Game.exe

Loader

The executable Game.exe has been detected as malware by 10 anti-virus scanners.
Product:
Loader

Version:
1.0.0.0

MD5:
0fe4691d6dc66cf1a563684e87db8675

SHA-1:
7a9de7eac46b4bc84cdb48db2f5c3b01e704d800

SHA-256:
36adf4add4692261d6feb1f9524fb4e39861fcb1e832c401c811b57466747709

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
4/25/2024 12:10:33 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Trojan.MSIL.Agent
4.0.3.1446

Comodo Security
UnclassifiedMalware
17288

Emsisoft Anti-Malware
Trojan-Dropper.SuspectCRC!IK
8.14.02.04.06

ESET NOD32
MSIL/Agent.OJF (variant)
8.9058

F-Prot
W32/Fathom.3-based
v6.4.7.1.166

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.2.29

K7 AntiVirus
Trojan
13.173.10217

McAfee
Artemis!BBA5BC90F0A4
5600.7168

Norman
Suspicious_Gen4.EYHQJ
11.20140406

Sophos
Mal/Generic-S
4.94

File size:
103.5 KB (105,984 bytes)

Product version:
1.0.0.0

Original file name:
Game.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\game.exe

File PE Metadata
Compilation timestamp:
4/27/2011 8:34:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:SOdtGc/sJ2LH4fZkMrnMGMptgeKdjSVQDkhVR+URBdaTTtn4EoRVUePHA0AZ+b/K:SOdlK2acBU8/Bs

Entry address:
0x1902E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
92.5 KB (94,720 bytes)

Remove Game.exe - Powered by Reason Core Security