真三国无双6中文版_s5g2919.exe

游戏安装程序

上海游创网络科技有限公司

The application 真三国无双6中文版_s5g2919.exe by 上海游创网络科技有限公司 has been detected as a potentially unwanted program by 13 anti-malware scanners. The file has been seen being downloaded from d11.kuai8.com.
Publisher:
上海游创网络科技有限公司  (signed and verified)

Product:
游戏安装程序

Version:
1.0.0.221

MD5:
1535cd8709b4f7e1fe825541ded734aa

SHA-1:
c9985e87bfab7950ec70c80be5e7ccbd3336e238

SHA-256:
eef9998b44f6659287168cdf9803d16c58e94fe4c9d96ea73fd60583b1717a0a

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 2:27:18 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.102330
386

Arcabit
Trojan.Strictor.D18FBA
1.0.0.642

Bitdefender
Gen:Variant.Strictor.102330
1.0.20.75

Comodo Security
ApplicUnwnt.Win32.AdWare.Kuaiba.gh
23971

Emsisoft Anti-Malware
Gen:Variant.Strictor.102330
8.16.01.15.05

ESET NOD32
Win32/Adware.Kuaiba (variant)
10.12870

F-Secure
Gen:Variant.Strictor.102330
11.2016-15-01_6

G Data
Gen:Variant.Strictor.102330
16.1.25

IKARUS anti.virus
PUA.Kuaiba
t3scan.1.9.5.0

McAfee
Artemis!1535CD8709B4
5600.6520

MicroWorld eScan
Gen:Variant.Strictor.102330
17.0.0.45

Rising Antivirus
PE:PUF.GMUnpackerInstaller!1.9C4F [F]
23.00.65.16113

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
1.6 MB (1,665,584 bytes)

Product version:
1.0.0.221

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\?????6???_s5g2919.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
7/2/2015 1:55:44 AM

Valid to:
9/2/2017 1:55:44 AM

Subject:
CN=上海游创网络科技有限公司, E=leiz@1188.com, O=上海游创网络科技有限公司, L=上海市, S=上海市, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA G2, O=WoSign CA Limited, C=CN

Serial number:
35D0DB03C4179B99E5337097D3EA37CE

File PE Metadata
Compilation timestamp:
1/4/2016 9:11:39 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:tWllIx7e0sulgA+I3qe9be1LILGBZiIZiXxRTMKkfHw0:2I9e0sulgA+I3qe9be1LILGBZiIZiXN0

Entry address:
0x59541

Entry point:
E8, 83, D4, 00, 00, E9, 17, FE, FF, FF, 8B, 44, 24, 04, 66, 8B, 54, 24, 08, EB, 07, 66, 3B, CA, 74, 11, 40, 40, 0F, B7, 08, 66, 85, C9, 75, F1, 66, 39, 10, 74, 02, 33, C0, C3, 55, 8B, EC, B8, FF, FF, 00, 00, 83, EC, 14, 66, 39, 45, 08, 0F, 84, 97, 00, 00, 00, 53, FF, 75, 0C, 8D, 4D, EC, E8, FC, E6, FF, FF, 8B, 45, EC, 8B, 48, 14, 33, DB, 3B, CB, 75, 14, 8B, 45, 08, 8D, 48, 9F, 66, 83, F9, 19, 77, 03, 83, C0, E0, 0F, B7, C0, EB, 5E, 66, 81, 7D, 08, 00, 01, 73, 29, 8D, 45, EC, 50, 6A, 02, FF, 75, 08, E8, 99...
 
[+]

Entropy:
6.7428

Code size:
1.1 MB (1,175,552 bytes)

The file 真三国无双6中文版_s5g2919.exe has been seen being distributed by the following URL.

Remove 真三国无双6中文版_s5g2919.exe - Powered by Reason Core Security