king_of_fighters_v1.0.exe

King of Fighters

Nowstat.com

The executable king_of_fighters_v1.0.exe, “King of Fighters Setup ” has been detected as malware by 10 anti-virus scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from bg.gafree.com.
Publisher:
Nowstat.com

Product:
King of Fighters

Description:
King of Fighters Setup

MD5:
c006321fcc7f17a97775aa79d001d6c8

SHA-1:
4b9cf01f3bfb598b0ae28461da4a13e331ad71c2

SHA-256:
19c158cd459cf6b85b53eb88d224cde92669b4e1173a20a2b2ea856ee6478861

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
4/23/2024 10:39:32 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160503-1

AVG
Win32/Sality
2015.0.4568

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.221.606.0

Norman
Win32.Sality.3
19.05.2016 05:17:13

VIPRE Antivirus
Threat.4721115
48878

File size:
2.2 MB (2,353,451 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\king_of_fighters_v1.0.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:a2FCaZIxY4QIMoYcSRW0YhLaEQgN+o/ZnbqXw9yJ3OECvTI:7DIxY4v4HQ+EXco/ZnW+yJ3gk

Entry address:
0x9B24

Entry point:
60, 77, 0D, 22, D7, 8D, 35, B5, 5D, 89, 96, 2D, B9, F0, AD, CE, 55, 77, 08, C7, C7, BF, 4B, 0D, 7F, 03, CB, 0F, AF, C3, EB, 06, 88, FB, 41, 0F, AF, EB, 3B, F3, 77, 02, B3, CF, 81, C6, AE, 5A, 00, 00, F3, 81, C6, 73, 02, 00, 00, 38, C4, 4F, 0F, B6, D5, 88, D6, 72, 09, 8D, 15, 56, DB, C0, ED, F6, C5, 44, 68, 58, F0, 58, 00, 55, F3, E8, 20, 00, 00, 00, FF, CA, 0F, B7, F9, 0F, AF, EF, 0F, AF, C9, 0F, BF, C7, EB, 0A, 13, CE, 81, D0, C4, F3, 38, 02, 23, D0, 81, FB, 78, 57, 00, 00, 3D, 47, A2, 00, 00, 77, 02, 46...
 
[+]

Entropy:
7.9937  (probably packed)

Code size:
37 KB (37,888 bytes)

The file king_of_fighters_v1.0.exe has been seen being distributed by the following URL.

Remove king_of_fighters_v1.0.exe - Powered by Reason Core Security