO AntiVirus
Trojan.Win32.IframeExec.dteiuc
0.30.26.3947

Norman
Win32.Runouce.B@mm
04.08.2015 10:30:46

nProtect
Win32.Runouce.B@mm
15.10.06.01

Panda Antivirus
Generic Malware
15.10.07.07

Quick Heal
W32.Runouce.B
10.15.14.00

Rising Antivirus
PE:Worm.Mail.ChineseHacker!245783[F1]
23.00.65.151005

Sophos
Virus 'W32/Chir-B'
5.19

Total Defense
Win32/Chir.B
37.1.62.1

Trend Micro House Call
PE_Chir.B
7.2.280

Trend Micro
PE_Chir.B
10.465.07

Vba32 AntiVirus
Virus.Win32.Chur.A
3.12.26.4

VIPRE Antivirus
Threat.219451
42326

ViRobot
Win32.Chir.B[h]
2014.3.20.0

Zillya! Antivirus
Worm.RunOnce.Win32.2
2.0.0.2431

File size:
3.2 MB (3,344,892 bytes)

Product version:
0.0.0.0

Original file name:
GAME SPEED.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\dota 2 item hack with speed hack game changer play v1.0.exe

File PE Metadata
Compilation timestamp:
5/16/2015 3:47:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:ngAMX89mRDDmrw/zv9wKTLe/vLHZfFsHF59BTtjvV02/Nh:n7E893U/zRLmzpkBt

Entry address:
0x331000

Entry point:
60, E8, E6, 19, 00, 00, 8B, 74, 24, 20, E8, 08, 00, 00, 00, 61, 68, 4E, 62, 72, 00, C3, E9, 59, E8, 01, 16, 00, 00, 81, E6, 00, F0, FF, FF, 81, EE, 00, 10, 00, 00, 66, 81, 3E, 4D, 5A, 75, F3, 0F, B7, 7E, 3C, 03, FE, 8B, 6F, 78, 03, EE, 8B, 5D, 20, 03, DE, 33, C0, 8B, D6, 83, C3, 04, 40, 8B, 3B, 03, FA, E8, 0F, 00, 00, 00, 47, 65, 74, 50, 72, 6F, 63, 41, 64, 64, 72, 65, 73, 73, 00, 5E, 33, C9, B1, 0F, FC, F3, A6, 75, DA, 8B, F2, 8B, 5D, 24, 03, DE, 0F, B7, 0C, 43, 8B, 5D, 1C, 03, DE, 8B, 1C, 8B, 03, DE, 81...
 
[+]

Entropy:
7.2730

Packer / compiler:
ASPack v1.08.04

Code size:
3.1 MB (3,297,280 bytes)

The file dota 2 item hack with speed hack game changer play v1.0.exe has been seen being distributed by the following URL.