leagueoflegends.exe

The executable leagueoflegends.exe has been detected as malware by 11 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from l3cdn.riotgames.com.
MD5:
58ca6015918abb74a4c7f3f5a25c4169

SHA-1:
40c6bb0537464da1c5932591155834a396f261db

SHA-256:
c91e916b2e9c03ebb8328f9a696fb471c9c3b6abeb00cb59dca02491a8bedd1f

Scanner detections:
11 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 8:54:34 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160215-2

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.215.1857.0

Norman
Win32.Sality.3
29.02.2016 03:11:57

VIPRE Antivirus
Threat.4721115
47432

File size:
3 MB (3,193,704 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\leagueoflegends.exe

File PE Metadata
Compilation timestamp:
10/29/2012 9:15:15 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
49152:L3iCOLMw0uSQ9EKF+mWgGRbhRjSmxXiTEcMGHtZTJeRzCsR1358d2OoiEjS80NV:eCOMKF+mlGxxSTEcMGNuusR12d2OWpoV

Entry address:
0xAE0F00

Entry point:
60, 74, 02, 8B, EB, B8, 36, 79, 57, A8, F7, C2, CD, 94, 5D, 92, 0D, 0C, FA, AC, E7, F3, F7, C1, 86, C2, 06, 07, EB, 05, 3C, 80, 85, F9, 45, 73, 08, 80, E5, BF, 19, C9, C6, C5, 4D, 3B, DF, C7, C6, AF, B1, 84, D5, EB, 05, 84, C8, 33, E9, 46, 14, 95, 51, 53, 87, DD, 69, D3, F4, 81, 7F, 1A, 69, FD, 37, 71, 08, 80, E8, 00, 00, 00, 00, EB, 04, F2, F2, FF, C8, 81, F9, F4, 8F, 00, 00, 78, 06, 81, CD, B8, FB, DD, BC, 77, 04, 2C, 35, FE, C8, 81, F7, 27, 40, 00, 00, 0F, AF, F5, 8A, F9, 58, C6, C6, A6, 88, D3, 80, E6...
 
[+]

Code size:
2.9 MB (3,084,288 bytes)

The file leagueoflegends.exe has been seen being distributed by the following URL.

Remove leagueoflegends.exe - Powered by Reason Core Security