gsautoclicker-setup.exe

GS Auto Clicker

The executable gsautoclicker-setup.exe has been detected as malware by 8 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from down.goldensoft.org.
Product:
GS Auto Clicker

Version:
3.1.4

MD5:
948d60e7509234b78141a14aa9802254

SHA-1:
61773776a1aa8926222feb7f3aeb4c9e73510dc7

SHA-256:
5bc004ad001957c97ac05ef0acd05a0265d9fb587aedba251e544860b2c748bf

Scanner detections:
8 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 12:07:11 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160518-2

AVG
Win32/Sality
2015.0.4604

Emsisoft Anti-Malware
Win32.Sality
16.07.03

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.E.gen
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.225.283.0

Norman
Win32.Sality.3
28.05.2016 15:32:18

File size:
914.9 KB (936,873 bytes)

Product version:
3.1.4

Copyright:
goldensoft.org

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\gsautoclicker-setup.exe

File PE Metadata
Compilation timestamp:
5/30/2016 9:33:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:4aWzgMQ7v3qnCibErQohh0F4zCJ8lnywQ8Sx+JMeiCYBGXe74050MOm:vaH8v6Cbrj/nywQ8Sx+6Js+7

Entry address:
0x16310

Entry point:
0F, AF, D0, C7, C1, A7, C2, B0, 36, 0F, AF, ED, 4E, 0F, B6, F1, 69, D2, ED, 52, 74, E8, 34, C3, 0F, AF, CE, E8, 27, 00, 00, 00, 81, FA, 7E, AD, 00, 00, 78, 06, 69, D3, 35, E4, 44, D8, 0D, 94, C3, BA, BE, 80, D4, A1, 00, C9, 85, C7, 75, 05, 15, 44, 95, 1D, 26, 81, FB, 44, 93, 00, 00, 01, CB, 8B, FD, FF, C2, C6, C5, 95, F6, C3, 5F, 28, EE, 35, C5, D5, 00, 00, F6, C4, EB, 86, DA, F2, 83, E7, 00, 3D, B8, 75, 49, 92, FF, C3, 8D, 1D, CD, 2C, DC, A5, 85, CD, 12, FA, 8B, D5, 81, C7, 25, 0C, 00, 00, 85, C3, 81, EF...
 
[+]

Entropy:
7.1403

Code size:
512.5 KB (524,800 bytes)

The file gsautoclicker-setup.exe has been seen being distributed by the following URL.

Remove gsautoclicker-setup.exe - Powered by Reason Core Security