game_3dmgame-1480_s0s.exe

WCalendar

The application game_3dmgame-1480_s0s.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from www.baidu.com.
Publisher:
WCalendar

Product:
WCalendar

Version:
2016.0803.18.0

MD5:
ad188352c71dde8773062e11723604cb

SHA-1:
f93159e6ce6b53f3e4b418e906cb00eeac4f68ad

SHA-256:
621e09ace8eb74a71e59f34a43e698b176164cdfc4edf1e2c6ac415555c39a72

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 8:35:53 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bundler (L)
16.9.4.11

File size:
2.3 MB (2,455,337 bytes)

Product version:
1.0

Copyright:
Copyright © 2012-2016 WCalendar, Inc.

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\game_3dmgame-1480_s0s.exe

File PE Metadata
Compilation timestamp:
7/25/2016 5:25:02 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:JyPaT8+IQW7Z68xdNikNMCg8E1qql8Zqb+N8OpP9tGYf:JyPaTvIQW7A2dPAqql8ZqLosYf

Entry address:
0x10256C

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, 57, B8, FC, 00, 50, 00, E8, CD, 69, F0, FF, 6A, EC, A1, 6C, 5E, 50, 00, 8B, 00, 8B, 98, 70, 01, 00, 00, 53, E8, 78, 78, F0, FF, 25, 7F, FF, FF, FF, 50, 6A, EC, A1, 6C, 5E, 50, 00, 53, E8, CD, 7A, F0, FF, 33, C0, 55, 68, E7, 25, 50, 00, 64, FF, 30, 64, 89, 20, 6A, 01, E8, 18, 72, F0, FF, E8, 7F, D8, FF, FF, A1, 34, FD, 4F, 00, 50, 68, 98, FD, 4F, 00, A1, 6C, 5E, 50, 00, 8B, 00, E8, 0C, 9E, F7, FF, E8, D3, D8, FF, FF, 33, C0, 5A, 59, 59, 64, 89, 10, EB, 19, E9, F4, 20, F0, FF...
 
[+]

Entropy:
7.4760

Developed / compiled with:
Microsoft Visual C++

Code size:
1 MB (1,052,160 bytes)

The file game_3dmgame-1480_s0s.exe has been seen being distributed by the following URL.

Remove game_3dmgame-1480_s0s.exe - Powered by Reason Core Security