interlude-online gve.exe

The executable interlude-online gve.exe has been detected as malware by 8 anti-virus scanners. While running, it connects to the Internet address h3.ihc.ru on port 80 using the HTTP protocol.
MD5:
626e0eca83e26761fe5ac872f1ae3770

SHA-1:
92d30aa0a046e6e574b3b3ce675b1870736a4407

SHA-256:
f866637fc7f38888d1e37c6477c4a53fbad6b083c68f2b009d275ddf567dca7d

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
4/27/2024 12:56:30 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.Offend.Kd!c
2.1.4+

Avira AntiVirus
TR/Offend.KD.468665
8.3.3.2

IKARUS anti.virus
Trojan.Offend
t3scan.2.0.7.0

McAfee
Artemis!626E0ECA83E2
5600.6482

nProtect
Trojan-Downloader/W32.Genome.1281024
16.02.19.01

Qihoo 360 Security
HEUR/QVM05.1.Malware.Gen
1.0.0.1120

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16219

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
9310

File size:
1.2 MB (1,281,024 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\gve-updater\interlude-online gve.exe

File PE Metadata
Compilation timestamp:
9/20/2010 4:19:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:MDYoP1JgW1tQ2IXUFTBVx2S8lsdu1Hy+mWdyYoltCCiTcs/w1wV//QRqS7rA:MkUQIF2AaHTcsouV//Y38

Entry address:
0xCDD08

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, 57, B8, 4C, BE, 4C, 00, E8, 65, 95, F3, FF, 33, C0, 55, 68, EA, DD, 4C, 00, 64, FF, 30, 64, 89, 20, 33, C0, 55, 68, BB, DD, 4C, 00, 64, FF, 30, 64, 89, 20, A1, 70, 50, 4D, 00, 8B, 00, E8, E1, A6, F9, FF, A1, 70, 50, 4D, 00, 8B, 00, BA, 04, DE, 4C, 00, E8, 88, A1, F9, FF, A1, 70, 50, 4D, 00, 8B, 00, BA, 04, DE, 4C, 00, E8, C7, B2, F9, FF, E8, 66, B2, FA, FF, 84, C0, 75, 43, E8, FD, AF, FA, FF, 83, 78, 08, 00, 74, 14, E8, F2, AF, FA, FF, 8B, 50, 08, A1, 70, 50, 4D, 00, 8B, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
817 KB (836,608 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to h3.ihc.ru  (91.218.229.11:80)

Remove interlude-online gve.exe - Powered by Reason Core Security