goodgame-empire.exe

Goodgame Empire

GameTop Pte. Ltd.

The application goodgame-empire.exe, “Goodgame Empire Setup ” has been detected as a potentially unwanted program by 16 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from x.gametop.com.
Publisher:
GameTop Pte. Ltd.

Product:
Goodgame Empire

Description:
Goodgame Empire Setup

MD5:
0f66f1930fce7fab822b8c9d6a7e9c53

SHA-1:
4332734ae1cbd817de77065ec7078391a8ead5ac

SHA-256:
0db01bf122449d4d4484bc0059919c05fe252000e906813abccf473e48ef6e77

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 12:06:36 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.145879
5813612

avast!
Win32:Dropper-NVQ [PUP]
160112-0

AVG
Worm/Pakes.BZH
2015.0.4477

Clam AntiVirus
Win.Worm.Autorun-1424
0.98/21255

Dr.Web
Trojan.Click2.42536
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Graftor.145879
10.0.0.5366

ESET NOD32
Win32/Blueh.A virus
7.0.302.0

F-Prot
W32/Trojan2.NUWQ
4.6.5.141

Kaspersky
Trojan.Win32.Blueh
15.0.0.562

McAfee
Trojan.Trojan-FDMI!0F66F1930FCE
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.2713.0

Norman
Gen:Variant.Graftor.145879
11.01.2016 17:30:26

Sophos
Virus 'Mal/Generic-L'
5.22

VIPRE Antivirus
Threat.4792057
46446

File size:
973.6 KB (996,989 bytes)

Product version:
1.0

Copyright:
Copyright © GameTop Pte. Ltd.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\goodgame-empire.exe

File PE Metadata
Compilation timestamp:
3/29/2012 11:00:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:GD+vUISCuEhIXPQQWVzWMljuS0gwDEpUZ51QiG+v892DndmIwsn5y6alKhC2Iqjb:6CuAIXYQyjBpW1QijdD1wMy6asIti

Entry address:
0x2845

Entry point:
E8, 7E, 04, 00, 00, E9, 37, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 40, 51, 40, 00, 89, 0D, 3C, 51, 40, 00, 89, 15, 38, 51, 40, 00, 89, 1D, 34, 51, 40, 00, 89, 35, 30, 51, 40, 00, 89, 3D, 2C, 51, 40, 00, 66, 8C, 15, 58, 51, 40, 00, 66, 8C, 0D, 4C, 51, 40, 00, 66, 8C, 1D, 28, 51, 40, 00, 66, 8C, 05, 24, 51, 40, 00, 66, 8C, 25, 20, 51, 40, 00, 66, 8C, 2D, 1C, 51, 40, 00, 9C, 8F, 05, 50, 51, 40, 00, 8B, 45, 00, A3, 44, 51, 40, 00, 8B, 45, 04, A3, 48, 51, 40, 00, 8D, 45, 08, A3, 54, 51, 40...
 
[+]

Entropy:
7.2845

Code size:
7.5 KB (7,680 bytes)

The file goodgame-empire.exe has been seen being distributed by the following URL.

Remove goodgame-empire.exe - Powered by Reason Core Security