secretcrushrevealer.exe

Game Play Labs

This is part of a distribution package that is classified as adware distributed by 50onRed. This adware is used to interact with the installed web browsers and inject ads and modify the default search and homepages. The application secretcrushrevealer.exe by Game Play Labs has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Game Play Labs  (signed and verified)

MD5:
7496f9c277ecef6fb6146d3479a568d6

SHA-1:
ea945fdd640aad3f6ab2d1913d04dfa4663db790

SHA-256:
1f258a65bb0b6ad069b68e815069e04423595d88d3e140a074caa8364f0dc193

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 2:21:35 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.50OnRed (M)
17.2.3.16

File size:
1.2 MB (1,213,056 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\secretcrushrevealer.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/3/2010 6:00:00 PM

Valid to:
11/4/2011 5:59:59 PM

Subject:
CN=Game Play Labs, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Game Play Labs, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6ACCE23BF8176B4E2BFCFFAB8FB3BB19

File PE Metadata
Compilation timestamp:
12/6/2010 8:07:09 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1313C

Entry point:
E8, A7, B5, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 08, F3, 42, 00, 33, C5, 89, 45, FC, F6, 05, 84, F1, 42, 00, 01, 56, 74, 08, 6A, 0A, E8, D9, 5B, 00, 00, 59, E8, 61, B6, 00, 00, 85, C0, 74, 08, 6A, 16, E8, 63, B6, 00, 00, 59, F6, 05, 84, F1, 42, 00, 02, 0F, 84, CA, 00, 00, 00, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC, FD, FF, FF, 66, 8C, 95, F8, FD, FF, FF, 66, 8C, 8D, EC, FD, FF...
 
[+]

Entropy:
7.0947

Code size:
149 KB (152,576 bytes)

Remove secretcrushrevealer.exe - Powered by Reason Core Security