need_for_speed_most_wanted.exe

WindowsApplication1

The executable need_for_speed_most_wanted.exe has been detected as malware by 12 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from cluster007.ovh.net and multiple other hosts.
Publisher:
Microsoft*  (Invalid match)

Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
ca1883290f184a3430210c035346d818

SHA-1:
09a25df5af8e1fa49f265241e9b5121f4f76bf59

SHA-256:
6aa3902098ad087921545568d747aa9f0ae21c77cfa3e97f3b7dad84e83d52cf

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
5/7/2024 7:03:49 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11587787
863

avast!
Win32:Dropper-gen [Drp]
2014.9-140925

Bitdefender
Trojan.Generic.11587787
1.0.20.1340

Emsisoft Anti-Malware
Trojan.Generic.11587787
8.14.09.25.06

F-Secure
Trojan.Generic.11587787
11.2014-25-09_5

G Data
Trojan.Generic.11587787
14.9.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.7.5.0

K7 AntiVirus
Riskware
13.183.13139

McAfee
Artemis!CA1883290F18
5600.6997

MicroWorld eScan
Trojan.Generic.11587787
15.0.0.804

nProtect
Trojan.Generic.11587787
14.08.22.01

Trend Micro House Call
TROJ_GEN.R0CBH09GU14
7.2.268

File size:
5.7 MB (5,942,784 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Microsoft 2014

Original file name:
Need for Speed Most Wanted.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\need_for_speed_most_wanted.exe

File PE Metadata
Compilation timestamp:
7/19/2014 2:42:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:AQznnx8Qznnx4QznnxdWmDnnEK+CVyNIlfXMuI8yMHhVqhvldJE6SWc92YT9wiaw:Fznx5znx9znxd5nHyNIlfMl8p2tE6Lcj

Entry address:
0x5A83EE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 0C, BF, C9, 53, 00, 00, 00, 00, 02, 00, 00, 00, 8F, 00, 00, 00, 1C, A0, 5A, 00, 1C, 68, 5A, 00, 52, 53, 44, 53, 41, 6D, 40, 75, 61, BF, 8A, 4B, 90, 7F, E7, 57, 74, 48, 5C, 1A, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 57, 6F, 6A, 74, 65, 6B, 5C, 44, 6F, 77, 6E, 6C, 6F, 61, 64, 73, 5C, 44, 65, 73, 6B, 74, 6F, 70, 20, 28, 37, 29, 5C, 49, 6E, 73, 74, 61, 6C, 61, 74, 6F, 72, 45, 4E, 47, 5C, 49, 6E, 73, 74, 61, 6C...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
5.6 MB (5,923,840 bytes)

The file need_for_speed_most_wanted.exe has been seen being distributed by the following 2 URLs.

Remove need_for_speed_most_wanted.exe - Powered by Reason Core Security