gta-vc.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from s8297.chomikuj.pl and multiple other hosts.
MD5:
167a5c8b31b3e0dbefa033ca24453d4e

SHA-1:
41cfa0d33fdc662bdc03e612b792a63887f1027f

SHA-256:
04e4db72629eaa786fdd182ac224f4fd6d68806f5f4fe5c1fb5f756dc4da11d7

Scanner detections:
5 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/24/2024 2:21:56 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAutoB
1.3.0.4613

Norman
Suspicious_Gen2.RYCIZ
11.20131228

Rising Antivirus
PE:Trojan.Crypt!6.A33
23.00.65.131221

VIPRE Antivirus
Trojan.Win32.Generic
24264

ViRobot
Trojan.Win32.A.NSAnti.3088896.A
2011.4.7.4223

File size:
2.9 MB (3,088,896 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
9/10/2012 5:15:03 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.50

CTPH (ssdeep):
24576:TtrSZlat4EQKhSFI1NvWM7axC7tpiCt90HhPuq1ihVCF2M1qrui6EbPjeW11Rdab:TSrMXypP5nsfbHrnYk3DL0LJkHDqFw

Entry address:
0x267BF0

Entry point:
55, 89, E5, 53, 83, EC, 48, 55, B8, FF, FF, FF, FF, 50, 50, 68, 40, 7E, 67, 00, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 83, EC, 20, 83, E4, E0, 68, 88, E6, 6D, 00, E8, EE, 00, 00, 00, 59, E8, 98, B5, 00, 00, E8, 23, 26, 00, 00, 85, C0, 74, 0F, 68, E0, A0, 66, 00, E8, B5, BC, FF, FF, 59, 85, C0, 74, 08, 6A, FF, E8, D9, BC, FF, FF, 59, E8, 43, 04, 01, 00, E8, 3E, 06, 01, 00, FF, 15, 68, 24, 6F, 00, 89, C3, EB, 18, 8D, 44, 20, 00, 3C, 22, 75, 0F, 43, 8A, 03, 84, C0, 74, 04, 3C, 22, 75, F5, 3C...
 
[+]

Packer / compiler:
REALbasic

Code size:
2.5 MB (2,609,152 bytes)

The file gta-vc.exe has been discovered within the following programs.

GTA San Andreas  by Rockstar Games Inc.
Grand Theft Auto: San Andreas is an open world action-adventure video game.
www.rockstargames.com
1% remove it
Gta vice city  by Modern
GTA Vice City is a video game distributed by Modern Games, a Persian downloadable game portal and translated into Farsi.
www.moderngamesiran.com
6% remove it
www.vc-o.com
About 1% of users remove it
 
Powered by Should I Remove It?

The file gta-vc.exe has been seen being distributed by the following 31 URLs.

http://s8297.chomikuj.pl/File.aspx?e=XLdUBnpGlACSvHf_PKxcp1qky0GkAUWH1T00YGv3XUwf7xO8EwhnncDFk8jy-787BJFeWJHM365Aund1Z9R1KrXwvX1x83oNdDCIxTLlfh2NTDTWiEv0i-xHm4279UV_&pv=2

http://download18.mediafire.com/vtmjr7ut11hg/.../gta-vc.exe

http://s7101.chomikuj.pl/File.aspx?e=Xwhq5gDMG3C6bCi3nCGk0hxic4kjgUObyR11DJ63RqlQRmQ0gdVyVVVpAq72bGUwiWT89vlxyH5JSVWGVnAHU8AjNvzcK2sQ_l1JRgQHmL2xTIFZd8-t6DIPy_1M1V4N&pv=2

https://docs.google.com/uc?authuser=0&id=0BxZFYkiyOdOfYVJsOFZFZDJtRzA&export=download

http://s7101.chomikuj.pl/File.aspx?e=Xwhq5gDMG3C6bCi3nCGk0o6uBOc2Vjzu3RTxgY3VMUrBOO8Zkb1zuQAveYT0fqYtyCLW0h7KmcpB2_rwyAqDZjv738YmNoCfaWoLb7ozF6yhtFMgBVgefdQ_AKHww64N&pv=2

temp:gta.exe

http://s7101.chomikuj.pl/File.aspx?e=Xwhq5gDMG3C6bCi3nCGk0kz_929-33k5I2VSJDZpcyb6EN33dzQ59YibOSb6I_JESAFvabrZ_9mXhGNAtvIbnGU9qJcTF41FH1SK7ymE7Em96ohb5vYVSCaGMtUbFJXJ&pv=2

http://s6649.chomikuj.pl/File.aspx?e=Xwhq5gDMG3C6bCi3nCGk0vxKbrEyPLh-RF_HUPdsKvzH41xPitukHJCZS6pvVvKwvcnVvBbyz3Z98vY8STD23YljMDXtgvU_2-DNgL2MvogtAyYCrtTs0F_mX62BTwlr&pv=2

http://s7101.chomikuj.pl/File.aspx?e=Xwhq5gDMG3C6bCi3nCGk0rbi0L3hwi_35XR6hyDhiUBVxH_3y_X1tDSLUTMjRFq9oIIcldUmOpq7jWDFJLyM5xLHBHSJJB1z0qooIbqQ21yHaxr_j9IimUxB-Tn8tyR1&pv=2

http://s7101.chomikuj.pl/File.aspx?e=bsOrp6_tN2B6qZTmEZqsaLe2Zm_RHZr7WtiikGTPhTqraceXeBcaOFn5tRXDe3G032QOm_Zh_u67frBMrdq0CqsWvKrk255GSRT_8V5o95jILV7pEjx-prtaekDL_EXV&pv=2

temp:$RO5060G.exe

http://s6649.chomikuj.pl/File.aspx?e=Xwhq5gDMG3C6bCi3nCGk0kFeovfXsT9lhDzydHZLj37U9i3z9LRbDjvJh1yXL_hIPck3jA-tWeVnqj0REn5_VfK4aH3fDYc3FtTMCblX6GPGfrZ7q9MaG8tqJrKm57Pw&pv=2

http://s7101.chomikuj.pl/File.aspx?e=IG7RAWQXlbELkxBaSsiX4u91t8cgZF_oqNBTJoNPU24xpiHu7Em3oMAaC1CPYnskXIvPKI6fnKrmHlCEYK6U6iDmlDiVceriwRDapOLsu7n6fW4gcDzXNTlRhXAq30yY&pv=2

about:internet

Latest 30 of 31 download URLs

The executing file has been seen to make the following network communications in live environments.

TCP:
Connects to vhcfw01.vrocker-hosting.co.uk  (46.105.184.132:8000)

TCP:
Connects to 31.52.6132.ip4.static.sl-reverse.com  (50.97.82.49:8000)

Scan gta-vc.exe - Powered by Reason Core Security