multiplyroi_grand-theft-auto-3dfx-demo.exe

Helios Systems LLC

The application multiplyroi_grand-theft-auto-3dfx-demo.exe by Helios Systems has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from files4.downloadhub05.com.
Publisher:
Helios Systems LLC  (signed and verified)

MD5:
720a6bbfbad30594180f464928bee5ec

SHA-1:
680f66f064139d5976ce33d00dd9cbcc15bd4dba

SHA-256:
942a3540dc3c2e6daa4b9de6cf70da3c0cad80865ccef5913daa9ac70c42c66e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/2/2024 11:30:12 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DownloadAdmin.HeliosSy.Installer (M)
16.5.28.9

File size:
653.1 KB (668,728 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\multiplyroi_grand-theft-auto-3dfx-demo.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/1/2014 7:00:00 PM

Valid to:
6/4/2016 6:59:59 PM

Subject:
CN=Helios Systems LLC, O=Helios Systems LLC, L=Wilmington, S=Delaware, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
70C15F05936729D95E660D0642F059AF

File PE Metadata
Compilation timestamp:
5/11/2015 1:14:16 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:N9cazLCHa4Aq9C5pdDHG850PBkHh6wrZkbY9380QpkY6sj8eCaRV4gSQTOBN:bcaz+Hafq9CFDH3OmB6QZkM3cCS8KinN

Entry address:
0x1BB4

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, E0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, E8, DC, 51, 00, 00, 53, E8, 50, FD, FF, FF, 59, FF, 15, 50, 77, 40, 00, 68, 01, 80, 00, 00, FF, 15, 70, 70, 40, 00, 53, FF, 15, 4C, 77, 40, 00, 6A, 08, A3, 98, 2C, 42, 00, E8, B9, 09, 00, 00, 53, 68, 60, 01, 00, 00, A3, 00, 3D, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 73, 74, 40, 00, FF, 15, 9C, 71, 40, 00, 68, 68, 74, 40, 00, 68, 00, 35, 42, 00, E8, AB, 08, 00, 00, FF, 15, 6C, 70, 40, 00...
 
[+]

Entropy:
7.9744

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file multiplyroi_grand-theft-auto-3dfx-demo.exe has been seen being distributed by the following URL.

Remove multiplyroi_grand-theft-auto-3dfx-demo.exe - Powered by Reason Core Security