Grepolis resources adder v1.0.exe

Dark Orbit Uridium Generator v2.3

This is a setup program which is used to install the application. The file has been seen being downloaded from download630.mediafire.com.
Product:
Dark Orbit Uridium Generator v2.3

Version:
2.3.0.0

MD5:
0080e18d04048056f52b519aa78acc90

SHA-1:
f0a3bd3a6e4a6e84c912c064e6922004ca0ee83c

SHA-256:
751101210ef6bc5c410ad69eb7feb5bc33aa9428c0c5c860d945746ed59a7da2

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/18/2024 5:15:58 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/FakeTool.AAD trojan
7.0.302.0

File size:
1.9 MB (2,028,544 bytes)

Product version:
2.3.0.0

Copyright:
Copyright © 2014

Original file name:
Grepolis resources adder v1.0.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\grepolis resources adder v1.0.exe

File PE Metadata
Compilation timestamp:
3/14/2014 9:40:56 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:27//KAJJx9wi5HAKLiceMpYtRamZS9UPPYe:27vJJxGi5gKLjb8smZS9U3

Entry address:
0x1E75CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 48, 00, 00, 80, 10, 00, 00, 00, 60, 00, 00, 80, 18, 00, 00, 00, 78, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 02, 00, 00, 00, 90, 00, 00, 80, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8509

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.9 MB (1,988,096 bytes)

The file Grepolis resources adder v1.0.exe has been seen being distributed by the following URL.

Scan Grepolis resources adder v1.0.exe - Powered by Reason Core Security